Live data from Hacker News

Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

ptsecurity.com

41–50 of 56 posts

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#41
post #35
post #9

I was targeted this evening by a hacker who ported my phone number, and then got into FB + Yahoo (SMS reset). The motive appears to be bitcoin, based on the people contacted via facebook. Is it possible the initial PIN that was sent by Tmobile was intercepted via SS7? I am trying to find out if my phone (android) is compromised as well. The accounts and phone number are back under my control but I want to find out th…

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

If you know somebody's name, you have enough information to call each carrier until you get a hit and then escalate from there.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#42
post #35

Earlier quoted context omitted.

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

I don’t mean to say it was OP’s fault but you shouldn’t really use your primary phone number for 2FA anyways. Using a burner dumb phone dedicated only for 2FA should be standard, right?

Standard? As far as I know, the majority of users dont even use 2FA at all. How do you expect them to have a dedicated phone for it...

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#43
post #7

Slightly less exciting TLDR: as many of you already know, SMS isn't a good second factor for auth. That includes entrusting your Bitcoin wallet's private keys to a company using SMS for 2FA. Let's mention "cryptocurrency" as well to show up in more news alerts.

Exactly. Coinbase is a web service, not a 'true' wallet.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#44
post #13

Cryptocurrencies offer unprecedented transaction speeds Lol.

Maybe not Bitcoin, but most other currencies have near-instant transactions. Even Bitcoin's transaction speed outperforms wire transfers (in the US) by a matter of days.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#45
post #7

Slightly less exciting TLDR: as many of you already know, SMS isn't a good second factor for auth. That includes entrusting your Bitcoin wallet's private keys to a company using SMS for 2FA. Let's mention "cryptocurrency" as well to show up in more news alerts.

Paypal is offender number one. I don't understand why they can't use google authenticator. Is it some kind of pride thing, like paypal and Amazon?

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#46
post #20
post #19

Earlier quoted context omitted.

Good point. Some payment processors credit sellers with just one confirmation. But it can still take several minutes, or more if your wallet client doesn't add enough fee. Also, with Bitcoin price so high, fees are absurd for small transactions. That's the real problem. For large transactions, on the other hand, Bitcoin is faster than wire transfer. I can move thousands of USD in a few hours, anonymously through a mi…

Last month I moved £10,000 between two UK banks and it settled in 3 seconds. Fees were £0.00. I could have moved more for exactly the same fee of free.

>settled in 3 seconds

*subject to chargeback/reversal for up to n months.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#47
post #13

Cryptocurrencies offer unprecedented transaction speeds Lol.

Maybe not Bitcoin, but most other currencies have near-instant transactions. Even Bitcoin's transaction speed outperforms wire transfers (in the US) by a matter of days.

Actually, I was shocked how quickly Bitcoin transfers were. About a week ago I watched someone transfer me $10 in BTC and I got "unconfirmed: $10" within a few seconds.

It wasn't confirmed until a few minutes later, but that was enough time to assume everything was fine and to keep doing stuff in the meantime. Concretely, you can assume almost every unconfirmed transaction will be confirmed, and you'll almost never be wrong. That means Bitcoin is effectively instant for every transacfion you don't need to care about, and in the other cases you can just wait a few minutes.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#48
So, a little anecdote, a friend of mine was the victim of an attack and wanted my advice. The attackers used the SS7 hack, but he also used a phone based TFA, and somehow attackers were able to get the keys to this. He was able to get some of his coins elsewhere on a paper wallet, but they got everything in his hot wallet, and he received a notification that his coins were being moved out of his cold storage. Thankfully this process takes some time, so he was able to get that company on the line and stop it (probably pure luck that the attackers didn't intercept this). I told him to lock down the cold storage and trash his phone (based on the level of control that would be required to get TFA private keys). So, there hasn't been any further analysis done on this attack (the cold storage coins are safe, that's the main thing), but just want to mention this to get your gears turning. It's possible coins being stolen this way are being used to fund a nuclear program - keep them close.
Post reply on HN