4 ms·
SMS is better than nothing, but I personally know several people who had their accounts compromised because their SMS 2FA codes were intercepted. It's not possi
by computerfriend 3y ago
SMS is better than nothing, but I personally know several people who had their accounts compromised because their SMS 2FA codes were intercepted. It's not possible to do this with TOTP.
- mooreds 3y agoHow were they intercepted? Was it a sim takeover, where the attacker took over the phone number? Or intercepting the code over the air, since SMS has no encryption?
- computerfriend 3y agoThe latter.
- YetAnotherNick 3y agoHow can I someone see other's messages? Surely someone has step by step guide if it is that easy. Are you sure it was interception without SIM takeover?
- TheNewsIsHere 3y agoIt's not that you can do this just from any old device by flipping a built-in switch, but it's not that different from observing plaintext traffic over an Ethernet network with the right software. There are various ways to nab an SMS. Some are similar to SIM swap attacks in that they rely on social engineering or human or process fallibility to execute [1] [2], and others can grab messages right right out of the air, so to speak [3] [4]. This is in part because one of the foundational protocols that underlie modern cellular networks was never designed with modern security in mind. It's called SS7, and it's been extensively documented as a concern to the security of cellular based communications [5] [6] [7] [8]. Lot's of references because this is an area that has long fascinated me, and I have many bookmarks. There are also some recent papers on this behind paywalls (e.g., [9]). In between the lines and lightly touched on in some reporting is a nuanced point that I think plays a larger part - one issue is that overhauling these older foundational technologies isn't just a matter of commercial and standards changes but also moving the goal posts on where lawful interception happens in the stack, how it happens, and the technologies that support that. For example in the U.S., law enforcement agencies can acquire devices that impersonate cellular infrastructure in order to force communications to go through law enforcement controlled equipment (called IMSI catchers). If we were to revamp cellular networks with a view toward security in the way we probably should, it's reasonable that devices like that wouldn't be feasible without being operated by the telephone companies that own the networks, and that would probably become some amount of red tape that law enforcement doesn't like. [1] https://arstechnica.com/information-technology/2021/03/16-attack-let-hacker-intercept-a-t-mobile-users-text-messages/ https://arstechnica.com/information-technology/2021/03/16-at... [2] https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/ https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s... [3] https://www.firstpoint-mg.com/blog/ss7-attack-guide/ https://www.firstpoint-mg.com/blog/ss7-attack-guide/ [4] https://www.youtube.com/watch?v=RXBvO8TWGsw https://www.youtube.com/watch?v=RXBvO8TWGsw [5] https://www.theguardian.com/technology/2016/apr/19/ss7-hack-explained-mobile-phone-vulnerability-snooping-texts-calls https://www.theguardian.com/technology/2016/apr/19/ss7-hack-... [6] https://arstechnica.com/information-technology/2018/05/nefarious-actors-may-have-abused-routing-protocol-to-spy-on-us-phone-users/ https://arstechnica.com/information-technology/2018/05/nefar... [7] https://arstechnica.com/features/2019/04/fully-compromised-comms-how-industry-influence-at-the-fcc-risks-our-digital-security/ https://arstechnica.com/features/2019/04/fully-compromised-c... [8] https://www.zdnet.com/article/5g-networks-could-be-vulnerable-to-exploit-due-to-mishmash-of-old-technologies/ https://www.zdnet.com/article/5g-networks-could-be-vulnerabl... [9] https://link.springer.com/article/10.1007/s11235-023-01018-0 https://link.springer.com/article/10.1007/s11235-023-01018-0 edit: formatting
- YetAnotherNick 3y agoAgain, I want the tool through which I can see other people's messages, or at least a video of some hacker doing that. e.g. I can observe plaintext message over ethernet by using some splitter and wireshark.
- achandlerwhite 3y agoSo they had weak passwords? Or were their accounts recovered/reset via SMS which is prevalent but not 2nd factor login.