I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
81–90 of 137 posts
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#82I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…
How about, if you forget your password and can’t get into your account, you need to visit a store in person to show your ID, or mail in a notarized copy, or something like that?
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#83Earlier quoted context omitted.
> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?
Authy specifically stores your account in the cloud and can be recovered using SMS. They have a 24 hour warning period during which the email address on file receives multiple notifications that a recovery is being attempted with the option to cancel but if someone has control over your phone number for an extended period of time they can absolutely take over your Authy account. I found this out when my Authy account…
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#84Earlier quoted context omitted.
> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?
Authy at least will let you "recover" your account by them sending a text message to the associated phone number. Tap the link in the message and presto, 2FA codes.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#85I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.
In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…
Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access.
And no, restricting data/access and ease of use are not completely mutually exclusive. There is a harmonious middle of the venn diagram that is completely different to the way things are currently run. Nobody's asking to force 2FA on cell phones here (unless we opt-in), we're just asking for better identity verification and less apathy towards giving out my info (in all cases).
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#86Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#87Earlier quoted context omitted.
> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?
No that’s wrong. TOTP based 2FA is totally out of band with the only attack vectors being losing your physical device (or a device backup!) or leaking of the secret from the server side.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#88Earlier quoted context omitted.
In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…
> What do we want these companies to do? Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access. And no, restricting data/access and eas…
But the problem is the company doesn't know who "you" are.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#89Earlier quoted context omitted.
In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…
Is there an absolute requirement to be able to demonstrate your identity over the phone even if you have no secret information with which to confirm it? How about, if you forget your password and can’t get into your account, you need to visit a store in person to show your ID, or mail in a notarized copy, or something like that?
It also introduces plenty of other problems. For example, if you are mugged on the street and lose your phone and wallet are you just frozen out of your mobile account until you can get to the DMV and wait the month until you get a new ID?
It is a hard problem that can't just be fixed by "taking it seriously".
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#90Earlier quoted context omitted.
> What do we want these companies to do? Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access. And no, restricting data/access and eas…
>Stop giving out my data/access to anyone but me But the problem is the company doesn't know who "you" are.