They did not volunteer telephone numbers as universal proof of ID. So their threat model was proportional to their intended purpose of the identifier. If bad guys steal your phone number and run up $100 of calls, the phone company would eat the charges and get the number back. Of course nobody did that because it wasn't worth it.
Imagine you own a medium-sized residential building, maybe 20 households live there. You issue them all with front door keys. You use pretty good locks, from a no-duplicate series that isn't trivially picked by amateurs. You figure that picking the door or forging a key would be pretty hard so there's no way it's worth it when someone could just kick it down.
Then, to your astonishment, a local jewellery store announces that anyone who has one of your front door keys can now store up to $1M of valuables in safes they've made accessible from the street. "It's totally safe" they assure your residents, "because how could anybody else get one of these front door keys? That'd be impossible".
Um. What? Before you know what's happening, one of your residents is trying to sue you for a million dollars because they proudly used a safe to store their $1M of Bitcoins for some crazy reason and (duh) somebody just got a duplicate key easily enough for way less than $1M and stole them.
Communications Alliance chief executive John Stanton, representing the interests of mobile providers Telstra, Optus and Vodafone, took the extraordinary step of of declaring the technology insecure in the wake of numerous reports of Australians being defrauded via a phone porting scam first uncovered in Secure Computing magazine.
"SMS is not designed to be a secure communications channel and should not be used by banks for electronic funds transfer authentication," Stanton told iTnews this week.
The key trick isn't so much the two as that they're randomly selected.
I moved a large amount of money a few years back to buy my home (I do not like debt, so I saved up until I could afford somewhere to live, then I bought it)
The bank's web site lets you type in any amount of money but then it says politely that you can't do this from the web site, please call the bank.
I called the bank (they always pick up in 2-3 rings, I've worked with one of their founders, ensuring this was one of the key ideas behind the bank) and explained what I wanted to do. The nice lady took down all the details and then she explained that now one of her colleagues would be randomly selected to call me back and confirm everything and we hung up.
Sure enough, less than a minute later another of the people from the bank called (with the agreed password for when the bank calls me) and had me read out all the transaction details again, at which point the transaction was confirmed.
Think about that scenario as a bad guy trying to corrupt it. You bribe one employee to pretend someone called and authorised a huge transfer. OK. But then a different random employee has to confirm it. How do you bribe them? You have no way to know who it will be! Do you try just bribing every single employee who works the phones? Not very practical.
The other thing banks do is they background check employees. You can't test for "willing to take bribes" but you can weed out potential hires with previous convictions for financial crime, or debt problems. I've had checks like that for jobs touching sensitive personal information.
> You bribe one employee to pretend someone called and authorised a huge transfer. OK. But then a different random employee has to confirm it. How do you bribe them?
So first bank employee I bribe is one who can update the phone number on your account to one I control (or even better, an employee from your telco who'll let me port your number to my burner phone), the next employee I bribe is the one who pretends the call came in. The different random employee then just does their job confirming the transaction with a call to me. Bingo - I have your house payment...
After I identify myself I have to give them letters from a telephone password and a series of arbitrary questions I selected like "Memorable date" to answer. The very large transfer was years before I received a physical two factor authenticator, it's possible that these days I'd need to prove I had the authenticator too, I don't know.
Did you see in that article that the head of cyber security for AT&T added his two cents in shaming Twitter?
AT&T was just in the news recently where employees were accepting bribes that allowed criminals to swap SIMs steal bitcoins from AT&T customers.
Unbelievable.