Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

41–50 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#42
There's not a lot of detail in the article, but reading between the lines it seems like an attacker went to an AT&T retail location and pretended to be the plaintiff in order to re-assign the plaintiff's phone number to a new SIM card.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#43

I feel for him. But couldn't they reasonably argue they are not a service for securing this kind of thing? If i leave $224m in my car and park it in car park at my local shopping centre are they liable for $224m? I'm not saying they're not liable to some extent.

I could reasonably argue that they should not allow any employee to give out my details, such that they can intercept my messages, to anyone. And by allow, I mean even make it possible.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#44
My first thought was "cryptocurrency is fundamentally not investment but speculation they don't create anything of value but squander vast ammounts. Second is that it is multileveled frustration that both phone systems are so damn insecure like the completely insecure call identification - while international efforts to track down telefraud rings are well and good a proper system would prevent most of their tricks.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#45

Two things that jump out: 1) $200M in punitive damages? The hack occurred in January, and the price has gone down across all cryptocurrencies substantially since then. 2) Was the password hacked? Or did the exchange allow password resets via SMS? (So negligence made 2fa really 1fa) In this situation it seems AT&T would be at most 50% responsible.

> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel

And then increase it again by arguing that AT&T should never have made it possible for employees to do this.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#46
From TFA:

> Terpin was the victim of two hacks within seven months

If indeed these were separate occurrences of breaking in through the same phone account—and the article is not definitive on this—then the punitive damages seem quite appropriate. “Fool me twice, shame on me,” and all that.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#48
post #3

I feel for him. But couldn't they reasonably argue they are not a service for securing this kind of thing? If i leave $224m in my car and park it in car park at my local shopping centre are they liable for $224m? I'm not saying they're not liable to some extent.

It's more he parked it at the dealership, and the dealership made a stranger a spare key to get into the car.

> It's more he parked it at the dealership

I think the "cash left in the car" part captures the negligence on the cryptocurrency holder's part. One, he explicitly chose to store his wealth in a medium without reversal mechanisms. Two, he used an online account. AT&T bears some blame for his loss, but not a tremendous amount.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#49
post #36

Phone numbers are specifically designed to serve as public identifiers. I don't think you can expect a security mechanism that is supposed to work counter to that to work very well.

The validation mechanism is control over the phone number, not knowledge of it. Verification by knowledge of numbers intended to remain secret (social security, credit card) is also never okay.

I'm going by the content of the story, which describes acquiring the phone number as the key issue.

> After the first hack, Terpin alleged that an impostor was able to get his phone number from an "insider cooperating with the hacker" without an AT&T store employee requiring him to show valid identification or provide a required password. That phone number was later used to access Terpin's cryptocurrency accounts, according to the complaint.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#50
post #34

If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?

> If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information By Kerckhoffs's principle > https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr... a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.

Which gets to the frivolity of the lawsuit. The primarily responsible party, the exchange, is likely a less lucrative target than AT&T.
Post reply on HN