Hacker paid a company called Sakari $16 to reroute a reporter's texts and used SMS 2FA to break into his accounts, showing the need for regulation of SMS tools
incredibly — allowed a reporter's texts to be intercepted and sent to another device. All you had to do is swear you're authorized to receive texts at the targeted number. This is nuts. https://www.vice.com/... Tavis Ormandy / @taviso : SMS-2FA is harmful and literally doesn't work. There is no reason to ever enable it. https://twitter.com/... Erica Joy / @ericajoy : PMs should prioritize moving off SMS 2FA in their roadmaps. it's been years since the flaws in this method of authentication were first demonstrated, it's time y'all. https://twitter.com/... Malcolm Nance / @malcolmnance : This is a serious flaw. We are all exposed. https://twitter.com/... Joseph Cox / @josephfcox : This attack brings up all sorts of issues for private, corporate, etc, security. So much of our digital lives and security relies on a phone number for verification. Completely meaningless when you can pay $16 to beat that https://www.vice.com/... https://twitter.com/... Aki Peritz / @akiperitz : Everyone should read this. Every Member of Congress should read this. Every CEO should read this. https://twitter.com/... @motherboard : To achieve your worst nightmare, there's no SIM swapping required. https://www.vice.com/... Rob Zacny / @robzacny : As someone who has been grudgingly accepted SMS two-factor as the price of security, this is alarming! And also very annoying! https://www.vice.com/... Chris Riley / @mchrisriley : This feels like a major vulnerability here: “NetNumber owns and operates the proprietary, centralized database that the industry uses for text message routing, the Override Service Registry (OSR), Bandwidth said.” Are we talking about that at all, not just policy failures? https://twitter.com/...
VICE Joseph Cox
Related Coverage
- It's time to stop using SMS for anything. Medium
- View article Android Police
- Start Up No.1506: Berners-Lee calls for nicer networks, Telegraph mulls PPC journalism, carmakers try to delay electric future, and more The Overspill · Charlesarthur
- Companies can silently reroute your texts to hackers, sometimes for just $16 The Verge · Mitchell Clark
Discussion
-
@josephfcox
Joseph Cox
on x
New: this is truly insane. For $16, a hacker rerouted my texts; received messages meant for me; broke into my online accounts. This isn't SIM jacking or SS7. You just pay a company in this unregulated wild west and get control of text routing in minutes https://www.vice.com/...
-
@jason_koebler
Jason Koebler
on x
NEW: Software made to let businesses send text messages can take over anyone's phone number with no notifications, allowing anyone to intercept a target's phone numbers and leverage that access to break into other accounts. This is a gigantic flaw https://www.vice.com/...
-
@josephfcox
Joseph Cox
on x
This is a high level overview of how Sakari, the tested company, gets the capability to reroute text messages and then sells that for $16 https://www.vice.com/... https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
It's not clear how much this attack is being used against mobile numbers in the wild. But another company that offers a similar service says it has detected and acted on abuse, so people are doing it https://www.vice.com/... https://twitter.com/...
-
@disenpepe
king Pepe Alexander III
on x
Daily reminder SMS 2FA is pretty useless. https://twitter.com/...
-
@ariehkovler
Arieh Kovler
on x
Choose authenticator apps / devices over SMS 2FA every time. https://twitter.com/...
-
@ericajoy
Erica Joy
on x
PMs should prioritize moving off SMS 2FA in their roadmaps. it's been years since the flaws in this method of authentication were first demonstrated, it's time y'all. https://twitter.com/...
-
@briankrebs
@briankrebs
on x
Vice story on a service that — incredibly — allowed a reporter's texts to be intercepted and sent to another device. All you had to do is swear you're authorized to receive texts at the targeted number. This is nuts. https://www.vice.com/...
-
@wadhwa
Vivek Wadhwa
on x
This is crazy. Self regulation has indeed failed @AjitPai https://twitter.com/...
-
@dangillmor
Dan Gillmor
on x
SMS is one of the most insecure ways of communicating, and Big Telecom is not interested in fixing it. It's worse than you imagined, as this latest from @motherboard shows: https://www.vice.com/...
-
@josephfcox
Joseph Cox
on x
When signing up to the company that lets you reroute texts, you just have to sign a letter saying you have consent. But as the hacker showed, you can just add someone else's number https://www.vice.com/... https://twitter.com/...
-
@film_girl
Christina Warren
on x
Absolutely incredible reporting. https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
Presumably, now that this is public info, telecoms will be on the look out for anyone trying to exploit this and block it. Right? ... Right? https://twitter.com/...
-
@nbougalis
@nbougalis
on x
Some company nobody's every heard of controls the global routing of SMS messages... great. It's easy to pretend this is about SMS. It's not. It's about a whole industry whose security model is based on nothing! Ways to avoid this: https://twitter.com/...
-
@doctorow
Cory Doctorow
on x
Writing for @motherboard, @josephfcox describes how a security researcher named @lucky225 was able to (consensually) divert his text messages after paying $16 to a company called @sakari_io. https://www.vice.com/... 8/
-
@briankrebs
@briankrebs
on x
A Medium piece from @lucky225 has a deep dive into how all SMS-based authentication just got owned. https://lucky225.medium.com/ ... I agree: It's long past time to stop using SMS for anything.
-
@babyfrogz0730
Nugz
on x
Watch out where u using ur phone esp unsecured WiFi networks these hackers ain't no joke! https://twitter.com/...
-
@onekade
@onekade
on x
This is terrifying. Three things: 1. Congress, where you at? 2. Use signal, not SMS. 3. Didn't get that 2-factor auth text? Maybe someone else did. https://www.vice.com/...
-
@petersterne
Peter Sterne
on x
Incredible. This isn't even a hack. It's just a fundamental insecurity that's built into the SMS system. https://www.vice.com/...
-
@josephfcox
Joseph Cox
on x
Sakari, the company used in this test, is just one company. There is a whole industry of these providers that let you bring your own number and receive texts via their service https://www.vice.com/... https://twitter.com/...
-
@snazzyq
Quinn Nelson
on x
This is why Apple should release imessage for Android. I know nobody outside of the U.S. uses SMS still but we do and nobody here is gonna switch to WhatsApp, Telegram, Signal or whatever else you want to suggest. https://twitter.com/...
-
@ericgarland
Eric Garland
on x
Yes. It seems problematic. https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
We tested not just the text rerouting itself, but the step after that: using the hijacked text service to then break into various accounts. In our case, Postmates, WhatsApp, and Bumble. Shows issue with SMS based login https://www.vice.com/... https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
FCC Acting Chairwoman Jessica Rosenworcel says FCC needs to “better understand this potential vulnerability and make sure we are taking the right steps to protect and educate consumers.” https://www.vice.com/... https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
Each of the telecos, including T-Mobile that we conducted the text hijack attack on, declined to comment, and instead CTIA, the wireless trade association, gave this statement. https://www.vice.com/... https://twitter.com/...
-
@vickerysec
Chris Vickery
on x
Listen up folks. You know how a lot of prosecutions rely heavily on text message records? Surprise, surprise- Telecom companies have been so loose and recklessly irresponsible with our trust and privacy that it now costs only $16 to hijack another person's phone number. https://t…
-
@viss
@viss
on x
you want companies to stop using sms 2fa? find the phone numbers of the board and the entire c-suite of execs and do this to them watch how fast they demand their devs move to totp. https://www.vice.com/...
-
@benthepcguy
Ben Rudolph
on x
This is SUPER SCARY. Get yourself an authenticator app (Microsoft makes a great one, so does Google) and ditch SMS-based 2FA. https://twitter.com/...
-
@malcolmnance
Malcolm Nance
on x
This is a serious flaw. We are all exposed. https://twitter.com/...
-
@taviso
Tavis Ormandy
on x
SMS-2FA is harmful and literally doesn't work. There is no reason to ever enable it. https://twitter.com/...
-
@kimcrayton1
@kimcrayton1
on x
Tech is NOT neutral nor apolitical AND we should stop approaching these matters as “flaws” when in fact, they're the direct result of mediocre, unremarkable white dudes who refuse to rely on the expertise of those with the lived experiences of how tech is used to target and harm …
-
@josephfcox
Joseph Cox
on x
This attack brings up all sorts of issues for private, corporate, etc, security. So much of our digital lives and security relies on a phone number for verification. Completely meaningless when you can pay $16 to beat that https://www.vice.com/... https://twitter.com/...
-
@akiperitz
Aki Peritz
on x
Everyone should read this. Every Member of Congress should read this. Every CEO should read this. https://twitter.com/...
-
@motherboard
@motherboard
on x
To achieve your worst nightmare, there's no SIM swapping required. https://www.vice.com/...
-
@robzacny
Rob Zacny
on x
As someone who has been grudgingly accepted SMS two-factor as the price of security, this is alarming! And also very annoying! https://www.vice.com/...
-
@mchrisriley
Chris Riley
on x
This feels like a major vulnerability here: “NetNumber owns and operates the proprietary, centralized database that the industry uses for text message routing, the Override Service Registry (OSR), Bandwidth said.” Are we talking about that at all, not just policy failures? https:…