If you watched to the end, which privacy camp do you self-select into? Leave a comment to let me know. Thanks for watching!
@clanholmes3 ай бұрын
I am not sure if you can do this. But you should interview Ron Diebert. He is the citizen lab at the University of Toronto and was part of the group that helped Dalai Lama after he was hacked. He has a booking coming soon, so he might be willing to some interviews.
@concernedrn28443 ай бұрын
is google voice encrypted? since it is a voip, is it more secure than the cellular sms?
@EIRE553 ай бұрын
I only use a dumb phone for 2FA codes.
@gelbphoenix3 ай бұрын
@@concernedrn2844 Google Voice apparently also uses SS7 when using 2G or 3G.
@DavidDLee3 ай бұрын
TL;DR nothing to do for now. Most banks I use have text 2nd factor as the only option.
@graysonpeddie3 ай бұрын
Yup. Bank of America doesn't care for allowing 2FA applications...
@asadosan6934Ай бұрын
That's the thing, in my country attacks like these has been happening and its fairly successful. They would pose as an E-wallet sms. Since you already have older messages from that E-wallet you'd think your safe when clicking their links cause they often do this, and yes they would also use the same phone number as the e wallet or even the ISP, meaning you can't send them messages cause your phone won't allow you, You click the link it opens the E-wallet app, it bypasses all the security features, transfers all your fund to a different account, what's crazy is that it bypasses the maximum transfer limit per transaction and per day, E-wallets are refusing to pay despite its their fault for having weak security
@WilliamBillWilson3 ай бұрын
I seem to recall a U.S. Supreme Court case from a few decades ago where they referred to cell phones as basically radios. Which, of course, they are--they just use a different part of the electromagnetic spectrum and are more sophisticated than the walkie-talkies some of us had as kids. I'm not going to change anything I'm doing, but I'm glad to know about this vulnerability. I'm also glad I'm not someone who is a juicy target (or, at least I wasn't until I left this comment). Thanks for the great explanation and context!
@ImPipkinrick3 ай бұрын
Do VOIP numbers like Google Voice get affected too?
@fernandosorrilha3 ай бұрын
Yes, because any phone number use SS7 Network
@AllThingsSecured3 ай бұрын
Yes, they still use SS7.
@sergetheijspartner20053 ай бұрын
So for nearly 50 years we are using this unsecure SS7? And no one came up with SS8, SS9....yet, as in being more secure with every iteration i mean? Why not? Is it so hard to replace? Not backwards compatible with existing phones? Not allowed buy security agencies worldwide (CIA, Mossad, DGSE, MSS, MI6....to name but a few )? I mean you do know that the one that comes up with a higher security protocol will dominate the cellphone market but also get Eppsteined or Mcafeed like really fast...
@OH2023-cj9if2 ай бұрын
The problem you identified is that people working for mobile phone companies have been careless. SS7 data can be accessed by anyone. UK banks insist on text messages to verify and the only way to beat this SS7 problem is to use voIP.
@rpm36053 ай бұрын
Josh, I’d like use one of the alternative MFA schemes but none of them is as ubiquitous as using a text or email for receiving an authication code. Have to use multiple solutions is as big a pain as trying to keep up with password management, if not bigger. IMHO anyway.
@vadnegru3 ай бұрын
Some password managers also have 2fa built-in. This makes them not so 2f but it's neat to use
@xileets3 ай бұрын
Everyone MUST also remember, the weakest MFA/2FA option that is *active* for auth is the maximum strength of your login security.
@AllThingsSecured3 ай бұрын
Great point. Although that wouldn't really help in an SS7 attack.
@timeisnow333 ай бұрын
Josh. Your link to fb2 key doesn't work. Please update it.
@illwittd3 ай бұрын
Would love to see a review vid on the Above Phone if you end up using it for a long enough period
@AllThingsSecured3 ай бұрын
Maybe so. We’ll see.
@synthwave73 ай бұрын
Email - created first in 1971 and still used today has a lot of security isuses - these old technologie are great, but needs a total rewrite from ground up to be secure for today's world.
@vadnegru3 ай бұрын
At least email could be signed to avoid forgery
@Jensen-James-Productions3 ай бұрын
hey josh! thanks for the real captions! i appreciate it!
@aperson11813 ай бұрын
I never do any business on a phone, as in no banking, I have a flip phone so no malware attacks and where possible (banks) I do give only Google Voice. MAny banks do not want VOIP numbers and restrict, so I tell them this is all I have and they either hand up nad then call back on my registered number, or send emails or ask security questions. NO Sim swaps for me are even possible.
@lussor13 ай бұрын
Banks still using SMS for 2FA 😭
@AllThingsSecured3 ай бұрын
Sadly, they do.
@TomO-nx1bd2 ай бұрын
Yes it's stupid they still use weak SMS. And to make things worse, I have never understood about 2FA is what good is it, if for account recovery ("forgot my password" option) many of them only send a code to your recovery phone and then you can reset the password. This means hackers don't even need to break through both layers of 2FA if they can just go straight for the "forgot my password" option and concentrate all their attention on getting your SIM swapped to break in.
@JRScaggs3 ай бұрын
I work in the telecom industry. The best solution to avoid Signaling System 7 (SS7) risk is to sunset 2G and 3G and only support 4G and 5G. The latest standard, 5G, has the best encryption to help maintain privacy. Later in the video, Josh points out that being seen as a mobile provider is difficult, so the average bear cannot easily do SS7 attacks.
@MyaHartLuv3 ай бұрын
You’d be surprised at just how “average” these attackers are- easily any neighbor with a false narrative against a target
@Freyja-f7m2 ай бұрын
@@MyaHartLuv requires a bit of equipment. Slightly costly, but not hard. There was a set up in the building next door to me for a number of years. Made my life.... interesting I suppose.
@Freyja-f7m2 ай бұрын
5G has distance limitations in a big way. In urban areas it's great.
@palles19723 ай бұрын
When you sign up for some counter service, you must give you a phone number away and you don’t have other kind of meanings
@Blaise1-2 ай бұрын
How do you protect your network then 🤔
@natalie61172 ай бұрын
Is an eSIM or physical SIM more secure /less likely to be SIM swapped? Here I am holding onto my old phone with a physical SIM, thinking it was somehow more secure than an eSIM, but turns out I might be totally wrong. Any insight for me there Josh?
@kiriup81883 ай бұрын
So can this be used silently on someone without them knowing or is there a way to check/know of you are a victim of this attack? I guess what im asking is how do I know this hasnt already happened to me and someone out there isnt already intercepting and collecting all my data?
@rompis.a3 ай бұрын
The demo done on Veritasium shows that when a call gets intercepted, there will be no sign of it on the victim's end. The only way for the victim to find out is when they talk with the caller afterwards.
@AllThingsSecured3 ай бұрын
It can be done silently, but as I said in this video, unless you are a high-value target and the person tracking you has a lot of technical expertise and money, the chances of you being the victim of an SS7 attack are very, very, VERY small.
@MyaHartLuv3 ай бұрын
The Securities Industry has deep pockets and endless foot soldiers. The targeting is more prevalent than one might think. Electronic harassment is a growing epidemic because its becoming easier by the day.
@polymatrix3 ай бұрын
I watched the entireveritasium video, but I'm not clear if a data-only cellular plan (where you don't have a phone number) would be subject to the attack. I want to say "no" as this is exploiting an authorization/tracking mechanism for the phone number, but I'm not sure if it's actually looking for the exact phone number or the SIM the phone is authorized on.
@rompis.a3 ай бұрын
Data-only plan would stop your calls and SMS messages getting intercepted, but it won't save you from other SS7-related spying. Veritasium video mentioned, for example, about finding out your location by triangulating the cell towers around you.
@AllThingsSecured3 ай бұрын
Yes, because you're still using a SIM/eSIM for the data-only plans. So there's still tracking involved. As said in another comment, though, it would keep your calls and SMS from being intercepted.
@concernedrn28443 ай бұрын
is google voice encrypted? since it is a voip, is it more secure than the cellular sms?
@AllThingsSecured3 ай бұрын
The SMS texts aren't encrypted as far as I know. Not sure about the voice.
@TheJDSmith3 ай бұрын
What using FaceTime Audio over standard mobile and iMessage over sms?
@a95031283 ай бұрын
Because US telcos are 10years behind, if your telco is communicating with you in-band then you need to explain why you’re leaving them.
@1TechCritic3 ай бұрын
Except it’s every carrier. Not just US. Or did you just not bother watching lol.
@a95031283 ай бұрын
@@1TechCritic not every carrier, in the developed word SS7 and MMS are for phone calls and cat pictures from your gran
@ThisIsLiam-m6j3 ай бұрын
@@a9503128 You're mistaken. While 5G does not use SS7, your car's emergency button may rely on 2G, which does use SS7. Additionally, outside of the US, 5G coverage in the EU is not universal, and in areas with poor connectivity, 3G or 2G networks will still operate using SS7.
@charlesdoesmore54883 ай бұрын
So here the choice: Either keep this hack happening in the world, or make carrier to force a planned obsolescence on tech.
@JSATI3 ай бұрын
Not specific to this video however if you are using virtual card services such as privacy or clutch can you start using these services while having a credit freeze already in place?
@AllThingsSecured3 ай бұрын
Yes, most of the virtual cards don't do a credit pull to get started.
@MarceloMazzaАй бұрын
so? we are doomed on the cloud - to be really secure you must be completely offline
@tubeDude483 ай бұрын
Your *2FA* link is dead!
@cottagekeeper3 ай бұрын
Completely freaked out! Now I know why a certain person always knows everything. How much do I have to spend to fix this?
@rompis.a3 ай бұрын
Convince all phone providers (not just yours) to move away from SS7.
@AllThingsSecured3 ай бұрын
Just move to a new private number that this certain person doesn't know.
@Nobleflex1013 ай бұрын
Brilliant 👏
@tails3003 ай бұрын
Is this the reason that why 2g and 3g networks are getting shutdown.
@vadnegru3 ай бұрын
No, it's just to free up space for 5G
@bine353 ай бұрын
Is a PIN/PUK code on the SIM sufficient or no?
@Miranox23 ай бұрын
Nope.
@dumbdee43 ай бұрын
@@Miranox2 Yep
@AllThingsSecured3 ай бұрын
No, that's just to protect against SIM swaps. An SS7 attack is different.
@happyzahn80312 ай бұрын
what is wrong with a one-time authentication code texted to you? unless someone is actively watching your on-line interaction or monitoring your phone call, shouldn't matter. i have enough trouble getting the code and typing it in, let alone something else.
@kemarchristie60503 ай бұрын
Efani the sim company eliminates this but its like 999$ usd per year for this service. oh you mentioned it I commented at the start
@AllThingsSecured3 ай бұрын
Yea, believe it or not, that's actually a reasonable charge based on other competition that is $130/mo +. It just depends on your threat model.
@kemarchristie60503 ай бұрын
@@AllThingsSecured yea depends on the person. CEOS For large companies and mid sized companies definitely need this. Government officials etc since they are highly targeted.
@MyaHartLuv3 ай бұрын
Great channel! I had 3 months of peace with my new carrier, number and device- then a cyber attack so hard my only phone crashed. I was completely locked out. So I went back to the flip phone for calls and text and the smart phone for net with calls and text completely disabled at the carrier level. Im looking forward to Efani!! TYSMUCH
@CRK19183 ай бұрын
4g and 5g are more secure? Doing the test, the video doesn't mention what Linus is using...
@gelbphoenix3 ай бұрын
4G and 5G aren't using SS7 but could be also vulnerable. Especially 4G is more vulnerable because it has a higher compatibility with 3G.
@lopar4ever2 ай бұрын
I've always been a bit jealous of people who can speak to a wide audience in a way that is understood and listened to. I spend half my life saying the same things as you and people just twiddle their thumbs. But when a KZbin video comes out, like BOOM, look what intelligent, correct, rational things this person is saying. Thank you for bringing these thoughts to people.