news.volyx.in

SMS phishing is way too easy (bejarano.io)

637 points by ricardbejarano · 1541 days ago · 294 comments on HN

Article summary

The article discusses the ease of SMS phishing due to the lack of verification in the sender ID field, which can be set by the sender to any arbitrary string. This allows malicious senders to impersonate legitimate senders, making it difficult for recipients to distinguish between real and fake messages. The article suggests that sender ID should be tied to the sender's phone number and that phones should warn users of non-verified sender IDs. Companies should also stop sending URLs over SMS to prevent phishing attacks.

Main themes

  • SMS phishing
  • sender ID verification
  • phone number porting
  • VoIP numbers
  • 2FA and verification
  • phone number security

What commenters say

  • Some countries have implemented protections against SMS phishing, but the US has not.
  • The use of shortcodes, which are more expensive and require vetting, can help prevent SMS phishing, but they are not foolproof.
  • Phone numbers are not a reliable form of identification and should not be used as the primary user identifier.
  • The process of porting a phone number to a VoIP provider can be complex and may lead to issues with receiving SMS messages.
  • Some services may block or flag VoIP numbers, making it difficult to use them for 2FA or other purposes.
  • The use of burner phone numbers or prepaid plans can also lead to issues with verification and 2FA.
  • There is a need for better protections against SMS phishing, including more robust verification and authentication methods.