Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

91–100 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#91
post #68

Earlier quoted context omitted.

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

Authy specifically stores your account in the cloud and can be recovered using SMS. They have a 24 hour warning period during which the email address on file receives multiple notifications that a recovery is being attempted with the option to cancel but if someone has control over your phone number for an extended period of time they can absolutely take over your Authy account. I found this out when my Authy account…

Yes but your backup is encrypted by a password. So even if someone steals your number for long enough to go through recovery, they still need to be able to decrypt the backup.

>this password is not stored anywhere on Authy's servers! If you forget the password and none of your devices are synched, your tokens are lost and you will need to delete them and start over

https://support.authy.com/hc/en-us/articles/115001750008-Bac...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#92
Given the revelation that phone number security just isn't that secure, I have changed my online accounts that allow 2FA to use a crypto key. However, I have found that most seem to only allow crypto keys in addition to a cell phone number. You can't turn it off. Has anyone else noticed this? What is the point of moving to something more secure if you can't get rid of the weak link?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#93
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

I hope he loses, so financial services will stop supporting 2FA over SMS. Is that more or less likely than SMS providers fixing their security?

2FA isn't _this_ problem. It's password resets via SMS that are the problem here.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#94
post #64

Earlier quoted context omitted.

Yes, you have to opt-in to this type of security

Opt-in security is the best form of security, after security by obscurity /s

I prefer both options: opt-in by obscurity.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#95
post #88

Earlier quoted context omitted.

> What do we want these companies to do? Stop giving out my data/access to anyone but me. Once you set a general company attitude towards distribution of data/access, you can't ask for pity when that attitude comes back to bite you. Collect less, lock it down, proliferate it less, etc. Then you'll get my sympathy when an employee at one of your stores gives away my data/access. And no, restricting data/access and eas…

>Stop giving out my data/access to anyone but me But the problem is the company doesn't know who "you" are.

No, the problem is often the company doesn't care. In their defense, they believe they are trying to help you and probably 99% of the time, that is what they are doing.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#96
post #89
post #82

Earlier quoted context omitted.

Is there an absolute requirement to be able to demonstrate your identity over the phone even if you have no secret information with which to confirm it? How about, if you forget your password and can’t get into your account, you need to visit a store in person to show your ID, or mail in a notarized copy, or something like that?

Requiring customers to come to a store would basically exclude anyone from accessing their account outside the retail footprint of the company. That isn't realistic for companies that are trying to provide you a global service like most telecoms. It also introduces plenty of other problems. For example, if you are mugged on the street and lose your phone and wallet are you just frozen out of your mobile account until…

Physical presence wouldn’t be required unless you forgot your credentials. If you are mugged and forgot your password, then you’d be screwed. I’m not sure how reasonable it is to try to make that particular situation better though.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#97
post #34

Earlier quoted context omitted.

> If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information By Kerckhoffs's principle > https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr... a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.

Which gets to the frivolity of the lawsuit. The primarily responsible party, the exchange, is likely a less lucrative target than AT&T.

Which would be the case if Kerckhoff's principle was enshrined in law, which it's not.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#98
post #67
post #45

Earlier quoted context omitted.

And then increase it again by arguing that AT&T should never have made it possible for employees to do this.

And then diminish it to zero again because yes it should be possible for employees to do that. The economic value for most people of being locked out of your phone number and not being able to easily fix the problem or easily upgrade a phone exceeds the cost imposed when some of those people are morons and assume ability to receive an SMS message sent to a particular phone number is any sort of security factor.

"And then diminish it to zero again because yes it should be possible for employees to do that."

Absolutely not. It never should be possible for a single employee to do that with no checks at all.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#99
post #45

Earlier quoted context omitted.

And then increase it again by arguing that AT&T should never have made it possible for employees to do this.

Accountability yes, but holding them responsible for what their service was used for is a slippery slope.

I don't think so. Their service was used to steal someone's phone account, which was then used to steal someone's money.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#100

I hope we see more of this. A lot more. These fuckers need to hurt.

Who, phone companies or cryptocurrency investors?

well, first and foremost phone companies. But also anyone who trust phone companies to protect them
Post reply on HN