Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
31–40 of 137 posts
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#32Earlier quoted context omitted.
In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.
How does it work? Why is it so easy?
The SS7 (https://en.wikipedia.org/wiki/Signalling_System_No._7) does not have any authentication so anything over the telephone networks can be easily MITM'd.
And at provider's stores they are too eager to please a "customer" so social engineering is very effective at swapping SIM cards out and hijacking your number.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#33I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
When I was surprised that this is all the authn they needed, the sales guy joked with the rhetorical question “well, you are , right?” i.e. “well, it ain’t a problem at the moment, right?”
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#34If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?
By Kerckhoffs's principle
> https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr...
a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#35Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#36I don't think you can expect a security mechanism that is supposed to work counter to that to work very well.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#37Sorry for his loss, and the mobile providers do need to do something about this known attack vector. But with cryptocurrencies you need to "be you own bank", and extending his own analogy how many legitimate or long lasting banks would store USD24 million in cash in a hotel room safe?
Maybe you can be your own bank, but banks have to depend on external factors/entities to do what they're supposed to do as well.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#38I hope we see more of this. A lot more. These fuckers need to hurt.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#39I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
Are you saying that they will send the password to ANY email if you just provide the phone number ?
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#40Phone numbers are specifically designed to serve as public identifiers. I don't think you can expect a security mechanism that is supposed to work counter to that to work very well.
Verification by knowledge of numbers intended to remain secret (social security, credit card) is also never okay.