TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

I Hacked My Friend's Phone to Show How Easy It Is [video]

93 pointsby marvinborner8 months ago

9 comments

brianmiddleton8 months ago
I just got an email from my credit union that they&#x27;re &quot;transitioning from email passcode delivery to more secure methods such as phone calls and text messages&quot;. I need to send them this video.<p>That credit union is awful for many other reasons, so I don&#x27;t keep much in that account, but I wonder why banking in the US is so bad at security. I don&#x27;t think I have a single bank or credit card online account that allows for TOTP. It&#x27;s all SMS or phone call, with one bank allowing for app push notifications.<p>Is there a compliance check box that requires SMS over something with at least some security?
评论 #41620900 未加载
评论 #41617413 未加载
gastonmorixe8 months ago
Therefore, by adding multiple ways to log in&#x2F;recover an account, each additional one lowers the safety?<p>Also, worse: does this mean that by just having one bad 2FA&#x2F;recovery method like SMS along with more secure ones like TOTP&#x2F;RFC 6238 or hardware keys, the overall security level is as low&#x2F;bad as the worst method undermining the rest? Why do companies still allow or even encourage multiple methods (and SMS)?<p>I love the convenience of SMS sometimes, but if it doesn&#x27;t add any security at all, just a sense of fake security that they won&#x27;t even need an IMEI from me, just my phone number, jeez. This should be solved or forbidden by major institutions and services.
评论 #41614675 未加载
exabrial8 months ago
Can we stop requesting sms “authentication” for everything. Holy hell I don’t want my cell number to a back door into everything, so many services are making this account backdoor mandatory
Zren8 months ago
Feels like SS7 was deliberately left vulnerable from requests within the country for tracking purposes. A lot of the security seems to be done with firewalls within the walled garden so it&#x27;s easier for the five eyes to track cell phones live without giving direct access to the databases.<p>That said, the real world example Veratasium used was chilling.<p>Having LinusTechTips as a 2nd example (whos showing off his new apple phone) was a nice counter too. I&#x27;m pretty sure LTT uses multi factor+user auth though so I&#x27;m guessing that sms 2fa email was an alt email for personal use.<p>Gonna have to watch that 2014 presentation on ss7 it seems.
评论 #41614227 未加载
评论 #41613924 未加载
评论 #41614047 未加载
threesevenths8 months ago
If you’re looking for privacy don’t bring a two way radio gps tracker with you everywhere you go.
评论 #41619931 未加载
ksec8 months ago
The video actually shows this only applies to 2G and 3G. And while it stated that EU ( as usual ) used 2G for every car sold. They can stop supporting all 2G and 3G on Mobile.<p>To quote a report from GSA;<p>&gt;192 operators in 68 countries and territories have completed, planned, or are in the process of switching off their 2G and 3G networks.<p>So it is not as bad as most people thinks. My only wish is that we could do the 5.5G transition a lot faster and switch off 2G &#x2F; 3G ASAP.
cute_boi8 months ago
I am worried about Banks who uses sms for 2fa. :&#x2F;
absqueued8 months ago
Can we keep the original video title when posting?
评论 #41618104 未加载
bbogdn28 months ago
Privacy really doesn&#x27;t exist, huh?