SS7 is vulnerable to attack. However, the types off attacks on the video don’t affect Signal as it requires a pin. (Make sure you set your pin to something strong and secure)

1 point

PSA: if your financial institution/government/<other website> is using SMS codes (aka PSTN MFA) for multi-factor authentication they are practically worthless against a determined attacker who can use SIM swap or an SS7 attack to obtain the code. Basically you are secured by a single factor, your password. If your password is compromised it may be sold via black hat marketplaces and purchased by an attacker who would then likely attempt to break that second factor.

The best way to protect yourself is to use a unique password; a password manager especially helps with this. Sometimes institutions will offer “Authenticator” (TOTP) as a second factor, or PassKey authentication, both secure alternatives to SMS codes.

Here in Aus I’m working with Electronic Frontiers Australia to try and force some change within government and financial institutions (via the financial regulator). Most banks here use SMS codes and occasionally offer a proprietary app. One of the well-known international banks, ING Bank, even uses a 4 pin code to login to their online banking portal. 😖

Unfortunately SMS codes are a legacy left from old technology and a lack of understanding or resourcing by organisations that implement it. Authenticator/TOTP tokens have been around for 16 years (and standardised for 13 years), and PassKeys are relatively newer. There is a learning curve but at the very least every organisation should at least provide either TOTP or PassKeys as an option for security-minded users.

permalink
report
reply
2 points
*

He says nothing about the PIN, so I don’t think that is what protects Signal as OP writes. It simply doesn’t rely on SS7.

You only type your PIN into Signal about once a month.

permalink
report
reply
2 points

I found it confusing. Did he explain how the IMSI number is obtained?

Towards the end he said there was a special “interrogation” command that would reveal the IMSI but that loophole is now closed.

permalink
report
reply
-6 points

Can everyone please stop linking to Linus? He’s a YouTube huckster.

permalink
report
reply
14 points

For one this isn’t a video by LTT.

Secondly not everyone hates LTT like you do

permalink
report
parent
reply
-1 points

Would GrapheneOS with default settings be immune since 2G is disabled and networks don’t have 3G anymore?

permalink
report
reply
6 points

No as ss7 is still widely used for compatibility

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 4.8K

    Monthly active users

  • 1.6K

    Posts

  • 23K

    Comments