Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

111–120 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#112
Who the hell keeps $24M worth of crypto on a phone? I only trust open source systems, do all large transactions on fresh Linux, disable JS if I have to use the browser, never visit any unusual websites, nothing not related to the process.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#113
post #60

Earlier quoted context omitted.

A "baseless allegation" is one with no evidence or reason. This guy has a reason and presumably evidence, so his allegations are not baseless. A baseless allegation would be if I were suing AT&T for losing all my crypto investments. I have none and am not an AT&T customer. An "allegation without merit" means no rational interpretation of the law would result in a guilty conviction of the allegations. Baseless ones ar…

You think that lawyers say an allegation is "baseless" iff it is baseless? That's an interesting epistemic outlook.

“If the facts are against you, argue the law. If the law is against you, argue the facts. If the law and the facts are against you, pound the table and yell like hell.”

I suspect good lawyers refrain from falsely alleging a claim is baseless when they have more sound arguments to make, and they save the histrionics for table pounding occasions.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#114
post #31

Sorry for his loss, and the mobile providers do need to do something about this known attack vector. But with cryptocurrencies you need to "be you own bank", and extending his own analogy how many legitimate or long lasting banks would store USD24 million in cash in a hotel room safe?

Following this analogy, would the bank sue the builder or vault manufacturer if they gave someone a key to the vault without the bank's knowledge and it was used to rob the vault? Or might the bank sue a armored carrier for irresponsibly storing monies that were stolen in transit between banks? Maybe you can be your own bank, but banks have to depend on external factors/entities to do what they're supposed to do as w…

Seems reasonable, because bank vaults and armoured vehicles are designed specifically for protecting high value items. Hotel room safes on the other hand are not (in fact some even have a disclaimer advising you not to store valuables in them).

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#116
post #68
post #54

While I was working at a blockchain forensics company (we built one of the first AI backed block-explorers both for Bitcoin and Ethereum & our service was also used to identify the DAO hack), both myself and my boss were targeted multiple times a year with this kind of attack even though we held no crypto through the company. It seemed that just since my name was on the web with the word crypto I was a target. To thi…

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen. I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

[deleted]

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#117
post #41

Are there any phone companies that have decent security practices? As far as I can tell switching is pointless because they're all awful in this regard.

My snarky answer is use an MVNO that will both show up as the base carrier to any searching online/number lookups, and has completely useless clueless terrible support that either couldn't or wouldn't redirect like this.

Assuming you even have to use SMS, get some weird walmart mobile service that you can't even really call for support.

It's security through obscurity but they often literally wont let you port your number out without absurd gymnastics, the support people don't know how, their crappy web based management system the CSRs use doesn't have a button, etc.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#118
post #93

Earlier quoted context omitted.

I hope he loses, so financial services will stop supporting 2FA over SMS. Is that more or less likely than SMS providers fixing their security?

2FA isn't _this_ problem. It's password resets via SMS that are the problem here.

SMS is 2FA.

I'm sure you mean TOTP, but it's an important distinction to make. All 2FA isn't created equal.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#119
post #101
post #81

Earlier quoted context omitted.

In my opinion "take security more seriously" is too nebulous to be constructive here. What do we want these companies to do? Security is an incredibly hard problem. It is only exacerbated when we go years without speaking with one of these companies. Anything that you have to remember in that time whether it is a password, pin code, or "who was your childhood hero" type security questions can all be forgotten. How el…

I think there could be a sliding scale of sorts, with the last resort as sorry, you must visit a store. Perhaps a series of strong security questions(no 'mothers maiden name' type), and if failed, you must present ID at a physical location. Perhaps a copy of an ID or other photo on file that you could match/resend? Maybe an option to 'lock' the account to changes, that can only be unlocked by the user when logged in,…

> Maybe an option to 'lock' the account to changes, that can only be unlocked by the user when logged in, or by visiting a store?

AT&T sorta offers this - there's an enhanced security option that lets you provide a password or PIN if you want to make account changes. This is allowed in lieu of ID.

My AT&T account is technically still tied to my father-in-law, because my wife and I took it over over a decade ago, when we were still in college. They no longer have AT&T phones and I consider it my account, but whenever I visit a store I have to provide the password before I can upgrade my phone or change the service plan. To move the account into my name would require me and my FIL to visit a store together, which is inconvenient enough that we've not bothered.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#120
post #87
post #75

Earlier quoted context omitted.

No that’s wrong. TOTP based 2FA is totally out of band with the only attack vectors being losing your physical device (or a device backup!) or leaking of the secret from the server side.

No that's wrong, authy backs up your TOTP seed to their server and will give them out to anyone who gains access to your authy account and can verify that they can receive sms messages sent to the number associated with the authy account. (Though they are encrypted and authy does not store the encryption keys).

That's a vulnerability of Authy's service, not TOTP.

I have some of my more important services tied to an older Yubikey. The only attack vectors for it would be on the server-side and the physical key.

Post reply on HN