Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.


Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...


Seriously who designed a system that habituates people to giving out 2fa codes over the phone?? That's explicitly a weakness of the 2fa system, nobody should ever read out or forward their 2fa code.


In this case it sounds like the user is calling ETrade, so unless the user calls a wrong number that just so happens to be a hacker it's unlikely this would be an issue.


Actually, that is a very common trick that scammers have used and still do. In the past they would buy Google ads or do some black hat SEO to get their fake number to the top of search engines.

Then, people searching for things like "Microsoft tech support" would get the scammers number and call it. Google and other search engines will even pull that number from your site and handily present it to you at the top of the search results to make it appear even more legit.

Taking over unclaimed Google map listings for businesses is also really common.

Simply buying a toll free number that is close to the customer service number for a large company is bound to get you more inbound callers than you care to scam.

So no, absolutely no excuses for teaching people to share their 2fa codes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: