News: 1707812830

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Meta says risk of account theft after phone number recycling isn't its problem to solve

(2024/02/13)


Meta has acknowledged that phone number reuse that allows takeovers of its accounts "is a concern," but the ad biz insists the issue doesn't qualify for its bug bounty program and is a matter for telecom companies to sort out.

The core problem is that telecom companies recycle phone numbers that have been abandoned after a brief waiting period – at least 45 days in the US. That can become a problem because many online services require a phone number to identify users and/or send one-time passwords for two-factor authentication. Users who abandon a number, and forget to update their new number, are therefore at risk of malicious account reset attempts by whoever gets access to their old numbers. Account takeovers are a common consequence.

This is not a new issue. In 2021, privacy researchers from Princeton University published a [1]report [PDF] on the topic titled, "Security and Privacy Risks of Number Recycling at Mobile Carriers in the United States."

[2]

The report found 171 of 259 sampled numbers "were tied to existing accounts at popular websites, potentially allowing those accounts to be hijacked." It also found that 100 of those 259 were linked to leaked login credentials that would make it easier to defeat SMS-based multi-factor authentication.

[3]

[4]

The findings were disclosed to telecom carriers in October 2020, and various measures were put into place to make it more difficult to hijack telecom accounts. T-Mobile for example published [5]a support page advising customers who change numbers to "update your contact number on any accounts that may have your number saved, such as notifications for bank accounts, social media, etc."

Nonetheless, it appears this vulnerability persists with other online services that rely on mobile phone numbers for multi-factor authentication.

Enter one of Big Tech's least favorite activists

Privacy consultant Alexander Hanff, an occasional [6]contributor to The Register , noted a social media post in which a Reddit user [7]describes gaining access to a "random girl's" account by using a newly provisioned mobile phone number to login to Meta's Instagram service.

"So naturally I got curious and tested other apps," the post says. "TikTok, Snapchat, Amazon, Facebook, Messenger, Cash App, and DoorDash were all easily accessible with this new number into this random person's account. But now I'm also scared because if I can do it, then the person who gets my old number can [too]? Isn't this like against some law or something?"

[8]FCC gets tough: Telcos must now tell you when your personal info is stolen

[9]Europe's largest caravan club admits wide array of personal data potentially accessed

[10]Crime gang targeted jobseekers across Asia, looted two million email addresses

[11]Meta to try 'cutting edge' AI detection on its platforms - asking people to add labels

The post omits some details that clarify how this might work – The Register has not verified that all the services cited above can be compromised as claimed.

If, for example, a Facebook user changes phone numbers but fails to note that change in Facebook or other accounts that use it for authentication, the recipient of the old, recycled number can try to login to the Facebook account still linked to that number. Doing so generally requires a password too.

[12]

But not having the password isn't necessarily a barrier. The phone number may be sufficient to reset the password and access it despite multi-factor authentication. Typically, users are sent notification of the password change to the email address associated with their account.

In some login flows for a new sign-in, like the one used by DoorDash, an email address is required first, though isn't necessary thereafter. After providing an email address and clicking "Continue to Sign In," a user can provide that same email address or a phone number to receive a one-time verification code sent in a text message that completes the login process. In this instance, controlling the phone number provides account access without need for concurrent email validation.

Procedural variations aside, initiating a password reset without permission to hijack an online account is against the law in the US, the UK, and elsewhere, Hanff wrote in his [13]reply , in addition to being a privacy intrusion.

[14]

Hanff subsequently tried to alert Meta. "I reported this under their security vulnerabilities (bug bounty) system as there is no other obvious way to report this," he told The Register . "Obviously I am not interested in any bounty, I am just trying to get this fixed, but Meta has a habit of obstructing people from contacting them."

No bounty for you says Meta

Meta has rejected Hanff's bug bounty report. The company's reply, provided to The Register , reads as follows:

There are situations where phone numbers expire that are made available to someone other than the original owner. For example, if a number has a new owner and they use it to log into Facebook, it could trigger a Facebook password reset. If that number is still associated with the user's Facebook account, the person who now has that number could then take over the account.

While this is a concern, this isn't considered a bug for the bug bounty program. Facebook doesn't have control over telecom providers who reissue phone numbers or with users having a phone number linked to their Facebook account that is no longer registered to them.

Hanff, in a LinkedIn post, [15]argued this is unacceptable.

"We do not say 'Well we know that passwords with low entropy can be hacked very quickly, but we are not responsible for people using password busting technology so we will continue to allow four-character passwords consisting of only lower-case letters in the first half of the alphabet,'" he wrote.

"So if you know a risk exists, the whole point of security design is to mitigate or remove those risks, not ignore them because you are not responsible for them."

Hanff said he has reported Meta to the Irish Data Protection Commission for alleged violations of Articles [16]5 , [17]25 and [18]32 of Europe's General Data Protection Regulation. Those rules require responsible data handling.

Meta did not immediately respond to a request for comment, nor did AT&T, T-Mobile, and Verizon. ®

Get our [19]Tech Resources



[1] https://recyclednumbers.cs.princeton.edu/assets/recycled-numbers-latest.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZctL13@9QQDde10zCjwCcAAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZctL13@9QQDde10zCjwCcAAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZctL13@9QQDde10zCjwCcAAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.t-mobile.com/support/account/change-your-phone-number

[6] https://www.theregister.com/Author/Alexander-Hanff

[7] https://www.reddit.com/r/privacy/comments/1ale62k/i_changed_my_number_and_now_i_can_log_into_others/

[8] https://www.theregister.com/2024/02/12/fcc_gets_tough_on_telcos/

[9] https://www.theregister.com/2024/02/12/europes_largest_caravan_and_rv/

[10] https://www.theregister.com/2024/02/09/resume_looters_jobs_ads_malicious_code/

[11] https://www.theregister.com/2024/02/06/meta_ai_label/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZctL13@9QQDde10zCjwCcAAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.reddit.com/r/privacy/comments/1ale62k/comment/kphl3am/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZctL13@9QQDde10zCjwCcAAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.linkedin.com/feed/update/urn:li:activity:7162706598010863617?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A7162706598010863617%2C7162721171585675264%29&dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287162721171585675264%2Curn%3Ali%3Aactivity%3A7162706598010863617%29

[16] https://gdpr-info.eu/art-5-gdpr/

[17] https://gdpr-info.eu/art-25-gdpr/

[18] https://gdpr-info.eu/art-32-gdpr/

[19] https://whitepapers.theregister.com/



Dinanziame

Using SMS as a security measure is broken in more than one way. SMS messages are broadcast across the world, and it only takes one corrupt phone company anywhere to intercept them.

Paul Crawford

SMS / phone number should not be the only means - it is acceptable as the '2' in 2FA where something more robust is the primary authentication, but not here where your allocated (and reused) phone number is all you need to get in to an account.

They won't fix it most likely as they are more concerned about making it easy to sign up for whoring to advertisers.

Well if Meta are going to get roasted for this one

Anonymous Coward

They're going to have a lot of company because so many services have taken the 2FA = SMS route. I've got far more accounts (including banks) that use SMS than an authenticator app. for instance.

Re: Well if Meta are going to get roasted for this one

aerogems

It is better than no 2FA, but that's not really saying much, so...

Re: Well if Meta are going to get roasted for this one

Paul Crawford

Oh it is much better than nothing, but only really if both are not on the same device (e.g. 2nd to 1st = saved password on your phone) as then all keys lie with whoever has accesses to it.

Re: Well if Meta are going to get roasted for this one

Doctor Syntax

It's rather worse for nothing on two accounts. As I've written here before, if this is being relied on then whoever has your phone or your phone number is you, even if it's not you. That opens the door to a variety of mechanisms for fraud. Secondly, it's an indication of sloppy thinking around security which should start you wondering what other sloppy thinking is going on.

Anyone who ever bought a new phone...

Anonymous Coward

...knows how easy it is to transfer a number.

SMS based authentication is a terrible idea.

My guess

aerogems

If the EU agency involved decided to pick this up and investigate, it's going to cost Facebook a lot more than it would have if they'd just paid the bounty and figured out some way to address the issue. You'd think, given the number of times Facebook has been dragged over hot coals for privacy and security issues, they'd default towards just paying the bounty in situations like this and then using it as part of a PR campaign to claim how they are proactively working to address issues.

Re: My guess

Richard 12

You're assuming a greater level of competence than prior evidence would indicate.

Re: My guess

AlexanderHanff

I am not even remotely interested in a bounty and if one was issued I would simply donate it to an NGO doing privacy work. As I explained to Tom, this was simply the easiest way to report this issue due to Meta's complete obstruction to users being able to contact them.

To be clear, they didn't even evaluate this (I am guessing the response was AI generated) as they literally closed the ticket within seconds of me submitting it - it would have taken longer than that for a human to even read the submission, let alone evaluate it.

Re: My guess

Roland6

If the EU really pick this up, the outcome going to impact everyone who uses a phone number as part of their security: HMRC, banks, …

It is also a reminder to people that simply ditching a phone number, is no longer simple, particularly if you have associated any online accounts with it. (Which given how many want a phone number, is going to be a lot).

However, if we make it too secure, then it will become too difficult to regain legitimate access to an account and the public will respond accordingly.

Re: My guess

Doctor Syntax

"If the EU really pick this up, the outcome going to impact everyone who uses a phone number as part of their security"

Or more precisely, their insecurity.

Tubz

Meta, no profit in it for us, no action. The bounty not be paid isn't the problem, it's Meta's ignorant handling of the notification. They had the opportunity here to say, yes this is big problem and we are going to use our vast resources to fix it for the industry and finally get some privacy/security brownie points back, but no, open mouth, insert foot, kick self in ass.

Test Man

This is a Meta issue whether they like it or not. It's been well known right from when mobiles started to become popular in the 80s and 90s that numbers get recycled in much the same way that landlines do, yet companies like Meta use them for identification without coming up with a solution for number recycling. It is they who need to find a solution, not telecoms companies.

mark l 2

Its mainly because even when services do allow better forms of 2FA such as TOTP they still require you provide a mobile number to 'prove identity'.

Paypal do this even though i have 2FAset up with TOTP they often still require i prove i am 'real' by having them send me a SMS which considering i don't get a phone signal in my office means i have to go outside an wave my mobile about like a madman to do something i have already done by logging in with a much more secure 2FA method

How *is* this Meta's problem?

localzuk

Surely it is up to individual users to update their details properly when they change numbers? How could Meta even know that you've changed number in some way to deal with this?

Re: How *is* this Meta's problem?

Headley_Grange

I'm not sure about this either. Many of the sites which use my phone for 2FA bug me every few months to confirm my details, which is an annoying-but-good thing. I'm not on any Meta apps, so I don't know, but I think that the only way that Meta could be criticized is if they make it difficult to change your phone number.

Re: How *is* this Meta's problem?

Munehaus

Because it's Meta that asked for the number in the first place. People lose numbers for many reasons outside their control. Moving house, health issues etc. For those same reasons they may also not be able to login for some time, even if they wanted to update their number and knew they should.

Once the number is lost someone else can access your Meta accounts before you get a chance to update them, if you can even login or know you need to. Every part of that is Meta's problem, not the user that only gave a number because they were asked.

Re: How *is* this Meta's problem?

AlexanderHanff

The way Meta have designed the login and password resets opens them up to a security risk as a result of re-provisioning of cell phone numbers. That is why this is their issue to resolve - under the GDPR they are legally obligated to identify and resolve security risks where possible - clearly here it is possible to remove this risk by designing login and password resets in a way which is not open to this risk - they have failed to do that and as such are in breach of Article 5(1)(f) (the principle of security), Article 25 (data protection by *design* and by *default*) and Article 32(1)(b) and 32(2) (security of processing based on risks).

So whereas you think Meta shouldn't be responsible, the law disagrees with you. The fact that they are aware of these risks but have chosen not to do anything to counter them, is a breach of their legal obligations.

Re: How *is* this Meta's problem?

Doctor Syntax

"Surely it is up to individual users to update their details properly when they change numbers?"

In order to do that you have to be in control of the old number - which will be used to verify you - while already knowing the new one. This isn't necessarily going to happen. OTOH it is going to happen if someone has stolen your own phone and is transferring your number to theirs.

ExampleOne

Setting aside the questions around SMS 2FA (which I don't think is the core of the problem here), the question is "Who is responsible for a user maintaining correct contact details?".

As I see it, the complaint seems to be Meta provided the password reset details to the contact details the user asked them to provide them to. Why can Meta be held liable if the user fails to update those contact details? I am pretty sure we have seen similar stories when domain names have been recycled, and the new owner of the domain started receiving email for the previous owner. I know I still receive post for previous residents of my current home, some of whom last lived here over 20 years ago!

Doctor Syntax

Let's conduct a thought experiment.

Your phone number has been changed. How do you go about changing contact details if they want to send an SMS to the old one to verify you?

Another:

Your phone has been stolen. How do you persuade them to block it's number for verification if they want to send an SMS to it to verify it's you calling?

The Fifth Rule:
You have taken yourself too seriously.