Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

21–30 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#21
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

Are you saying that they will send the password to ANY email if you just provide the phone number ?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#22

I’m not sure if he has any legal recourse against AT&T, but it’s another example why sms based 2FA is a bad security scheme, especially if you’re a high value target.

NIST recommended in 2016 that 2FA via SMS be deprecated (though they backed off of that a bit in 2017)

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#23

If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?

Sure.. you can sue for whatever you want. There is no guarantee that you will be awarded the damages though.

That was my literal question, yes :-) I'll reword it to be match what I was trying to say.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#24

Two things that jump out: 1) $200M in punitive damages? The hack occurred in January, and the price has gone down across all cryptocurrencies substantially since then. 2) Was the password hacked? Or did the exchange allow password resets via SMS? (So negligence made 2fa really 1fa) In this situation it seems AT&T would be at most 50% responsible.

> AT&T would be at most 50% responsible

You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#25

Two things that jump out: 1) $200M in punitive damages? The hack occurred in January, and the price has gone down across all cryptocurrencies substantially since then. 2) Was the password hacked? Or did the exchange allow password resets via SMS? (So negligence made 2fa really 1fa) In this situation it seems AT&T would be at most 50% responsible.

> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel

Given that the NIST published guidance in 2016 recommending it not be used for 2FA, I agree with you.

That's why I said "at most" :-)

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#26

If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?

Sure.. you can sue for whatever you want. There is no guarantee that you will be awarded the damages though.

This kind-of comment would have been clever in elementary school.

Here, you're just being a dick.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#27
post #15

Earlier quoted context omitted.

How does it work? Why is it so easy?

SMS is not exactly the most secure protocol. But you do not need to use SMS for 2fa, that's a misconception.

Isn't it effectively plaintext?

I don't know too much about the SMS protocol. But I do know that most protocols do start out plaintext because programmers are lazy and optimistic.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#29
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

Are you saying that they will send the password to ANY email if you just provide the phone number ?

I read that as him saying that T-Mobile belongs on http://plaintextoffenders.com/

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#30
post #6

Wasn't it like a year ago that famous YouTubers and such were getting their accounts stolen the exact same way and AT&T promised they would tighten up security measures?

Yes, you have to opt-in to this type of security
Post reply on HN