{"id":191512,"date":"2017-08-11T18:49:59","date_gmt":"2017-08-11T16:49:59","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=191512"},"modified":"2017-08-11T15:50:13","modified_gmt":"2017-08-11T13:50:13","slug":"the-loophole-hackers-can-use-to-get-around-south-african-banks-sms-verification","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/mobile\/191512\/the-loophole-hackers-can-use-to-get-around-south-african-banks-sms-verification\/","title":{"rendered":"The\u00a0loophole hackers can use to get around South African banks&#8217; SMS verification"},"content":{"rendered":"<p>Long-known but relatively obscure vulnerabilities in global mobile telecommunications systems are reaching a wider audience, including cyber criminals, according to Neil Bester, senior vice president at fintech company Entersekt.<\/p>\n<p>Bester was citing a\u00a0recent malicious attack on customers of O2-Telefonica in Germany which saw many bank accounts emptied of funds.<\/p>\n<p>In the attack, the thieves exploited flaws in the mobile SS7 protocol over several months to intercept two-factor authentication codes sent to online banking customers, thereby gaining access to their accounts and draining them of funds.<\/p>\n<p>Signaling System 7 (SS7) is an international telecommunications standard that defines how cellphone networks connect with each other.<\/p>\n<p>It allows cellphone users in South Africa, for example, to roam on networks anywhere else in the world.<\/p>\n<p>SS7 means they can make and receive calls, as well as text messages across networks.<\/p>\n<p>&#8220;It\u2019s the backbone of worldwide mobile communication used by billions of people,&#8221; said Bester.<\/p>\n<p>He noted that once they have gained access to the SS7 network, intruders can impersonate a phone\u2019s location, read or redirect messages, and even listen to calls.<\/p>\n<p>This poses significant risks for any institution that uses mobile networks to transmit authentication information such as SMS one-time passwords (OTPs).<\/p>\n<p>&#8220;There has been a high level of complacency around the risks of SS7, despite repeated warnings from security researchers in recent years, he said.<\/p>\n<p>&#8220;That\u2019s because no large-scale fraud attack has ever been reported \u2013 until now.&#8221;<\/p>\n<h3 class=\"my-4\"><strong>South Africa<\/strong><\/h3>\n<p>According to Bester, while there as yet have been no SS7 attacks reported in South Africa \u2013 network operators have had to remain vigilant.<\/p>\n<p>This is because they\u00a0rely on detection schemes rather than an encrypted channel that would render any SS7 attack approach ineffective, he said.<\/p>\n<p>&#8220;Network-initiated unstructured supplementary service data (NI-USSD, also known as push USSD) is a safer option for authenticating transactions than is SMS.&#8221;<\/p>\n<p>&#8220;Unlike SMS, which is a store-and-forward technology, push USSD allows a two-way exchange of data in real time, and no data useful to fraudsters is stored on the device.&#8221;<\/p>\n<p>&#8220;Push USSD sessions can, however, still be illegally redirected in the same way that calls can because the process depends on the handset\u2019s SIM card,&#8221; he said. &#8220;An attacker could redirect an entire USSD session to their own phone and the victim would never know,&#8221; Bester said.<\/p>\n<p>If a network operator is vulnerable to SS7 attack, then USSD is technically no safer than SMS, he added.<\/p>\n<p>However, by deploying adequate SS7 firewalls, mobile operators can at least provide some resistance to attacks.<\/p>\n<p>According to Bester the only way to\u00a0completely avoid the kind of eavesdropping SS7 makes possible, you need to open a completely isolated, end-to-end encrypted communications channel between the mobile phone and the servers that process payments or store sensitive data, and to properly authenticate the users of this channel.<\/p>\n<p>&#8220;Using a self-contained cryptographic infrastructure deployed to the phone, you avoid having to rely on the security provided by telecommunications protocols, mobile network operators or the device\u2019s operating system,&#8221; he said.<\/p>\n<p>&#8220;No third party can access or modify data travelling over this protected channel, making it impervious to the kind of attacks seen in Germany.&#8221;<\/p>\n<hr \/>\n<p><strong>Read:\u00a0<a href=\"https:\/\/businesstech.co.za\/news\/banking\/189462\/the-banking-and-finance-jobs-were-most-likely-to-lose-to-robots-in-sa\/\" target=\"_blank\" rel=\"noopener\">The banking and finance jobs we\u2019re most likely to lose to robots in SA<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While confirming a log in or transaction with an SMS or email has long been thought of as safe &#8211; that is no longer the case &#8211; especially with South Africa&#8217;s current systems according to Neil Bester, senior vice president at fintech company Entersekt.<\/p>\n","protected":false},"author":10,"featured_media":191532,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[961,34],"tags":[2099,26],"class_list":["post-191512","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking","category-mobile","tag-entersekt","tag-headline"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/191512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=191512"}],"version-history":[{"count":6,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/191512\/revisions"}],"predecessor-version":[{"id":191716,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/191512\/revisions\/191716"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/191532"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=191512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=191512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=191512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}