Just in:
ISCA and ICAI Deepen Collaboration on AI Fluency and Professional Recognition // Sun’s personal WLFI claims stay in federal court // 5G Capital Sets a New Benchmark:China Unicom Beijing and Huawei Power the 2nd World Humanoid Robot Games with 5G-A GigaUplink // MacSync rotates domains as macOS credential theft expands // Anonymous Ox Alpha raises questions over prompt retention // From Vietnam to the U.S: East West Barbershop takes on the world’s most competitive market // Iran braces for sweeping US economic offensive // CFTC prepares crypto rules as Clarity Act stalls // NASA images expose crater from Falcon 9 crash // 40 Teams Gather in Hong Kong to Compete in the “AI x Cybersecurity Challenge” // MyRepublic expands GAMER lineup with Dreamcore x MyRepublic RTX 5060 Ti Gaming PC and Limited Edition ASUS T1 Graphics Card Broadband Bundle // AI sharpens cyber battle across financial markets // MoreTickets Reveals Hong Kong’s Top-Searched Summer Events and Evolving Ticket-Buying Behaviours // TDCX Opens Second Hyderabad Campus, Reinforcing India as Key Global Delivery Hub // CoinShares broadens WGMI as miners chase AI demand // Grok glitch sends users streams of gibberish // Wuxi Symphony Orchestra Debuts at Ljubljana Festival: Sounds of the East Illuminate the Historic Central European City // Trump’s new green card era: What changes for US immigrants // Objective Digital Psychological Assessment Launches in Singapore, Offering Clarity for Inattention and Hyperactivity Concerns // Iran rial sinks beyond two million per dollar //

Two-factor security is so broken, now hackers can drain bank accounts

1493932411 two factor 2

two-factor-2.jpg

We’ve known for years that a key protocol that allows global cellular networks to communicate with each other had vulnerabilities — and nobody really took it that seriously.

Hackers and politicians alike have been warning for years that these flaws in the calling and text message routing system, known as Signaling System 7 (SS7), can be used to intercept and redirect calls and text messages, allowing hackers to eavesdrop on almost any phone in the world.

Now, financially driven hackers are using the weakness to intercept text messages that deliver two-factor codes to bank customers to break in and empty their bank accounts, according to a report in a German newspaper.

It’s likely the first known account of the SS7 vulnerability being exploited in the wild by a malicious actor, rather than for demonstrative purposes.

According to the newspaper, the attackers would try to get into a person’s bank account. Armed with their username and password — possibly recycled from another breach — they would log in to their victims’ online banking account. Trouble is, they may not be able to get past the two-factor code, which sends a code or a phone call to a trusted device — like a phone — to ensure nobody else can log in.

By intercepting the call or text message using equipment, which the German newspaper said can be sold for around €1,000 ($1,100 in today’s conversion), the attackers can use the code to get full access to the bank account — and send money to any other account they want.

Some networks fare better than others, but nobody has fixed the vulnerabilities — likely because of the thought-to-be low risk for consumers versus a high cost and difficulty to fix.

That might have to change, now that potentially any text message-based two-factor authentication might be at risk — social networking accounts, banking logins, and email accounts, to name a few.

“Everyone’s accounts protected by text-based two-factor authentication, such as bank accounts, are potentially at risk until the FCC and telecom industry fix the devastating SS7 security flaw,” said Rep. Ted Lieu (D-CA) in a statement. Lieu is one of the few members of Congress with a computer science background — and who allowed hackers to eavesdrop on his phone during a 2015 episode of CBS “60 Minutes.”

“Both the Federal Communications Commission and telecom industry have been aware that hackers can acquire our text messages and phone conversations just knowing our cell phone number,” he added, before urging Congress to hold “immediate hearings” on the matter.

Just last year, the National Institute of Standards and Technology (NIST) said that it would deprecate its advice — albeit, not entirely advise against — for text message-based authentication, because it wasn’t as secure as other forms of two-factor authentication — such as apps, like Google Authenticator and Authy, which use end-to-end encryption to send two-factor codes.

The problem is many apps don’t provide app support for two-factor codes. You can check on this website though, which shows which sites, services, and companies support “software tokens.”

And if you haven’t ventured into two-factor territory yet — you really should. We even have a handy step-by-step guide to help you through.

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…