SS7, a key component of the telecom backbone, facilitates carrier interoperability.
An SS7 attack takes advantage of a weakness in the design of SS7 (Signalling System 7) to enable data theft, eavesdropping, intercepting text & location tracking. To launch an SS7 attack, a criminal would hack or buy his way, via the dark web, onto the network.
Though SS7 network protocol is fundamental
to cellphones & telcos,
the security of the SS7 design
relies entirely on trust.
The SS7 telecom standard is vulnerable to interception of one-time password SMSes.
Positive Technologies demonstrated how to exploit this SS7 flaw to:
Discover the Coinbase wallet's e-mail address
Control the wallet
Access the wallet itself
Obtain the account password for wallet &
Withdraw BTC.
Hacking: beyond bitcoin to fiat banking
Attacks exploiting ... vulnerabilities can be launched from anywhere, which is a great benefit to attackers. In spring 2017, the first cases of attacks exploiting SS7 were registered in Germany, in which money was stolen from bank accounts. Cybercriminals intercepted texts with online banking authentication codes sent to customers of Telefonica Germany (O2), a German mobile operator, and used them to carry out unauthorized transactions.
Vulnerabilities in mobile networks opens bitcoin wallets to hackers
Today, SS7 is fair game to hackers. If you use 2FA through SMS, are a potential victim, till network administrators fix vulnerabilities in the telecom backbone.
To make yourself less hackable:
Use a data-based communications one-time codes, like those through Google Authenticator.
Use devices like Trezor & Ledger, as @madonos suggests, in his comment to this post.
Research for yourself & use what you are most comfortable with.
Stay paranoid, about security.
You may also be interested in:
He never abandons those who trust & call on Him
Holy Spirit must come down. And Africa will be saved.
Could a 24K Gold Cross Pendant Necklace be yours?
My soul magnifies the Lord & my spirit rejoices in God my Savior.
I Exalt Thee
Are you seeing numbers in sequence?
Dawood, ISI, ISPR or Maleeha?
Wannsee: the pivot of the Final Solution & the Atonement
Crypto mining: Has India's time come?