Live data from Hacker News

Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

ptsecurity.com

31–40 of 56 posts

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#31
post #25
post #21

Earlier quoted context omitted.

What mechanism? Moving funds internationally, in my experience, has sometimes taken days.

I routinely move funds internationally using the old-fashioned mechanism called "wire transfer" which for my particular case, is settled in hours and has zero fee.

Maybe things have improved. I recall some hassle getting my bank to handle international wires. And I suspect that "routinely" may be the distinction. Once the bank does one transfer, it becomes routine.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#32
post #22
post #16

Earlier quoted context omitted.

Better 2FA exists. We still need better identity authentication. Copied passports, phone numbers, and email all have problems. There are government initiatives (in the US it seems to be NSTIC and login.gov). This should be opened up and made international. It seems that login.gov is already an OpenID identity provider. So only marketing is left. Next to login with Facebook and Google, there should be a "login with Go…

I'd like to see something done in that area. Unfortunately, I'm not sure how politically feasible login.gov is. No, I know it exists and is technically possible - but we have people, a lot of them, who are very much against government tracking. We have people who think the census should be illegal and will claim it is a conspiracy when you point out it is an enumerated responsibility listed in the constitution. We ha…

Facebook already serves as a global identity provider. However, it does not fit some use cases. For example, to buy Bitcoins on Coinbase, you have to comply with KYC/AML laws, which essential means you must send them a scan of your passport and other stuff. A Facebook login is not enough.

Technically, it is not necessary that the government runs it. We could let Facebook do that, but that would be worse than government imho. Maybe a non-profit would work?

Still, governments must be involved because ultimately they are the original source and enforcer of identity.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#33
post #17

How many times do we have to read that X is vulnerable to SS7 attacks? This has been going for the last couple of years. SS7 in itself is huge disaster, I can recommend the following presentations: https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271... and https://media.ccc.de/v/31c3_-_6531_-_en_-_saal_6_-_201412272... tldr: everything that uses sms is vulnerable. edit: as others already mentioned, use offli…

> How many times do we have to read that X is vulnerable to SS7 attacks?

Until all those whose job it is to secure the various Xs stop ignoring the problem?

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#35
post #9

I was targeted this evening by a hacker who ported my phone number, and then got into FB + Yahoo (SMS reset). The motive appears to be bitcoin, based on the people contacted via facebook. Is it possible the initial PIN that was sent by Tmobile was intercepted via SS7? I am trying to find out if my phone (android) is compromised as well. The accounts and phone number are back under my control but I want to find out th…

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#36
post #27

Mobile phones should be used as a hot wallet storing small amount for convenience. The rest of the bulk should be on a https://trezor.io/

Or a paper wallet, which is free, although it involves jumping through some extra hoops. Here's the steps the steps commonly advised for Ethereum (also works for storing ERC-20 tokens): Look up "My Ether Wallet" (be extremely paranoid and treble check the URL so you don't get scammed with a fake duplicate website). If you follow the steps below, your wallet is as hack-proof as a Nano/Trezor (just store the paper wall…

HN user jrruethe offered his 2015 guide to bitcoin paper wallets a week ago:

http://jrruethe.github.io/blog/2015/04/23/bitcoin-paper-wall...

src: https://news.ycombinator.com/item?id=15246588

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#38
post #35
post #9

I was targeted this evening by a hacker who ported my phone number, and then got into FB + Yahoo (SMS reset). The motive appears to be bitcoin, based on the people contacted via facebook. Is it possible the initial PIN that was sent by Tmobile was intercepted via SS7? I am trying to find out if my phone (android) is compromised as well. The accounts and phone number are back under my control but I want to find out th…

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

I don’t mean to say it was OP’s fault but you shouldn’t really use your primary phone number for 2FA anyways. Using a burner dumb phone dedicated only for 2FA should be standard, right?

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#39
post #15

Sadly, as far as I know, Paypal only allows SMS. I believe business account, you cannot link your Paypal to Braintrees and thus you cannot use any 2-auth authenticator. If I am wrong, please correct me, but I see no other options on Paypal, which is ridiculous, considering Paypal is such an important service. SMS should not be used for any critical services, but in cases like Paypal there is no choice.

It is possible to enroll hardware tokens, but I believe SMS is a prerequisite.

It's also allegedly possible to deactivate in a bunch of other ways, e.g. by adding a new credit card.

https://github.com/dlenski/python-vipaccess

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#40
post #32
post #22

Earlier quoted context omitted.

I'd like to see something done in that area. Unfortunately, I'm not sure how politically feasible login.gov is. No, I know it exists and is technically possible - but we have people, a lot of them, who are very much against government tracking. We have people who think the census should be illegal and will claim it is a conspiracy when you point out it is an enumerated responsibility listed in the constitution. We ha…

Facebook already serves as a global identity provider. However, it does not fit some use cases. For example, to buy Bitcoins on Coinbase, you have to comply with KYC/AML laws, which essential means you must send them a scan of your passport and other stuff. A Facebook login is not enough. Technically, it is not necessary that the government runs it. We could let Facebook do that, but that would be worse than governme…

I wonder if some sort of global NGO would work? Maybe an offshoot of the UN? At least initially, it will get lots of blowback in the US - if it is a requirement to get services. So, maybe they can incentivize it? Total adoption may take quite a while, perhaps even a full generation, though maybe more.

We could start by making it optional and using it to expedite some services. We could also start initiating it at birth, to go along with the SSN. Maybe we could even make the SSN card a plastic card with a magnetic strip and a chip in it, for the NFR functionality, as well as making inexpensive USB devices for online authentication?

I'm not an authority on this, or anything. I'm just speculating as to how it might work and how it might be possible to get it adopted. There will still be people against it, thinking it is something like trying to force a single world government, but it should be okay so long as it isn't a strict requirement to access services. Of course, accessing those services might be more difficult and that'd give incentive to use it.

It'd have to be no-direct cost, and replaceable if lost or stolen. Maybe allow a free replacement every two years, or similar. Then, maybe a few bucks to replace it otherwise. There should probably be a hardship clause.

The card could have many other uses, as well. Maybe people could opt to use the same card for banking, for library loans, for welfare benefits, and things like that?

It seems doable, tech-wise. Politically, it's much more difficult. Even the new(ish) enhanced ID requirements went over poorly. My State fought that for years by using the excuse that it was an unfunded law. Yup, Maine fought against the enhanced ID that lets us cross the border into Canada without a passport. The excuse was funding, but it was really about not wanting to be told we needed a federal ID.

It's a potentially tough nut to crack.

Post reply on HN