Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right.
Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do.
So a random customer service rep couldn't access my account without my phone in their hand, even if they managed to clone my SIM to get past the text message check.
I’m not sure habituating people to getting asked for 2FA codes is a good idea. Seems like it’s just going to make people more susceptible to social engineering attacks.
I’ve long considered why apps don’t have some VOIP client in them; if one can Face ID into their account, and use the VOIP client to connect to a rep - then the metadata associated with the call can inform the rep you are who you say you are. Seems E* is almost there!
Presumably the process for that is much more involved and fewer people have the power to do it. And if it requires the approval of two higher up people to do then that lowers the risk even further.
I dunno but I have been unable to get back my Gmail account after changing phone numbers, and unable to change email on Netflix account after credit card I used to open account expired.
Seriously who designed a system that habituates people to giving out 2fa codes over the phone?? That's explicitly a weakness of the 2fa system, nobody should ever read out or forward their 2fa code.
In this case it sounds like the user is calling ETrade, so unless the user calls a wrong number that just so happens to be a hacker it's unlikely this would be an issue.
Actually, that is a very common trick that scammers have used and still do. In the past they would buy Google ads or do some black hat SEO to get their fake number to the top of search engines.
Then, people searching for things like "Microsoft tech support" would get the scammers number and call it. Google and other search engines will even pull that number from your site and handily present it to you at the top of the search results to make it appear even more legit.
Taking over unclaimed Google map listings for businesses is also really common.
Simply buying a toll free number that is close to the customer service number for a large company is bound to get you more inbound callers than you care to scam.
So no, absolutely no excuses for teaching people to share their 2fa codes.
Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do.
So a random customer service rep couldn't access my account without my phone in their hand, even if they managed to clone my SIM to get past the text message check.