5 ms·
> This time can also be significantly reduced through phone number hints from password reset flows in other services such as PayPal, which provide several more
by Brybry 1y ago
> This time can also be significantly reduced through phone number hints from password reset flows in other services such as PayPal, which provide several more digits (ex. +14•••••1779)
I've never thought about this but it's extra scary. If you have the same phone number and email address with enough services and they all mask in a different order for reset hints...
- dkdcio 1y agowhat’s the risk? your email being made public? your phone number?
- rvnx 1y agoGet personal info, then call carrier for a SIM swap, access crypto from there. Bonus: no KYC, since it's the other person's identity + you can login from 4G internet, so a trusted IP range.
- shruggedatlas 1y agoWhat can be done to protect oneself from a SIM swap attack?
- sgjohnson 1y agoAbsolutely nothing whatsoever. If SIM Swap doesn’t work, you can always attack SS7. There’s also nothing you can do about that. So stop using your phone number as an authentication factor. It’s trivial to pwn for any actor determined-enough.
- deleted 1y ago[deleted]
- qingcharles 1y agoWhere can I get this though? I haven't been able to get into my main Google account for years because they enabled 2FA without warning and it had a phone number I no longer have. I have the username and password and I get all the emails because I also have the recovery email address. I just need to get the recovery code by SMS.
- c22 1y agoEven scarier, whoever has access to admin those services can just look up the unmasked data! Better to use unique numbers and addresses per service.
- rvnx 1y agoThere are now Telegram bots to find such information. The fact that this bruteforce was revealed probably annoyed many users (like the infamous "EoG" bot).
- lesuorac 1y agoThere were a few stories in the past about people social engineering their way past support by asking one companies support for the last 4 of a card and then using that last 4 for a different company.
- anonymars 1y agoHere's the one I'm thinking of (time flies, doesn't it?) https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/ https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking... > Those security lapses are my fault, and I deeply, deeply regret them. > But what happened to me exposes vital security flaws in several customer service systems, most notably Apple's and Amazon’s. Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information – a partial credit card number – that Apple used to release information. In short, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification. The disconnect exposes flaws in data management policies endemic to the entire technology industry, and points to a looming nightmare as we enter the era of cloud computing and connected devices.
- deleted 1y ago[deleted]
- paxys 1y agoIf it makes you feel better (it probably won't) hundreds/thousands of services have collected your phone number over the years (for 2FA or any other reason), with or without consent, and a large chunk of them have had data breaches. So your name-email-phone number combo is 100% already available in public data dumps.
- nicce 1y agoIf you have used Twitter or Facebook long enough while keeping the account, public your information is.
- permo-w 1y agonot so long ago practically everyone's name and phone number was available publicly for free in any phone box
- Rychard 1y agoNot to mention that these "phone books" also included everyone's address, and married couples were usually listed together.
- ghaff 1y agoYeah, you could get an unlisted number but you were charged for it and almost no one did because it was also how people you wanted to get in touch with you found you a lot of the time. Not that data breaches aren't bad but a lot of the breached info has been pretty routinely available for a very long time. (And, as you say, cell phone numbers are probably less routinely available than landlines were.) I don't go out of my way to publish my cell or address but a lot of people have them.
- 946789987649 1y agoWhen I was at university, I went to a talk from a security researcher who found this was the case with credit cards.
- 0x_rs 1y agoThere's services that do this automatically for a price, and they've been around for a while, for e-mail, phone numbers, and much more. Any bits (literally, bits) of information given without authorization (or plausible belief it's the intended user on the other side) will be efficiently put together from a variety of sources, as there's no shortage of incentive, and many all over the world prodding services used by billions of people worldwide. And then eventually leaked..
- ghaff 1y agoThere used to be deep web services that provided a lot of this stuff for free back in the early 2000s or so. I think everything like that is behind at least some level of paywall now but it's not hard to get a fairly complete dossier on someone given a bit of background information and a pretty small expenditure.