10 ms·
A hacker got all my texts for $16
- DyslexicAtheist 6y agoSMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.
- thaumasiotes 6y ago"2 Factor" isn't the right word choice. SMS isn't being used as a second factor here; it's the only factor.
- vmception 6y ago"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph
- jsnell 6y agoNonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries). The problem is purely with how some companies are applying SMS as an auth factor. In cases where SMS us being used as a recovery factor, it should not be allow for immediate recovery. Instead the user should be notified via other channels (email, phone notifications) about the recovery attempt, be given the opportunity to reject it, and for the recovery to only succeed if it is not denied after e.g. 3 days.
- devoutsalsa 6y agoI hate having to use a smartphone for auth in general. Especially when I have an app on my phone that expects me to be able to receive an SMS on the same phone. It’s like I need my phone to recover having lost my phone.
- nickjj 6y ago> I hate having to use a smartphone for auth in general. Same, especially since I don't have a smartphone. Often times I'll go a week without looking at my phone and by then it has lost its charge so if an app requires a OTP to do something I often need to wait a while before it's charged enough to receive a text. I do have a Google Voice number but I've mistakenly used my real number for a few services that frequently require SMS confirmations.
- devoutsalsa 6y agoI use Google Voice when at all possible, but there are a few cases where it doesn’t work. The easiest way to piss me off is to make me use a USA number that isn’t my Google Voice number! It doesn’t help that some services won’t even let me log from a non-USA IP when I’m traveling.
- vmception 6y agoOne Time Passcode seeds are a globally available ID system. and I really don't call them second factor, that conflates the whole issue of where they are stored, how they are synced and used. people should be able to recover access to their one time passcode seed and there is little excuse for this.
- jsnell 6y agoTOTP is globally available, but does not have an established way of recovering your key if it's lost. ("Little excuse" or not, people will not back up the key or print backup codes.) While if I lose my SIM card, I'll walk to one of my operator's shops (there's probably one within 1km), show them my ID, and they'll replace the SIM. It's the only digital identifier that I could bootstrap from if I lost access to everything in one go.
- malwarebytess 6y agoDoes anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. Feels like the industry needs to push for a dedicated, universal, probably physical, tool for 2FA.
- david_shaw 6y ago> Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. This is not the case in my experience. Many apps that once used Authenticator-based TOTP now use app-based push alerts (Steam Authenticator, Blizzard Authenticator, Google->GMail App, etc.), but I haven't noticed a trend toward actual SMS. Are there major orgs that switched to SMS 2FA and disabled authenticator apps? If so, I'd be interested in learning why, also.
- SilverRed 6y agoThe shit part is I now need 50 apps on my phone to use stuff. I don't want the steam app, I have no use for it. But features of my steam account are now limited because I don't use the app.
- closeparen 6y agoService providers that are very behind the curve (e.g. banks, brokerages) started providing SMS-only 2FA years after internet companies started with TOTP. That could create the perception of a shift towards SMS.
- t-writescode 6y agoUbiquity: almost everyone has a cell phone. They’re nearly required for all but the richest people. Simplicity: nearly everybody understands how texting works.
- lstamour 6y agoThey have it, it’s called FIDO2, and it even works with existing devices such as Touch ID or Windows Hello in common browsers such as Chrome. Even Google doesn’t promote Google Authenticator now, but they keep it around for legacy reasons because it still works, until you lose your phone. That’s where FIDO2 shines: just authenticate more than one device, including purchased hardware tokens if you want something cheaper than a phone, and you’ll always have at least one device with access, somewhere.
- t-writescode 6y agoI like not being locked out of my applications when my phone goes for an unexpected swim and I have to replace it. The numerous emails I get when I log in from a new device serve me pretty well, all things considered
- 177tcca 6y agoSecure phones are sub-$200. If you have multiple accounts, services, etc, then backing up your 2FA codes, or registering two devices/phones at the same time should be on your radar.
- t-writescode 6y agoThis doesn't sound like something your average user is going to be doing in most cases - keeping a backup, secondary phone. We've already successfully gotten people to start using some level of 2FA in the form of SMS-based identity validation along with their password. That's a pretty impressive step forward, and sufficient for most non-specifically targeted users' usage.
- 177tcca 6y agoUntil they're targeted. You can fool carrier customer service with no training.
- t-writescode 6y agoYes, that is indeed what I said. edit: everyone has a threat matrix they have to deal with.
- 177tcca 6y agoNOBODY is targeted to be robbed until they are — what?
- JoshTriplett 6y ago> or registering two devices/phones at the same time A substantial number of services don't support this, which is a serious impediment to using 2FA both safely and securely.
- minusSeven 6y agoWhat is an alternative that can work in all countries without any problems?
- twiddling 6y agohttps://lucky225.medium.com/its-time-to-stop-using-sms-for-anything-203c41361c80 https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
- tbodt 6y agoThis doesn't load for me for some reason. This works better: http://web.archive.org/web/20210315224524/https://lucky225.medium.com/its-time-to-stop-using-sms-for-anything-203c41361c80 http://web.archive.org/web/20210315224524/https://lucky225.m...
- the_snooze 6y agoToo many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all.
- lxgr 6y agoIt's neither convenient nor stable for anyone moving between countries either. When given the choice between a service that uses my phone number as my permanent user identifier and one that uses my email, I'll always go for the latter. Unfortunately, big parts of the industry seem to be headed the other direction.
- firecall 6y agoInternational relocation is a very good point! Something I hadnt considered. Thanks!
- ronnier 6y agoI just transferred my phone number to google voice when I moved out of the country. When I moved it back I simply transfer it back to my carrier
- bravura 6y agoThere seem to be horror stories on reddit about Google Voice numbers being terminated for people out of the country too long. Is there a stable inexpensive phone number service for folks that are outside the US a lot?
- 0x38B 6y agoI've been looking into Google Voice alternatives, and https://voip.ms/ https://voip.ms/ looks good.
- kevincox 6y agoI've been using voip.ms and it is fairly good. I wish the SMS support was a bit better but it does reliable deliver messages to email or SIP. (Large messages are not re-joined though and sending is based off of a code in the subject instead of an email address per-number which could be easily be added to an address book)
- testfoobar 6y agoHow do you protect against this type of attack?
- 0xbadcafebee 6y agoDon't use a phone. Lucky's company has this product that can monitor for the attack, but it won't prevent it: https://okeymonitor.com/ https://okeymonitor.com/
- wealthyyy 6y agoBanks already has tools that detects SIM Swaps and SS7 attacks. It's just hard to make decisions. Banks care about false positives too.
- techrat 6y agoDon't use Phone number based 2Factor or if you must use a number, keep it to an app (eg, Google Voice) and don't forward your Google Voice texts to your phone's number. Basically, avoid using your carrier provided phone number for anything related to an account.
- jrwr 6y agoGoogle Voice SMS might not be able to help since they are all in the same POTS ecosystem as well.
- bogwog 6y agoBut Google Voice requires a Google account, and to create a Google account you need to provide a valid phone number. There are also a lot of service providers that don't allow you create an account without providing a valid phone number. I wonder how high-profile politicians and celebrities deal with security issues like this? If this is really such an easy attack to pull off, what's stopping someone from shilling cryptocurrencies on celebrity social media accounts (again)?
- davchana 6y ago
- lstamour 6y agoIt’s worth pointing out that often LOA forms ask for a PIN, usually the same PIN as would be required to check voicemail. A better telecom company might make the PIN something harder to remember but enforcing such things would also make it harder to switch carriers, particularly if it replaced today’s standard forms of ID checks. It’s better to assume that until phone numbers can be locked and unlocked the way domains can, with a random authorization code only accessible by real offline 2FA (though not all domain providers require it), and with the option of completely encrypted end-to-end texting (RCS?), well, then SMS won’t really be all that secure.
- lvs 6y agoMy reading of this article suggests that the PIN requirement for number porting is bypassed in this forwarding scenario, since this method is claimed to be distinct from simjacking. That is, the number hasn't been ported by the FCC's guidelines, although I didn't glean exactly how that's happening by these retail providers.
- fatnoah 6y agoSMS routing and number porting are different things, as the voice and SMS operate independently. I headed Engineering for a company that allowed you to SMS enable your landline or toll-free number, and our automated flow for non-toll-free landlines required receiving a code via telephone call (to avoid the situation of compromised SMS routing). We didn't support numbers that were not in those two buckets, i.e. mobile numbers (not allowed by carriers) as well as "virtual" numbers like Google voice, Twilio, etc. (possibility for abuse and/or no way to properly validate ownership). OP's issue is purely the fault of Sakari for having terrible process. The process of changing the routing is pretty simple. It's a matter of being a trusted actor and having the ability to submit changes in routing for SMS to a central provider that maintains and propagates this info.
- lvs 6y agoThanks. So, as with simjacking, a bad actor, e.g. an employee at a company with poor internal controls, can sell (or inadvertently give) access to anyone's 2FA codes.
- voicedYoda 6y agoVoip.ms, vonage/twilio, et al let you set up an SMS capable number really quickly and cheaply, available globally... And you'd be fully in control
- ampdepolymerase 6y agoUntil you get deplatformed. Tech-first MVNOs don't always have the same consumer rights and anti trust requirements as those regulated by the FCC.
- floss_silicate 6y agoI tried to set up a Twilio number specifically to handle these services that demand SMS for login. Weirdly it only works for a minority of services, I expect many use Twilio to send their auth texts and Twilio blocks sending these to their own numbers?
- closeparen 6y agoPart of SMS verification is to raise the cost of Sybil attacks. Well known sources of cheap bulk phone numbers are often banned for that reason.
- sushid 6y agoI'm not sure if Twilio blocks sending to their own numbers but you can't receive from or send to short codes, which will limit you a lot when verifying with services like Uber.
- dimmke 6y agoThe reason most services require a phone number is so you can't just create a new account if you get banned and ideally your account is somewhat tied to a real person. They ban VOIP numbers because it would defeat the whole point.
- TwoBit 6y agoWhat's preventing someone from getting mutiple regular phones and accounts for them then?
- hn_throwaway_99 6y agoLots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker did was fill out a form and say pretty please. I hope phone companies that allow this get sued.
- coding123 6y agoWhen they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.
- AnimalMuppet 6y agoIf I understand correctly, the initial telephone systems were run by manual operators at a physical switchboard, who could listen in to anything that was said on any line. Many people also had party lines, where someone (in another house or apartment) could pick up their phone and listen to your conversations. So, no, not much of an expectation of privacy - at least, there shouldn't have been.
- mgbmtl 6y agoIf there was no expectation of privacy, the police would not need a warrant to tap a line.
- edgyquant 6y agoWhen cell phones first became big, probably 10-15 years ago at least, there was a website for my area I lived in at the time (southern Illinois) that would list texts and people could vote on the funniest ones. There were some really private messages that would hit the top (obviously phone numbers weren’t displayed.) So it used to be people had the assumption that texts were public, because for some carriers they basically were.
- Mandatum 6y agoIn Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level of security seems to only be available to VIPs.
- lxgr 6y agoI think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).
- batiudrami 6y agoSIM swaps are relatively easy in Australia, requiring only some fairly simple social engineering of staff in a phone store. Number porting is trickier, requires a name and account number (or DOB in the case of a prepaid account) of the victim and they receive an SMS informing them their number was ported in advance.
- Mandatum 6y agoYeah getting thee account ID can be a pain, I've learned that the number in the UI and bill is not the identifier they want. Security by poor implementation.
- incompatible 6y agoI couldn't even get my own number ported in Australia (to a new provider on a new SIM). The old provider said the authentication failed. I gave up pretty quickly and just went with a new number.
- pabs3 6y ago
- angst_ridden 6y agoSo, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.
- pgsimp 6y agoAuthenticator Apps?
- angst_ridden 6y agoThe difficulty there is evaluating which ones are reliable, secure, and easy to use. I'd welcome recommendations.
- easton 6y agoThe integrated TOTP in 1Password is pretty good, it can grab the QR code off the screen and everything. https://support.1password.com/one-time-passwords/ https://support.1password.com/one-time-passwords/
- arsome 6y agoJust be careful with these solutions, I use the one in Bitwarden for a few things and while great for convenience, there's a significant security tradeoff when you go ahead and load all your TOTP tokens into memory on the same machine you keep the passwords on. Turns your 2 factor authentication into single factor pretty fast against even a decent piece of malware, let alone a dedicated attacker.
- slickdork 6y agoI personally use andOTP [0] which I'm a fan of. I've been thinking of switching to aegis [1] for nothing more than a UI change. [0]https://github.com/andOTP/andOTP https://github.com/andOTP/andOTP [1]https://github.com/beemdevelopment/Aegis https://github.com/beemdevelopment/Aegis
- intrasight 6y agoMy strategy is to have a second phone that has Authenticator and is also the phone for any SMS based 2FA. The phone is locked in a file cabinet when not in use and never leaves my desk. An extra phone only costs me $10/month. Well worth the peace of mind.
- markdown 6y agoYou have to pay a monthly fee to own a phone?
- culturestate 6y agoSince they said it's also a backup for SMS-based 2FA, I assume the monthly fee covers the SIM and not the phone.
- f430 6y agookay so how did he manage to pull this off and is this still possible? how would you protect yourself against this attack (i dont understand how it works)
- balls187 6y agoThe details are in the article, but essentially the attacker used a 3rd party bulk SMS service that allows it's users to use their own number and routes sms messages to said service provider. The attacker instead used the cell number of the author of the article, and supplied a fraudulent letter authorizing the re-routing of text messages through the bulk SMS service. The attacker works for a service, which purports to verify the routing and carrier settings for a given mobile phone number; I expect that their solution periodically checks the results and issues an alert if the results differ from a known valid value.
- f430 6y agoand there are no checks and bounds on their side??? no regulations?
- balls187 6y agoNot really; that is the crux of the problem. The article goes into detail; it's worth the read to answer your questions. From my experience, there is very little process and oversight being followed. I had my number ported over (with my knowledge) to Tmobile by a 3rd party, however Tmobile had not attempted to verify my consent. The store associate took this person at her word. My then current phone stopping working caught me by surprise. I can imagine if I signed up for a family plan, any store associate would be happy to move any number of phone numbers into my control.
- plank_time 6y agoCan they do this with a Google Voice phone number? I always hate hearing how I’m basically surviving hacks because of obscurity.
- TwoBit 6y agoIt would be useful to understand the flow of an SMS from a source to a Google voice number. While you can't port a Google voice number, it seems like if you can intercept an SMS from a source before it gets to Google then this technique will work. A useful strategy to help against this in any case is to use a different email address for every online service. Hackers generally can't initiate an account password reset if they don't know the account. Also if you use a different phone number for account security than your public one then it's a lot harder for them to know what SMS to intercept. Security by obscurity sucks but in this world it may be your only practical choice.
- techsupporter 6y ago> While you can't port a Google voice number You absolutely can port a Google Voice number. End-user subscriber numbers must be portable per FCC rules. Google, operating services provided by Bandwidth.com (mentioned in the article), does enable port-protection by default but this is easy to bypass by an operator who, like in the article, checks the box that says something like "I have a valid written LOA, complete the port as an exception." This has legitimate uses (some losing providers are very ruthless about not following the rules and letting customers move numbers) but unscrupulous or lazy operators will check the box and move on.
- techsupporter 6y agoYes. There's nothing special about a mobile phone number when it comes to SMS delivery. The underlying infrastructure company given in the article, Bandwidth, provides phone number provisioning and bulk service for Google's Voice product. On-net (one number hosted by Bandwidth to another number hosted by Bandwidth) might be slightly more of a hurdle to intercept or redirect but off-net is fairly trivial. Heck, even with "port lock" enabled on a Google Voice number, that is the barest of security against an attacker who has any kind of access better than "retail store employee." Working for a telco with access to our back-end port system, access several other people had, I could forcibly acquire a number by simply checking a box that said I had verified a written LOA even if the losing carrier responded with code 6P ("port-out protection enabled"). So, yes, you're likely sitting in a security-by-obscurity, or at least security-by-slightly-more-difficult-than-someone-else, situation.
- naebother 6y ago> While adding a number, Sakari provides the Letter of Authorization for the user to sign. Sakari's LOA says that the user should not conduct any unlawful, harassing, or inappropriate behaviour with the text messaging service and phone number. But as Lucky225 showed, a user can just sign up with someone else's number and receive their text messages instead. Um, what?!
- meibo 6y agoSo this means that the only protection from attacks like this is the law, and not a technical or operational hurdle like going through an AT&T hotline to get sim swapping going. This is bad news because following the law isn't a top priority when trying to hack someone.
- trashface 6y agoFCC obviously needs to come down on this like a ton of bricks.
- deleted 6y ago[deleted]
- wyqydsyq 6y agoWhat I would find really interesting is if someone used this exploit to hack into the accounts of Sakari staff and sabotaged their service, deleting all their infrastructure from their cloud hosting provider etc. I'm sure Sakari would take this security hole more seriously if their own C-suite fell victim to it.
- jfrunyon 6y agoReminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)
- fckthisguy 6y agoI completely agree. SMS 2FA is, at best, just adding a little hassle for the hacker. If it's not a targeted attack, there's a chance that the extra effort means they'll move on, but that won't stop any remotely determined hacker.
- anaganisk 6y agoAnd isn't that true for most of the people? Still better than nothing right?
- danmur 6y agoI'm not sure it's better, at least not in all cases. If you can reset your password or login without password using SMS, and you had a strong password, it could be worse.
- bsid 6y agothat would be a veryy incorrect implementation of 2FA. Wouldn't be surprised if some service works that way, but would def. be unfortunate
- efreak 6y agoSome services work in exactly this way; it's like using a magic link to log you into a website in the browser from an app on your phone/computer.
- path411 6y ago
- neo2006 6y agoBased on the high level description given in the article it seems to be related to enum lookup or net number. It's basically a kind of DnS lookup for phone numbers used for sms routing. Also this is used for routing sms that are belonging to a user to an application (in case you want to reroute your sms to an application). The company will change the enum code for the number to a.code that belong to the company and reroute the messages to its services. So the hack is not really a hack in a sense that it work as intendant, the safety net is missing though. The company operating the enum is supposed to check the legitimacy of the change.
- supermatt 6y agoIt’s insane that providers can do this. I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc. Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s their reasoning: https://www.nist.gov/blogs/cybersecurity-insights/questionsand-buzz-surrounding-draft-nist-special-publication-800-63-3 https://www.nist.gov/blogs/cybersecurity-insights/questionsa...
- camkego 6y agoIs there any chance my cellphone number is a VOIP-routable nubmer? Is there a way I can check to find out?
- supermatt 6y agoTwilio has a (US-only) API for this: https://www.twilio.com/docs/lookup/tutorials/carrier-and-caller-name https://www.twilio.com/docs/lookup/tutorials/carrier-and-cal... Im not sure what banks use, but I have had UK VOIP numbers flagged before when trying to register them for 2FA, so theres likely API providers for other countries.
- aidenn0 6y agoMeanwhile my bank just added 2FA in the past year and it's... SMS. No option to use TOTP or U2F.
- wealthyyy 6y agoYes, this is only for VOIP. The author of article is dishonest. He mentioned that his TMobile phone number got hacked but I am willing to bet that this is a marketing .. .
- supermatt 6y agoFurther reading suggests this isn’t just voip numbers! How worrying!
- Jan454 6y agoSo how to disable the possibility to switch to SMS-Authentication as alternative 2nd token on my Google-Login?
- matijs 6y agoRemove your phone number from your account.
- nozx 6y agoThe problem is that user does'nt own his own phone number
- GameOfKnowing 6y agoI’ll sell all my texts for $15.
- NiceWayToDoIT 6y agoIsn't this easy solvable with additional SMS token approval as mentioned in article? > "orsman added that, effective immediately, Sakari has added a security feature where a number will receive an automated call that requires the user to send a security code back to the company, to confirm they do have consent to transfer that number. As part of another test, Lucky225 did try to reroute texts for the same number with consent using a different service called *Beetexting*; the site already required a similar automated phone call to confirm the user's consent. This was in part "to avoid fraud," the automated verification call said when Motherboard received the call. Beetexting did not respond to a request for comment." But it seems that the entire system is globally infested with security holes. Is this applicable worldwide or just limited to one country ?
- fatnoah 6y agoSakari just was dumb, and deserves the bad press. I've built similar products and we launched with the "phone call to verify" feature to specifically prevent this type of abuse.
- NiceWayToDoIT 5y agoI agree
- fmajid 6y agoSMS is irredeemably broken, like all telco-designed garbage protocols. The only way you can incentivize companies to stop using it as security theater is to shift liability so any losses incurred by SMS jacking is automatically the liability of the company using SMS, just as nowadays any credit card fraud is borne by the company that is not using the EMV chip to secure a transaction.
- neo_neo 6y agoThese hackers have so much time in their hands , that they can understand this technology more than the creators and abuse them, amazing how hacker culture works.
- wealthyyy 6y agoDamn lies. Damn lies. The attack vector only works for VOIP or Toll Free Numbers. The upstream agreements already block Mobile numbers. This is paid marketing for his company.
- fatnoah 6y agoJust adding that landline numbers, not just toll-free numbers, are probably vulnerable to this.
- wealthyyy 6y agoYes, I forget to include it.
- fatnoah 6y agoI also place the blame on Sakari. I headed Engineering for a company that allowed you to bring your own landline number for business, and our automated flow for non-toll-free landline required receiving a code via telephone call (to avoid the situation of compromised SMS routing) and entering that as part of the signup process. For toll-free numbers, it was a manual process where we received written LOAs and verified ownership via the SMS/800 database (ironically, SMS here has nothing to do with messaging and is purely coincidental).
- meowface 6y agoNot sure why this isn't higher up. This is crucial information showing this is FUD. There are still grave vulnerabilities in mobile provider SMS (2FA or otherwise) due to how easy it is for a dedicated attacker to SIM swap, but this particular claim is completely misleading.
- dataflow 6y ago> Not sure why this isn't higher up. This is crucial information showing this is FUD. It's already too high up given it's a blatantly baseless accusation. I'm confused why you think it's more credible than the article when it provides zero evidence.
- kwhitefoot 6y agoHe can have all mine for a tenner! How do I contact him?
- CRConrad 6y agoWeird. The whole idea behind the whole company is to send SMSes on behalf of its customers, if I understood the article correctly. So why would they need to muck about with reassigning the phone numbers of SMS recipients in the first place?
- e-clinton 6y agoThat’s crazy that there is no verification system in place allowing the user to approve the forwarding. Years ago I asked my carrier to not port or forward without me being physically present at a store. Maybe I should test them out to see if that’s still the case. Regardless, I don’t use SMS MFA for anything important and even when I do, I have a 32 character password to go along with it.