I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
21–30 of 137 posts
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#22I’m not sure if he has any legal recourse against AT&T, but it’s another example why sms based 2FA is a bad security scheme, especially if you’re a high value target.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#23If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?
Sure.. you can sue for whatever you want. There is no guarantee that you will be awarded the damages though.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#24Two things that jump out: 1) $200M in punitive damages? The hack occurred in January, and the price has gone down across all cryptocurrencies substantially since then. 2) Was the password hacked? Or did the exchange allow password resets via SMS? (So negligence made 2fa really 1fa) In this situation it seems AT&T would be at most 50% responsible.
You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#25Two things that jump out: 1) $200M in punitive damages? The hack occurred in January, and the price has gone down across all cryptocurrencies substantially since then. 2) Was the password hacked? Or did the exchange allow password resets via SMS? (So negligence made 2fa really 1fa) In this situation it seems AT&T would be at most 50% responsible.
> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel
That's why I said "at most" :-)
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#26If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?
Sure.. you can sue for whatever you want. There is no guarantee that you will be awarded the damages though.
Here, you're just being a dick.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#27Earlier quoted context omitted.
How does it work? Why is it so easy?
SMS is not exactly the most secure protocol. But you do not need to use SMS for 2fa, that's a misconception.
I don't know too much about the SMS protocol. But I do know that most protocols do start out plaintext because programmers are lazy and optimistic.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#28Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#29I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
Are you saying that they will send the password to ANY email if you just provide the phone number ?
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#30Wasn't it like a year ago that famous YouTubers and such were getting their accounts stolen the exact same way and AT&T promised they would tighten up security measures?