Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

51–60 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#51
post #49

Earlier quoted context omitted.

The validation mechanism is control over the phone number, not knowledge of it. Verification by knowledge of numbers intended to remain secret (social security, credit card) is also never okay.

I'm going by the content of the story, which describes acquiring the phone number as the key issue. > After the first hack, Terpin alleged that an impostor was able to get his phone number from an "insider cooperating with the hacker" without an AT&T store employee requiring him to show valid identification or provide a required password. That phone number was later used to access Terpin's cryptocurrency accounts, ac…

“Acquiring the phone number” means getting it mapped to the attacker’s phone/SIM card. Overview of SMS hijacking (copy paste link, JWZ doesn’t line HN referrer headers): https://www.jwz.org/blog/2018/07/two-factor-auth-and-sms-hij...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#52
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

I hope he loses, so financial services will stop supporting 2FA over SMS.

Is that more or less likely than SMS providers fixing their security?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#54
While I was working at a blockchain forensics company (we built one of the first AI backed block-explorers both for Bitcoin and Ethereum & our service was also used to identify the DAO hack), both myself and my boss were targeted multiple times a year with this kind of attack even though we held no crypto through the company. It seemed that just since my name was on the web with the word crypto I was a target.

To this day I have a personal phone and a revolving burner I only use for non-SMS 2FA with an unlisted number, which is kept in an EMF proof bag while not in use.

Security for this kind of thing is an absolute joke.

Granted, this guy should've known better granted the value of his holdings... Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen.

However, I'm still waiting for a carrier that creates a system that can't be trivially socially engineered by bored Chinese scammers...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#55
post #9

I’m not sure if he has any legal recourse against AT&T, but it’s another example why sms based 2FA is a bad security scheme, especially if you’re a high value target.

In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.

I see the advice not to use SMS for 2FA comes up a lot on HN, and understand the reasons why that is true. But I find that recommendation comes up short. What are the alternatives, and how can they be widely deployed for little cost?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#56

If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?

It's still absurd to me that it's nearly impossible to prevent BofA and other institutional banking companies from sharing this information.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#58

Publicity and tens of millions in Bitcoin /Ethereum++ is a bad idea. Especially since once it's gone it's gone. Hacking your account means FU money and then some, with less chance of getting caught than other crimes. So they have all the incentive in the world to take heir sweet time...even if they lost 50% laundering, it's still more than enough. I'm all for At&t to be held responsible if they broke security protoco…

Having any serious amount of money and being showy or grandiose about it is asking for trouble...

Only rich morons actually need armed security as a result of their social media habits emanating from a pathetically desperate ego.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#59
post #9

Earlier quoted context omitted.

In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.

I see the advice not to use SMS for 2FA comes up a lot on HN, and understand the reasons why that is true. But I find that recommendation comes up short. What are the alternatives, and how can they be widely deployed for little cost?

Token based 2FA, either via something like google authenticator or a USB dongle like a Yubikey or RSA token.

The point is to prove that you have possession of both knowledge and a physical token (hence two factor). And while sms to phone makes it seem like you are proving possession of the phone, you’re actually proving that you have the phone that texts will route to. That last bit is movable and subject to shockingly little security, hence the issue.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#60

I notice AT&T is quoted as saying "we dispute these allegations and look forward to presenting our case in court". It's interesting they didn't say "these allegations are baseless and without merit". I wonder if that means anything.

A "baseless allegation" is one with no evidence or reason. This guy has a reason and presumably evidence, so his allegations are not baseless.

A baseless allegation would be if I were suing AT&T for losing all my crypto investments. I have none and am not an AT&T customer.

An "allegation without merit" means no rational interpretation of the law would result in a guilty conviction of the allegations. Baseless ones are almost always without merit.

Post reply on HN