Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
41–50 of 137 posts
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#42Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#43I feel for him. But couldn't they reasonably argue they are not a service for securing this kind of thing? If i leave $224m in my car and park it in car park at my local shopping centre are they liable for $224m? I'm not saying they're not liable to some extent.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#44Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#45Two things that jump out: 1) $200M in punitive damages? The hack occurred in January, and the price has gone down across all cryptocurrencies substantially since then. 2) Was the password hacked? Or did the exchange allow password resets via SMS? (So negligence made 2fa really 1fa) In this situation it seems AT&T would be at most 50% responsible.
> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#46> Terpin was the victim of two hacks within seven months
If indeed these were separate occurrences of breaking in through the same phone account—and the article is not definitive on this—then the punitive damages seem quite appropriate. “Fool me twice, shame on me,” and all that.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#47Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#48I feel for him. But couldn't they reasonably argue they are not a service for securing this kind of thing? If i leave $224m in my car and park it in car park at my local shopping centre are they liable for $224m? I'm not saying they're not liable to some extent.
It's more he parked it at the dealership, and the dealership made a stranger a spare key to get into the car.
I think the "cash left in the car" part captures the negligence on the cryptocurrency holder's part. One, he explicitly chose to store his wealth in a medium without reversal mechanisms. Two, he used an online account. AT&T bears some blame for his loss, but not a tremendous amount.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#49Phone numbers are specifically designed to serve as public identifiers. I don't think you can expect a security mechanism that is supposed to work counter to that to work very well.
The validation mechanism is control over the phone number, not knowledge of it. Verification by knowledge of numbers intended to remain secret (social security, credit card) is also never okay.
> After the first hack, Terpin alleged that an impostor was able to get his phone number from an "insider cooperating with the hacker" without an AT&T store employee requiring him to show valid identification or provide a required password. That phone number was later used to access Terpin's cryptocurrency accounts, according to the complaint.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#50If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?
> If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information By Kerckhoffs's principle > https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr... a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.