SMS-based two-factor authentication has been much talked about. Despite the shortcomings of Signaling System 7 (SS7), which is a telecommunications protocol for routing texts and calls used internationally, the system is still widely used in banking and other services.

Security researchers at Positive Technologies have shown how they can hack a Bitcoin wallet using SS7 vulnerabilities. By taking control of the SS7 network, hackers were able to reset Gmail passwords using two-factor authentication.
A major flaw in SMS-based 2FA is that the one-time password can be accessed across a variety of devices and services, which may also have their own flaws. Thus, the attack surface increases.
Researchers have released a video showing how easy it is to carry out an attack to steal Bitcoin. By intercepting text messages in transit, hackers can take control of your Gmail account and any other services associated with it.
This flaw puts both your banking and social media accounts at risk. Access to the SS7 network is the biggest hurdle you have to overcome. Cybercriminals can buy access to it from the dark web. In the past, in at least one case, SS7 was used to empty bank accounts. According to Forbes, many surveillance companies also sell services to spy using the SS7 flaw.
What should the user do?
As highlighted earlier, the SS7 flaw has been known in the telecom industry for a long time. So, unless steps are taken to make it more secure, users will have to take it upon themselves. You can use tools like Google Authenticator, Google prompt, or a security key for extra security.
