Also, in what world when he lost $24M can he sue for $224M? Entited to a 10x return because of his own neglegence. Nope!
Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
111–120 of 137 posts
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#112Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#113Earlier quoted context omitted.
A "baseless allegation" is one with no evidence or reason. This guy has a reason and presumably evidence, so his allegations are not baseless. A baseless allegation would be if I were suing AT&T for losing all my crypto investments. I have none and am not an AT&T customer. An "allegation without merit" means no rational interpretation of the law would result in a guilty conviction of the allegations. Baseless ones ar…
You think that lawyers say an allegation is "baseless" iff it is baseless? That's an interesting epistemic outlook.
I suspect good lawyers refrain from falsely alleging a claim is baseless when they have more sound arguments to make, and they save the histrionics for table pounding occasions.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#114Sorry for his loss, and the mobile providers do need to do something about this known attack vector. But with cryptocurrencies you need to "be you own bank", and extending his own analogy how many legitimate or long lasting banks would store USD24 million in cash in a hotel room safe?
Following this analogy, would the bank sue the builder or vault manufacturer if they gave someone a key to the vault without the bank's knowledge and it was used to rob the vault? Or might the bank sue a armored carrier for irresponsibly storing monies that were stolen in transit between banks? Maybe you can be your own bank, but banks have to depend on external factors/entities to do what they're supposed to do as w…
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#115Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#116While I was working at a blockchain forensics company (we built one of the first AI backed block-explorers both for Bitcoin and Ethereum & our service was also used to identify the DAO hack), both myself and my boss were targeted multiple times a year with this kind of attack even though we held no crypto through the company. It seemed that just since my name was on the web with the word crypto I was a target. To thi…
> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#117Are there any phone companies that have decent security practices? As far as I can tell switching is pointless because they're all awful in this regard.
Assuming you even have to use SMS, get some weird walmart mobile service that you can't even really call for support.
It's security through obscurity but they often literally wont let you port your number out without absurd gymnastics, the support people don't know how, their crappy web based management system the CSRs use doesn't have a button, etc.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#118Earlier quoted context omitted.
I hope he loses, so financial services will stop supporting 2FA over SMS. Is that more or less likely than SMS providers fixing their security?
2FA isn't _this_ problem. It's password resets via SMS that are the problem here.
I'm sure you mean TOTP, but it's an important distinction to make. All 2FA isn't created equal.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#119Earlier quoted context omitted.
In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…
I think there could be a sliding scale of sorts, with the last resort as sorry, you must visit a store. Perhaps a series of strong security questions(no 'mothers maiden name' type), and if failed, you must present ID at a physical location. Perhaps a copy of an ID or other photo on file that you could match/resend? Maybe an option to 'lock' the account to changes, that can only be unlocked by the user when logged in,…
AT&T sorta offers this - there's an enhanced security option that lets you provide a password or PIN if you want to make account changes. This is allowed in lieu of ID.
My AT&T account is technically still tied to my father-in-law, because my wife and I took it over over a decade ago, when we were still in college. They no longer have AT&T phones and I consider it my account, but whenever I visit a store I have to provide the password before I can upgrade my phone or change the service plan. To move the account into my name would require me and my FIL to visit a store together, which is inconvenient enough that we've not bothered.
Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M
#120Earlier quoted context omitted.
No that’s wrong. TOTP based 2FA is totally out of band with the only attack vectors being losing your physical device (or a device backup!) or leaking of the secret from the server side.
No that's wrong, authy backs up your TOTP seed to their server and will give them out to anyone who gains access to your authy account and can verify that they can receive sms messages sent to the number associated with the authy account. (Though they are encrypted and authy does not store the encryption keys).
I have some of my more important services tied to an older Yubikey. The only attack vectors for it would be on the server-side and the physical key.