Internet Topology Security Issues
2 Factor Authentication (2FA) Vulnerabilities
Introduction
Most of the major players in the industry today double secure the accounts of their users so that they can be able to regain access just in case they forget or lose the password. The move is perfect as it allows the user to recover his or her credentials. However, the study herein shows that double securing an account can be one of the most dangerous security and privacy threats. Both private users and enterprises trust the major players in the Internet such as Google, Facebook, LinkedIn, and Twitter by giving them their privacy and allowing them to process their sensitive data.
However, as many people concentrate more on the large enterprises that are trusted, very few people take into consideration the impact of the background players who sell two-factor authentication security to those enterprise players. The latter can result in a perfect opportunity for a business to position in the right spot and generate huge profits by selling account access.
Considering the following assumptions:
- Assuming that Company A grows big through mergers and acquisitions and also starts providing services to Facebook, Google, LinkedIn, Twitter, and Banks.
- Assume that every time one decides to change his password through phone by SMS or Call, or login to the banking profile, the particular service provider would initiate an API call towards Company A asking them to send the code.
The Attack Pattern
A person in Company Y has the capability to virtually access any part of the digital life of the users of the companies to which it provides services. The person can view everything from life, social profiles, chats, contacts, messages, places you visit, as well as your bank account. The Flow: The attack can start when person X working at Company Y intentionally starts a password reset with a specific target victim in mind. Person X then intercepts the password reset message and performs a direct login to the account without the owner noticing. The implementation of double securing accounts opens a new discussion as far as Internet security is concerned and as information technology gets centralized in the current world. Looking at it in this context, instead of securing the account of the user, it makes it even more vulnerable than the initial approaches. The latter could open up an opportunity for a black market that targets online users using the techniques suggested in this study.
The following diagrams can be used to represent the regular flow and the attack flow paths.
Regular Request Flow
Attack Flow
The above scenario has been confirmed and many people have reported that their LinkedIn and Facebook accounts had been hacked. A forensic investigation of the systems revealed that the following scenario was being used to successfully hack accounts.
From the above image, it is clear that the email shows that a password reset had been done using Chrome on a Windows device located in the United States. The login sessions can also be used to detect cases of successful account hacking as can be seen in the screenshot below.
The Image Shows
The image shows two active logins using Chrome, from Windows, and the location is in the United States, and more importantly from the block that has been assigned to one of the biggest 2FA providers in the world that process Google, Facebook, Instagram, Twitter and many other services. Traffic is not delivered in any form of encryption. Due to the fact that the SMS/Voice MSU market functions just like a stock market, after the code gets submitted from the Social Network for upward delivery, it’s up to their partner to choose the "least cost route". There is no encryption in 2FA transmission:
Methods to Achieve Targeted Attack
The targeted attack can be achieved by dropping the SMS/Voice call price on the global market for a specific country and the operator of the victim, as a result of least cost routing, it’s a matter of minutes when the traffic is going to get re-routed towards the attacker platform. In order to be able to do so, without being suspicious, it could employ very serious tricks. This is the UK numbering plan of prefixes issued by Ofcom.
How below market costs are achieved to "get Social Networks verifications" at any time without even being suspicious:
- 078730 allocated by Ofcom to company X
- 078731 078732 078733 ... 078739 allocated to O2
Operators worldwide will try to shorten the lists of Global Titles (similar to iptables rules), and most of them have only 07873 = O2
Result
- Traffic accepted even if there is no Roaming Agreement with X (based on O2); Invoice goes to O2 - not X.
- Even if O2 has no agreement, it’s in small operators' interest to accept messages from a giant. The test by setting a number from the example pool using a VoIP white channel resulted in China Telecom thinking my operator is O2. This is the one and only case of such allocation in the UK or anywhere in the world.
Conclusion
This looks like a very sophisticated scheme aiming to control the whole market with the idea of being able to get access to any account at any time. The company might even make a loss on their business and sell access to any targeted account on any service to government or private sector via third-party companies to make an enormous amount of profit. This study presents forensic evidence that this scenario is already happening, affecting the whole Internet community.