/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hacker paid a company called Sakari $16 to reroute a reporter's texts and used SMS 2FA to break into his accounts, showing the need for regulation of SMS tools

incredibly — allowed a reporter's texts to be intercepted and sent to another device. All you had to do is swear you're authorized to receive texts at the targeted number. This is nuts. https://www.vice.com/... Tavis Ormandy / @taviso : SMS-2FA is harmful and literally doesn't work. There is no reason to ever enable it. https://twitter.com/... Erica Joy / @ericajoy : PMs should prioritize moving off SMS 2FA in their roadmaps. it's been years since the flaws in this method of authentication were first demonstrated, it's time y'all. https://twitter.com/... Malcolm Nance / @malcolmnance : This is a serious flaw. We are all exposed. https://twitter.com/... Joseph Cox / @josephfcox : This attack brings up all sorts of issues for private, corporate, etc, security. So much of our digital lives and security relies on a phone number for verification. Completely meaningless when you can pay $16 to beat that https://www.vice.com/... https://twitter.com/... Aki Peritz / @akiperitz : Everyone should read this. Every Member of Congress should read this. Every CEO should read this. https://twitter.com/... @motherboard : To achieve your worst nightmare, there's no SIM swapping required. https://www.vice.com/... Rob Zacny / @robzacny : As someone who has been grudgingly accepted SMS two-factor as the price of security, this is alarming! And also very annoying! https://www.vice.com/... Chris Riley / @mchrisriley : This feels like a major vulnerability here: “NetNumber owns and operates the proprietary, centralized database that the industry uses for text message routing, the Override Service Registry (OSR), Bandwidth said.” Are we talking about that at all, not just policy failures? https://twitter.com/...

VICE Joseph Cox

Discussion

  • @josephfcox Joseph Cox on x
    New: this is truly insane. For $16, a hacker rerouted my texts; received messages meant for me; broke into my online accounts. This isn't SIM jacking or SS7. You just pay a company in this unregulated wild west and get control of text routing in minutes https://www.vice.com/...
  • @jason_koebler Jason Koebler on x
    NEW: Software made to let businesses send text messages can take over anyone's phone number with no notifications, allowing anyone to intercept a target's phone numbers and leverage that access to break into other accounts. This is a gigantic flaw https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    This is a high level overview of how Sakari, the tested company, gets the capability to reroute text messages and then sells that for $16 https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    It's not clear how much this attack is being used against mobile numbers in the wild. But another company that offers a similar service says it has detected and acted on abuse, so people are doing it https://www.vice.com/... https://twitter.com/...
  • @disenpepe king Pepe Alexander III on x
    Daily reminder SMS 2FA is pretty useless. https://twitter.com/...
  • @ariehkovler Arieh Kovler on x
    Choose authenticator apps / devices over SMS 2FA every time. https://twitter.com/...
  • @ericajoy Erica Joy on x
    PMs should prioritize moving off SMS 2FA in their roadmaps. it's been years since the flaws in this method of authentication were first demonstrated, it's time y'all. https://twitter.com/...
  • @briankrebs @briankrebs on x
    Vice story on a service that — incredibly — allowed a reporter's texts to be intercepted and sent to another device. All you had to do is swear you're authorized to receive texts at the targeted number. This is nuts. https://www.vice.com/...
  • @wadhwa Vivek Wadhwa on x
    This is crazy. Self regulation has indeed failed @AjitPai https://twitter.com/...
  • @dangillmor Dan Gillmor on x
    SMS is one of the most insecure ways of communicating, and Big Telecom is not interested in fixing it. It's worse than you imagined, as this latest from @motherboard shows: https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    When signing up to the company that lets you reroute texts, you just have to sign a letter saying you have consent. But as the hacker showed, you can just add someone else's number https://www.vice.com/... https://twitter.com/...
  • @film_girl Christina Warren on x
    Absolutely incredible reporting. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Presumably, now that this is public info, telecoms will be on the look out for anyone trying to exploit this and block it. Right? ... Right? https://twitter.com/...
  • @nbougalis @nbougalis on x
    Some company nobody's every heard of controls the global routing of SMS messages... great. It's easy to pretend this is about SMS. It's not. It's about a whole industry whose security model is based on nothing! Ways to avoid this: https://twitter.com/...
  • @doctorow Cory Doctorow on x
    Writing for @motherboard, @josephfcox describes how a security researcher named @lucky225 was able to (consensually) divert his text messages after paying $16 to a company called @sakari_io. https://www.vice.com/... 8/
  • @briankrebs @briankrebs on x
    A Medium piece from @lucky225 has a deep dive into how all SMS-based authentication just got owned. https://lucky225.medium.com/ ... I agree: It's long past time to stop using SMS for anything.
  • @babyfrogz0730 Nugz on x
    Watch out where u using ur phone esp unsecured WiFi networks these hackers ain't no joke! https://twitter.com/...
  • @onekade @onekade on x
    This is terrifying. Three things: 1. Congress, where you at? 2. Use signal, not SMS. 3. Didn't get that 2-factor auth text? Maybe someone else did. https://www.vice.com/...
  • @petersterne Peter Sterne on x
    Incredible. This isn't even a hack. It's just a fundamental insecurity that's built into the SMS system. https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    Sakari, the company used in this test, is just one company. There is a whole industry of these providers that let you bring your own number and receive texts via their service https://www.vice.com/... https://twitter.com/...
  • @snazzyq Quinn Nelson on x
    This is why Apple should release imessage for Android. I know nobody outside of the U.S. uses SMS still but we do and nobody here is gonna switch to WhatsApp, Telegram, Signal or whatever else you want to suggest. https://twitter.com/...
  • @ericgarland Eric Garland on x
    Yes. It seems problematic. https://twitter.com/...
  • @josephfcox Joseph Cox on x
    We tested not just the text rerouting itself, but the step after that: using the hijacked text service to then break into various accounts. In our case, Postmates, WhatsApp, and Bumble. Shows issue with SMS based login https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    FCC Acting Chairwoman Jessica Rosenworcel says FCC needs to “better understand this potential vulnerability and make sure we are taking the right steps to protect and educate consumers.” https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Each of the telecos, including T-Mobile that we conducted the text hijack attack on, declined to comment, and instead CTIA, the wireless trade association, gave this statement. https://www.vice.com/... https://twitter.com/...
  • @vickerysec Chris Vickery on x
    Listen up folks. You know how a lot of prosecutions rely heavily on text message records? Surprise, surprise- Telecom companies have been so loose and recklessly irresponsible with our trust and privacy that it now costs only $16 to hijack another person's phone number. https://t…
  • @viss @viss on x
    you want companies to stop using sms 2fa? find the phone numbers of the board and the entire c-suite of execs and do this to them watch how fast they demand their devs move to totp. https://www.vice.com/...
  • @benthepcguy Ben Rudolph on x
    This is SUPER SCARY. Get yourself an authenticator app (Microsoft makes a great one, so does Google) and ditch SMS-based 2FA. https://twitter.com/...
  • @malcolmnance Malcolm Nance on x
    This is a serious flaw. We are all exposed. https://twitter.com/...
  • @taviso Tavis Ormandy on x
    SMS-2FA is harmful and literally doesn't work. There is no reason to ever enable it. https://twitter.com/...
  • @kimcrayton1 @kimcrayton1 on x
    Tech is NOT neutral nor apolitical AND we should stop approaching these matters as “flaws” when in fact, they're the direct result of mediocre, unremarkable white dudes who refuse to rely on the expertise of those with the lived experiences of how tech is used to target and harm …
  • @josephfcox Joseph Cox on x
    This attack brings up all sorts of issues for private, corporate, etc, security. So much of our digital lives and security relies on a phone number for verification. Completely meaningless when you can pay $16 to beat that https://www.vice.com/... https://twitter.com/...
  • @akiperitz Aki Peritz on x
    Everyone should read this. Every Member of Congress should read this. Every CEO should read this. https://twitter.com/...
  • @motherboard @motherboard on x
    To achieve your worst nightmare, there's no SIM swapping required. https://www.vice.com/...
  • @robzacny Rob Zacny on x
    As someone who has been grudgingly accepted SMS two-factor as the price of security, this is alarming! And also very annoying! https://www.vice.com/...
  • @mchrisriley Chris Riley on x
    This feels like a major vulnerability here: “NetNumber owns and operates the proprietary, centralized database that the industry uses for text message routing, the Override Service Registry (OSR), Bandwidth said.” Are we talking about that at all, not just policy failures? https:…