Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID.

I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself out of my own Gmail account. I guess apps like Authy as mentioned in the other comments are an alternative. In any case I guess there are (or should be) some special codes you can write down in case you lose access to your second-factor info.



> I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself out of my own Gmail account. I guess apps like Authy as mentioned in the other comments are an alternative. In any case I guess there are (or should be) some special codes you can write down in case you lose access to your second-factor info.

All systems/services I have seen that allow 2FA through a hardware device like a Yubikey also provide you a set of several recovery codes that you need to note down somewhere safe so that you can use those if your device fails or is lost. Some systems/services also force you to first setup a TOTP based authentication (with an app like OTP Auth/Authy) and then proceed with setting up additional hardware based 2FA. Unless you lose access to your recovery codes, which is the same as losing your password on a system with no 2FA, you should be fine (though I do get the concern here). People also get two hardware keys and set them up for the same platforms/services, keeping one in a safe place for future use in case the first one that's regularly used gets lost or breaks.


AFAIK there is a feature in WhatsApp Settings that tells you whenever a contact in an ongoing conversation changes their device.

So no protection, but a notification.

https://faq.whatsapp.com/en/android/28030014/?category=52452...


You can (should?) protect the verification step with a pin:

https://faq.whatsapp.com/general/26000021/?category=5245245

You can do the same in Signal.


> Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations.

source? There is lot of wrong with our authorities but I really really doubt about what you just said. I mean the way you have written it is giving wrong impression that authorities can clone any sim at their whim just like china or other authoritarian government.


eavesdrop ? the WhatsApp I use agrees to work only on one phone, if yo move it it stops working on the original.


Is that not per-phone number? The cloned SIM would have the same one


WhatsApp accounts can only be used from one device simultaneously.


Is that allowed by the network? Can 2 devices share one number?


but then the original owner will be notified about that while eavesdropping is "secretly listen to a conversation"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: