Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
61–70 of 137 posts
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#62Earlier quoted context omitted.
> If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information By Kerckhoffs's principle > https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr... a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.
Which gets to the frivolity of the lawsuit. The primarily responsible party, the exchange, is likely a less lucrative target than AT&T.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#63Earlier quoted context omitted.
In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.
How does it work? Why is it so easy?
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#64Wasn't it like a year ago that famous YouTubers and such were getting their accounts stolen the exact same way and AT&T promised they would tighten up security measures?
Yes, you have to opt-in to this type of security
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#65If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?
It's still absurd to me that it's nearly impossible to prevent BofA and other institutional banking companies from sharing this information.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#66Earlier quoted context omitted.
SMS is not exactly the most secure protocol. But you do not need to use SMS for 2fa, that's a misconception.
Isn't it effectively plaintext? I don't know too much about the SMS protocol. But I do know that most protocols do start out plaintext because programmers are lazy and optimistic.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#67Earlier quoted context omitted.
> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel
And then increase it again by arguing that AT&T should never have made it possible for employees to do this.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#68While I was working at a blockchain forensics company (we built one of the first AI backed block-explorers both for Bitcoin and Ethereum & our service was also used to identify the DAO hack), both myself and my boss were targeted multiple times a year with this kind of attack even though we held no crypto through the company. It seemed that just since my name was on the web with the word crypto I was a target. To thi…
I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#69Earlier quoted context omitted.
> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel
And then increase it again by arguing that AT&T should never have made it possible for employees to do this.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#70Earlier quoted context omitted.
I'm going by the content of the story, which describes acquiring the phone number as the key issue. > After the first hack, Terpin alleged that an impostor was able to get his phone number from an "insider cooperating with the hacker" without an AT&T store employee requiring him to show valid identification or provide a required password. That phone number was later used to access Terpin's cryptocurrency accounts, ac…
“Acquiring the phone number” means getting it mapped to the attacker’s phone/SIM card. Overview of SMS hijacking (copy paste link, JWZ doesn’t line HN referrer headers): https://www.jwz.org/blog/2018/07/two-factor-auth-and-sms-hij...
It's just that the article says, "was able to get his phone number".
Getting a phone number, to me, has always had a pretty universal meaning, which is to simply learn its digits. But I suppose you must be right and they actually mean a deeper compromise.