SCARY Mobile Hack will Change how we Use Phones

  Рет қаралды 35,947

All Things Secured

All Things Secured

Күн бұрын

Пікірлер: 77
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
If you watched to the end, which privacy camp do you self-select into? Leave a comment to let me know. Thanks for watching!
@clanholmes
@clanholmes 3 ай бұрын
I am not sure if you can do this. But you should interview Ron Diebert. He is the citizen lab at the University of Toronto and was part of the group that helped Dalai Lama after he was hacked. He has a booking coming soon, so he might be willing to some interviews.
@concernedrn2844
@concernedrn2844 3 ай бұрын
is google voice encrypted? since it is a voip, is it more secure than the cellular sms?
@EIRE55
@EIRE55 3 ай бұрын
I only use a dumb phone for 2FA codes.
@gelbphoenix
@gelbphoenix 3 ай бұрын
@@concernedrn2844 Google Voice apparently also uses SS7 when using 2G or 3G.
@DavidDLee
@DavidDLee 3 ай бұрын
TL;DR nothing to do for now. Most banks I use have text 2nd factor as the only option.
@graysonpeddie
@graysonpeddie 3 ай бұрын
Yup. Bank of America doesn't care for allowing 2FA applications...
@asadosan6934
@asadosan6934 Ай бұрын
That's the thing, in my country attacks like these has been happening and its fairly successful. They would pose as an E-wallet sms. Since you already have older messages from that E-wallet you'd think your safe when clicking their links cause they often do this, and yes they would also use the same phone number as the e wallet or even the ISP, meaning you can't send them messages cause your phone won't allow you, You click the link it opens the E-wallet app, it bypasses all the security features, transfers all your fund to a different account, what's crazy is that it bypasses the maximum transfer limit per transaction and per day, E-wallets are refusing to pay despite its their fault for having weak security
@WilliamBillWilson
@WilliamBillWilson 3 ай бұрын
I seem to recall a U.S. Supreme Court case from a few decades ago where they referred to cell phones as basically radios. Which, of course, they are--they just use a different part of the electromagnetic spectrum and are more sophisticated than the walkie-talkies some of us had as kids. I'm not going to change anything I'm doing, but I'm glad to know about this vulnerability. I'm also glad I'm not someone who is a juicy target (or, at least I wasn't until I left this comment). Thanks for the great explanation and context!
@ImPipkinrick
@ImPipkinrick 3 ай бұрын
Do VOIP numbers like Google Voice get affected too?
@fernandosorrilha
@fernandosorrilha 3 ай бұрын
Yes, because any phone number use SS7 Network
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Yes, they still use SS7.
@sergetheijspartner2005
@sergetheijspartner2005 3 ай бұрын
So for nearly 50 years we are using this unsecure SS7? And no one came up with SS8, SS9....yet, as in being more secure with every iteration i mean? Why not? Is it so hard to replace? Not backwards compatible with existing phones? Not allowed buy security agencies worldwide (CIA, Mossad, DGSE, MSS, MI6....to name but a few )? I mean you do know that the one that comes up with a higher security protocol will dominate the cellphone market but also get Eppsteined or Mcafeed like really fast...
@OH2023-cj9if
@OH2023-cj9if 2 ай бұрын
The problem you identified is that people working for mobile phone companies have been careless. SS7 data can be accessed by anyone. UK banks insist on text messages to verify and the only way to beat this SS7 problem is to use voIP.
@rpm3605
@rpm3605 3 ай бұрын
Josh, I’d like use one of the alternative MFA schemes but none of them is as ubiquitous as using a text or email for receiving an authication code. Have to use multiple solutions is as big a pain as trying to keep up with password management, if not bigger. IMHO anyway.
@vadnegru
@vadnegru 3 ай бұрын
Some password managers also have 2fa built-in. This makes them not so 2f but it's neat to use
@xileets
@xileets 3 ай бұрын
Everyone MUST also remember, the weakest MFA/2FA option that is *active* for auth is the maximum strength of your login security.
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Great point. Although that wouldn't really help in an SS7 attack.
@timeisnow33
@timeisnow33 3 ай бұрын
Josh. Your link to fb2 key doesn't work. Please update it.
@illwittd
@illwittd 3 ай бұрын
Would love to see a review vid on the Above Phone if you end up using it for a long enough period
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Maybe so. We’ll see.
@synthwave7
@synthwave7 3 ай бұрын
Email - created first in 1971 and still used today has a lot of security isuses - these old technologie are great, but needs a total rewrite from ground up to be secure for today's world.
@vadnegru
@vadnegru 3 ай бұрын
At least email could be signed to avoid forgery
@Jensen-James-Productions
@Jensen-James-Productions 3 ай бұрын
hey josh! thanks for the real captions! i appreciate it!
@aperson1181
@aperson1181 3 ай бұрын
I never do any business on a phone, as in no banking, I have a flip phone so no malware attacks and where possible (banks) I do give only Google Voice. MAny banks do not want VOIP numbers and restrict, so I tell them this is all I have and they either hand up nad then call back on my registered number, or send emails or ask security questions. NO Sim swaps for me are even possible.
@lussor1
@lussor1 3 ай бұрын
Banks still using SMS for 2FA 😭
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Sadly, they do.
@TomO-nx1bd
@TomO-nx1bd 2 ай бұрын
Yes it's stupid they still use weak SMS. And to make things worse, I have never understood about 2FA is what good is it, if for account recovery ("forgot my password" option) many of them only send a code to your recovery phone and then you can reset the password. This means hackers don't even need to break through both layers of 2FA if they can just go straight for the "forgot my password" option and concentrate all their attention on getting your SIM swapped to break in.
@JRScaggs
@JRScaggs 3 ай бұрын
I work in the telecom industry. The best solution to avoid Signaling System 7 (SS7) risk is to sunset 2G and 3G and only support 4G and 5G. The latest standard, 5G, has the best encryption to help maintain privacy. Later in the video, Josh points out that being seen as a mobile provider is difficult, so the average bear cannot easily do SS7 attacks.
@MyaHartLuv
@MyaHartLuv 3 ай бұрын
You’d be surprised at just how “average” these attackers are- easily any neighbor with a false narrative against a target
@Freyja-f7m
@Freyja-f7m 2 ай бұрын
​@@MyaHartLuv requires a bit of equipment. Slightly costly, but not hard. There was a set up in the building next door to me for a number of years. Made my life.... interesting I suppose.
@Freyja-f7m
@Freyja-f7m 2 ай бұрын
5G has distance limitations in a big way. In urban areas it's great.
@palles1972
@palles1972 3 ай бұрын
When you sign up for some counter service, you must give you a phone number away and you don’t have other kind of meanings
@Blaise1-
@Blaise1- 2 ай бұрын
How do you protect your network then 🤔
@natalie6117
@natalie6117 2 ай бұрын
Is an eSIM or physical SIM more secure /less likely to be SIM swapped? Here I am holding onto my old phone with a physical SIM, thinking it was somehow more secure than an eSIM, but turns out I might be totally wrong. Any insight for me there Josh?
@kiriup8188
@kiriup8188 3 ай бұрын
So can this be used silently on someone without them knowing or is there a way to check/know of you are a victim of this attack? I guess what im asking is how do I know this hasnt already happened to me and someone out there isnt already intercepting and collecting all my data?
@rompis.a
@rompis.a 3 ай бұрын
The demo done on Veritasium shows that when a call gets intercepted, there will be no sign of it on the victim's end. The only way for the victim to find out is when they talk with the caller afterwards.
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
It can be done silently, but as I said in this video, unless you are a high-value target and the person tracking you has a lot of technical expertise and money, the chances of you being the victim of an SS7 attack are very, very, VERY small.
@MyaHartLuv
@MyaHartLuv 3 ай бұрын
The Securities Industry has deep pockets and endless foot soldiers. The targeting is more prevalent than one might think. Electronic harassment is a growing epidemic because its becoming easier by the day.
@polymatrix
@polymatrix 3 ай бұрын
I watched the entireveritasium video, but I'm not clear if a data-only cellular plan (where you don't have a phone number) would be subject to the attack. I want to say "no" as this is exploiting an authorization/tracking mechanism for the phone number, but I'm not sure if it's actually looking for the exact phone number or the SIM the phone is authorized on.
@rompis.a
@rompis.a 3 ай бұрын
Data-only plan would stop your calls and SMS messages getting intercepted, but it won't save you from other SS7-related spying. Veritasium video mentioned, for example, about finding out your location by triangulating the cell towers around you.
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Yes, because you're still using a SIM/eSIM for the data-only plans. So there's still tracking involved. As said in another comment, though, it would keep your calls and SMS from being intercepted.
@concernedrn2844
@concernedrn2844 3 ай бұрын
is google voice encrypted? since it is a voip, is it more secure than the cellular sms?
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
The SMS texts aren't encrypted as far as I know. Not sure about the voice.
@TheJDSmith
@TheJDSmith 3 ай бұрын
What using FaceTime Audio over standard mobile and iMessage over sms?
@a9503128
@a9503128 3 ай бұрын
Because US telcos are 10years behind, if your telco is communicating with you in-band then you need to explain why you’re leaving them.
@1TechCritic
@1TechCritic 3 ай бұрын
Except it’s every carrier. Not just US. Or did you just not bother watching lol.
@a9503128
@a9503128 3 ай бұрын
@@1TechCritic not every carrier, in the developed word SS7 and MMS are for phone calls and cat pictures from your gran
@ThisIsLiam-m6j
@ThisIsLiam-m6j 3 ай бұрын
@@a9503128 You're mistaken. While 5G does not use SS7, your car's emergency button may rely on 2G, which does use SS7. Additionally, outside of the US, 5G coverage in the EU is not universal, and in areas with poor connectivity, 3G or 2G networks will still operate using SS7.
@charlesdoesmore5488
@charlesdoesmore5488 3 ай бұрын
So here the choice: Either keep this hack happening in the world, or make carrier to force a planned obsolescence on tech.
@JSATI
@JSATI 3 ай бұрын
Not specific to this video however if you are using virtual card services such as privacy or clutch can you start using these services while having a credit freeze already in place?
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Yes, most of the virtual cards don't do a credit pull to get started.
@MarceloMazza
@MarceloMazza Ай бұрын
so? we are doomed on the cloud - to be really secure you must be completely offline
@tubeDude48
@tubeDude48 3 ай бұрын
Your *2FA* link is dead!
@cottagekeeper
@cottagekeeper 3 ай бұрын
Completely freaked out! Now I know why a certain person always knows everything. How much do I have to spend to fix this?
@rompis.a
@rompis.a 3 ай бұрын
Convince all phone providers (not just yours) to move away from SS7.
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Just move to a new private number that this certain person doesn't know.
@Nobleflex101
@Nobleflex101 3 ай бұрын
Brilliant 👏
@tails300
@tails300 3 ай бұрын
Is this the reason that why 2g and 3g networks are getting shutdown.
@vadnegru
@vadnegru 3 ай бұрын
No, it's just to free up space for 5G
@bine35
@bine35 3 ай бұрын
Is a PIN/PUK code on the SIM sufficient or no?
@Miranox2
@Miranox2 3 ай бұрын
Nope.
@dumbdee4
@dumbdee4 3 ай бұрын
@@Miranox2 Yep
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
No, that's just to protect against SIM swaps. An SS7 attack is different.
@happyzahn8031
@happyzahn8031 2 ай бұрын
what is wrong with a one-time authentication code texted to you? unless someone is actively watching your on-line interaction or monitoring your phone call, shouldn't matter. i have enough trouble getting the code and typing it in, let alone something else.
@kemarchristie6050
@kemarchristie6050 3 ай бұрын
Efani the sim company eliminates this but its like 999$ usd per year for this service. oh you mentioned it I commented at the start
@AllThingsSecured
@AllThingsSecured 3 ай бұрын
Yea, believe it or not, that's actually a reasonable charge based on other competition that is $130/mo +. It just depends on your threat model.
@kemarchristie6050
@kemarchristie6050 3 ай бұрын
@@AllThingsSecured yea depends on the person. CEOS For large companies and mid sized companies definitely need this. Government officials etc since they are highly targeted.
@MyaHartLuv
@MyaHartLuv 3 ай бұрын
Great channel! I had 3 months of peace with my new carrier, number and device- then a cyber attack so hard my only phone crashed. I was completely locked out. So I went back to the flip phone for calls and text and the smart phone for net with calls and text completely disabled at the carrier level. Im looking forward to Efani!! TYSMUCH
@CRK1918
@CRK1918 3 ай бұрын
4g and 5g are more secure? Doing the test, the video doesn't mention what Linus is using...
@gelbphoenix
@gelbphoenix 3 ай бұрын
4G and 5G aren't using SS7 but could be also vulnerable. Especially 4G is more vulnerable because it has a higher compatibility with 3G.
@lopar4ever
@lopar4ever 2 ай бұрын
I've always been a bit jealous of people who can speak to a wide audience in a way that is understood and listened to. I spend half my life saying the same things as you and people just twiddle their thumbs. But when a KZbin video comes out, like BOOM, look what intelligent, correct, rational things this person is saying. Thank you for bringing these thoughts to people.
@chocolate_squiggle
@chocolate_squiggle Ай бұрын
Alarmist clickbait.
@Austin-ub2gi
@Austin-ub2gi 9 күн бұрын
Wrong
@OrlandoLetra
@OrlandoLetra 3 ай бұрын
efani works in Europe?
I QUIT Online Privacy. This is why.
8:26
All Things Secured
Рет қаралды 29 М.
My Device was Compromised...Here's What I Did
6:47
All Things Secured
Рет қаралды 25 М.
УНО Реверс в Амонг Ас : игра на выбывание
0:19
Фани Хани
Рет қаралды 1,3 МЛН
SLIDE #shortssprintbrasil
0:31
Natan por Aí
Рет қаралды 49 МЛН
She wanted to set me up #shorts by Tsuriki Show
0:56
Tsuriki Show
Рет қаралды 8 МЛН
Block Phone Tracking
14:31
Naomi Brockwell TV
Рет қаралды 138 М.
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 1 МЛН
SIM Swapping EXPLAINED (+ how YOU can easily avoid it)
8:57
All Things Secured
Рет қаралды 379 М.
STOP Using Proton & Signal? Here’s the TRUTH
7:54
All Things Secured
Рет қаралды 338 М.
How to Build Internet Privacy with Pseudonyms
7:39
All Things Secured
Рет қаралды 28 М.
The MOST private browser
8:14
Naomi Brockwell TV
Рет қаралды 960 М.
His CRAZY Story is a THREAT to Privacy Everywhere
5:55
All Things Secured
Рет қаралды 21 М.
SS7 ATTACK AND ITS IMPACTS | All It Takes Is Your Phone Number
16:01