Another Vulnerability of SMS Text Messaging

Joseph Cox, reporting for Motherboard:

While I was on a Google Hangouts call with a colleague, the hacker sent me screenshots of my Bumble and Postmates accounts, which he had broken into. Then he showed he had received texts that were meant for me that he had intercepted. Later he took over my WhatsApp account, too, and texted a friend pretending to be me.

Looking down at my phone, there was no sign it had been hacked. […] But the hacker had swiftly, stealthily, and largely effortlessly redirected my text messages to themselves. And all for just $16.

I hadn't been SIM swapped, where hackers trick or bribe telecom employees to port a target's phone number to their own SIM card. Instead, the hacker used a service by a company called Sakari, which helps businesses do SMS marketing and mass messaging, to reroute my messages to him. This overlooked attack vector shows not only how unregulated commercial SMS tools are but also how there are gaping holes in our telecommunications infrastructure, with a hacker sometimes just having to pinky swear they have the consent of the target.

Sure, the carriers have patched this flaw now, but how many others exist? SMS is and has always been an inherently unsafe way to communicate.

Two things to take away from this:

  1. Two-factor authentication using SMS is only going to stop the laziest, stupidest “hackers.”

  2. SMS messages are on the verge of being publicly available, and you should use an encrypted messaging service (iMessage, Signal, etc.)