Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

101–110 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#101
post #81
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…

I think there could be a sliding scale of sorts, with the last resort as sorry, you must visit a store.

Perhaps a series of strong security questions(no 'mothers maiden name' type), and if failed, you must present ID at a physical location.

Perhaps a copy of an ID or other photo on file that you could match/resend?

Maybe an option to 'lock' the account to changes, that can only be unlocked by the user when logged in, or by visiting a store?

Just off the top of my head, I can think of hundreds of things these companies could be doing better..many of which are not 100% foolproof, but far ahead of what they're doing now.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#103
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

There are of course two sides to every coin. The flip side is, cell carriers never signed up to be a secure identification mechanism. SMS wasn't designed for security, and there's little financial incentive for them to invest in those changes, i.e., they don't charge you more for secure authorization of 3rd party platforms. I think its very akin to the US Social Security Number being used as a 'secure' identification in many cases.

I imagine a world where you go into the cell store, and they demand three forms of identification including a utility bill to talk to you. I can already hear the complaints from a much larger portion of their customer base.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#104
post #103
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

There are of course two sides to every coin. The flip side is, cell carriers never signed up to be a secure identification mechanism. SMS wasn't designed for security, and there's little financial incentive for them to invest in those changes, i.e., they don't charge you more for secure authorization of 3rd party platforms. I think its very akin to the US Social Security Number being used as a 'secure' identification…

I just want a world where you go into a cell store, and they don't tell you they've got a great idea, just make your PIN your birthdate.

If they actually took part that seriously, most identification could be done with a PIN or a password or whatever and the serious identification could be reserved for people who've actually forgotten.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#105
post #103
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

There are of course two sides to every coin. The flip side is, cell carriers never signed up to be a secure identification mechanism. SMS wasn't designed for security, and there's little financial incentive for them to invest in those changes, i.e., they don't charge you more for secure authorization of 3rd party platforms. I think its very akin to the US Social Security Number being used as a 'secure' identification…

Exactly. You can always debate specific security practices. But there's definitely a tradeoff between resistance to social engineering and related attacks on the one hand and convenience on the other hand.

You give one example. It also applies when people lose the password for an account, no longer have access to their original or backup email, etc. The most secure thing to do is probably to tell the customer "tough." But that won't go over very well so account recovery practices get put in place that are probably susceptible to social engineering attacks.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#106
post #68

Earlier quoted context omitted.

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

Authy specifically stores your account in the cloud and can be recovered using SMS. They have a 24 hour warning period during which the email address on file receives multiple notifications that a recovery is being attempted with the option to cancel but if someone has control over your phone number for an extended period of time they can absolutely take over your Authy account. I found this out when my Authy account…

Storing your account in the cloud is optional with Authy at least.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#107
post #83

Earlier quoted context omitted.

Authy specifically stores your account in the cloud and can be recovered using SMS. They have a 24 hour warning period during which the email address on file receives multiple notifications that a recovery is being attempted with the option to cancel but if someone has control over your phone number for an extended period of time they can absolutely take over your Authy account. I found this out when my Authy account…

I mentioned this because I know multiple people who've had authy / other authenticators compromised down the line from social engineering attacks. Even if you can be alerted, usually it's too late by the time you realize what's happened to your creds.

Did they not put a password on the Authy backup?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#108
post #103
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

There are of course two sides to every coin. The flip side is, cell carriers never signed up to be a secure identification mechanism. SMS wasn't designed for security, and there's little financial incentive for them to invest in those changes, i.e., they don't charge you more for secure authorization of 3rd party platforms. I think its very akin to the US Social Security Number being used as a 'secure' identification…

That's a good point in general; NIST recommends not using SMS for challenge-response authentication.

I don't know whether in this case the victim was using SMS codes, or whether the attacker used their phone number as part of a more involved attack (e.g. calling customer support and impersonating the victim). Even if you don't use SMS codes, there are a number of attacks that are opened up if someone seizes your cell phone number.

In general, however, I think it would be a good thing if service providers were held liable for damages occurring due to account breaches; that's the only way we're going to get proper account security. Schneier has written on this subject extensively, e.g. https://www.schneier.com/essays/archives/2003/11/liability_c....

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#109
post #64

Earlier quoted context omitted.

Opt-in security is the best form of security, after security by obscurity /s

I prefer both options: opt-in by obscurity.

Sueing tge internet to force it to forget your number?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#110
post #105
post #103

Earlier quoted context omitted.

There are of course two sides to every coin. The flip side is, cell carriers never signed up to be a secure identification mechanism. SMS wasn't designed for security, and there's little financial incentive for them to invest in those changes, i.e., they don't charge you more for secure authorization of 3rd party platforms. I think its very akin to the US Social Security Number being used as a 'secure' identification…

Exactly. You can always debate specific security practices. But there's definitely a tradeoff between resistance to social engineering and related attacks on the one hand and convenience on the other hand. You give one example. It also applies when people lose the password for an account, no longer have access to their original or backup email, etc. The most secure thing to do is probably to tell the customer "tough.…

What if carriers created an "enhanced security mode," which users can opt-in to if they want more security and are okay with sacrificing convenience in case of account recovery?

It would be similar to the account recovery aspect of Google's Advanced Protection Program: "A common way that hackers try to access your account is by impersonating you and pretending they have been locked out of your account. To give you the strongest protection against this type of fraudulent account access, Advanced Protection adds extra steps to verify your identity during the account recovery process. If you ever lose access to your account and both of your Security Keys, these added verification requirements will take a few days to restore access to your account."[1]

[1] https://landing.google.com/advancedprotection

Post reply on HN