Live data from Hacker News

Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

nytimes.com

11–20 of 28 posts

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#11
Another huge looming problem: My emails were hacked recently with a fraudulent domain transfer using a fake ID. This exposes other accounts that use emails from the domain for recovery.

I lucked into some compelling evidence I'd like to share with any security experts that would be able to help me.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#13
post #8
post #5

I submitted this apparently just after: https://news.ycombinator.com/item?id=15070199 I got hacked a week ago in this exact fashion (I haven't tried to keep it a secret that I was involved in Bitcoin earlyish-on). I don't think they were able to get anything (largely because I am mostly out of the crypto space) but please remove cellphone 2FA from all your online dealings and add something like Google Authenticator i…

Is having Project Fi (Google as the carrier) safer?

Yes, according to Kraken. "Consider switching to a more secure telco, without a human interface. Google Fi: no phone support agents, no physical locations, no problems."

https://blog.kraken.com/post/219/security-advisory-mobile-ph...

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#14
post #13
post #8

Earlier quoted context omitted.

Is having Project Fi (Google as the carrier) safer?

Yes, according to Kraken. "Consider switching to a more secure telco, without a human interface. Google Fi: no phone support agents, no physical locations, no problems." https://blog.kraken.com/post/219/security-advisory-mobile-ph...

That's very interesting. I've looked at Google's lack of human support as a bug in the past, but when Google is used to protect currency that could be a feature.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#15

> Accounts with banks and brokerage firms and the like are not as vulnerable to these attacks because these institutions can usually reverse unintended or malicious transactions if they are caught within a few days. Ah, I see.

Can but (in case of some banks) won't. As I have learned from a friend who was a victim of debit card skimming and theft - with TD bank failing to block obviously out-of-character fraudulent transactions and refusing to revert the fraudulent charges, and then charging fees for fraudulent overdraft to add insult to injury.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#16

> Accounts with banks and brokerage firms and the like are not as vulnerable to these attacks because these institutions can usually reverse unintended or malicious transactions if they are caught within a few days. Ah, I see.

Can but (in case of some banks) won't . As I have learned from a friend who was a victim of debit card skimming and theft - with TD bank failing to block obviously out-of-character fraudulent transactions and refusing to revert the fraudulent charges, and then charging fees for fraudulent overdraft to add insult to injury.

Well shit, might as well put everything in a bitcoin wallet then.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#18
post #5

I submitted this apparently just after: https://news.ycombinator.com/item?id=15070199 I got hacked a week ago in this exact fashion (I haven't tried to keep it a secret that I was involved in Bitcoin earlyish-on). I don't think they were able to get anything (largely because I am mostly out of the crypto space) but please remove cellphone 2FA from all your online dealings and add something like Google Authenticator i…

>The cellphone companies could prevent this attack entirely by requiring in-person (with ID) transfers of cellphone numbers to new hardware, at the store. Given the infrequency that I would have to do that, the extra inconvenience is acceptable.

Fake IDs are cheap. This would not prevent a motivated attacker.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#20
post #4

Perhaps using a non-published extra phone number registered to someone else (perhaps your child) can provide protection? It's security through obscurity but with the phone number being the crucial piece of information, keeping it secret will go a long way. Of course the real fix would be to have better trained people working at the call centers.

The issue within the call centers are poorly enforced rules. If you have several customers a day demanding something eventually they just wear the reps down. When management fails to enforce those rules, and angry customers keep pushing, eventually the reps just do it. I've unfortunately seen/heard it more times than I can count in call center environments. I believe they honestly are trained well enough to know better, they just become apathetic. Not saying its right, its just what I have witnessed. Within my call center I am looked at as a stickler because I follow documentation to the T. It's sad that this generally makes you an anomaly within a call center.
Post reply on HN