Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

81–90 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#81
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How else is this company supposed to identify you over the phone, without something that can be forgotten, without referencing easy to find public information, and without using a secondary verified contact method like email?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#82
post #81
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…

Is there an absolute requirement to be able to demonstrate your identity over the phone even if you have no secret information with which to confirm it?

How about, if you forget your password and can’t get into your account, you need to visit a store in person to show your ID, or mail in a notarized copy, or something like that?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#83
post #68

Earlier quoted context omitted.

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

Authy specifically stores your account in the cloud and can be recovered using SMS. They have a 24 hour warning period during which the email address on file receives multiple notifications that a recovery is being attempted with the option to cancel but if someone has control over your phone number for an extended period of time they can absolutely take over your Authy account. I found this out when my Authy account…

I mentioned this because I know multiple people who've had authy / other authenticators compromised down the line from social engineering attacks. Even if you can be alerted, usually it's too late by the time you realize what's happened to your creds.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#84
post #68

Earlier quoted context omitted.

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

Authy at least will let you "recover" your account by them sending a text message to the associated phone number. Tap the link in the message and presto, 2FA codes.

This is exactly the kind of feature you don't want...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#85
post #81
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…

> What do we want these companies to do?

Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access.

And no, restricting data/access and ease of use are not completely mutually exclusive. There is a harmonious middle of the venn diagram that is completely different to the way things are currently run. Nobody's asking to force 2FA on cell phones here (unless we opt-in), we're just asking for better identity verification and less apathy towards giving out my info (in all cases).

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#86
I think about this a lot as the phone is a pretty obvious single point of failure for 2FA and telcos are easily pwned through basic social engineering. I struggle with removing it as an alternative though because losing your phone or 2FA device leaves you in a pretty nasty spot. Tough choice.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#87
post #75
post #68

Earlier quoted context omitted.

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

No that’s wrong. TOTP based 2FA is totally out of band with the only attack vectors being losing your physical device (or a device backup!) or leaking of the secret from the server side.

No that's wrong, authy backs up your TOTP seed to their server and will give them out to anyone who gains access to your authy account and can verify that they can receive sms messages sent to the number associated with the authy account. (Though they are encrypted and authy does not store the encryption keys).

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#88
post #81

Earlier quoted context omitted.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…

> What do we want these companies to do? Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access. And no, restricting data/access and eas…

>Stop giving out my data/access to anyone but me

But the problem is the company doesn't know who "you" are.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#89
post #82
post #81

Earlier quoted context omitted.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…

Is there an absolute requirement to be able to demonstrate your identity over the phone even if you have no secret information with which to confirm it? How about, if you forget your password and can’t get into your account, you need to visit a store in person to show your ID, or mail in a notarized copy, or something like that?

Requiring customers to come to a store would basically exclude anyone from accessing their account outside the retail footprint of the company. That isn't realistic for companies that are trying to provide you a global service like most telecoms.

It also introduces plenty of other problems. For example, if you are mugged on the street and lose your phone and wallet are you just frozen out of your mobile account until you can get to the DMV and wait the month until you get a new ID?

It is a hard problem that can't just be fixed by "taking it seriously".

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#90
post #88

Earlier quoted context omitted.

> What do we want these companies to do? Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access. And no, restricting data/access and eas…

>Stop giving out my data/access to anyone but me But the problem is the company doesn't know who "you" are.

Reasonable attempts at identification validation, especially in these contexts, can be excused when they fail for a very determined actor. But I don't think these attempts are occurring not because the policies aren't there (even though many times they aren't), but because there is a general attitude to not care about what is being protected. If it were my bars of gold you can damn well bet vigilance would be higher.
Post reply on HN