Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

121–130 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#121
post #103

Earlier quoted context omitted.

There are of course two sides to every coin. The flip side is, cell carriers never signed up to be a secure identification mechanism. SMS wasn't designed for security, and there's little financial incentive for them to invest in those changes, i.e., they don't charge you more for secure authorization of 3rd party platforms. I think its very akin to the US Social Security Number being used as a 'secure' identification…

That's a good point in general; NIST recommends not using SMS for challenge-response authentication. I don't know whether in this case the victim was using SMS codes, or whether the attacker used their phone number as part of a more involved attack (e.g. calling customer support and impersonating the victim). Even if you don't use SMS codes, there are a number of attacks that are opened up if someone seizes your cell…

I work in fraud prevention. While it's not yet a typical attack, it is does happen regularly.

Usually the attack is done against an individual who is known to have significant crypto assets and is using Gmail. By default if you enable 2fa on your Gmail account, sms based 2fa is activated as backup.

The attacker social engineers the phone provider to port the victims number, then resets the victims Gmail account, uses Android device manager to wipe their devices, and using the details found in Gmail they proceed to gain access to other accounts owned by the victim. The main goal being to social engineer access to services where they store crypto or to find unencrypted wallet backups in the cloud.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#122

Earlier quoted context omitted.

I hope he loses, so financial services will stop supporting 2FA over SMS. Is that more or less likely than SMS providers fixing their security?

How about he wins, and then we slowly wean off a more secure SMS system for everybody?

There are plenty of secure messaging services out there. Making one that works for everyone is not a trivial problem.

Suppose you own a coffee shop and offer free wifi, should you be held responsible if someone logs into a bank without SSL and gets their credentials sniffed?

Should you be responsible for designing a wifi protocol that uniquely encrypts the traffic of each user, without shared keys, to prevent sniffing?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#123
post #84

Earlier quoted context omitted.

Authy at least will let you "recover" your account by them sending a text message to the associated phone number. Tap the link in the message and presto, 2FA codes.

This is exactly the kind of feature you don't want...

It requires a password to decrypt the contents of the synced 2FAs.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#124
post #93

Earlier quoted context omitted.

2FA isn't _this_ problem. It's password resets via SMS that are the problem here.

SMS is 2FA. I'm sure you mean TOTP, but it's an important distinction to make. All 2FA isn't created equal.

sms password resets are not 2fa. 2fa means you have two factors of authentication. If the only thing you need to authenticate is control over a phone number, then that's just one factor.

Two factor authentication is when you need both a password and an SMS token, like how GitHub does it.

I'm not saying SMS 2fa is strong enough, often passwords are weak and/or weakly guarded, and ostensibly phone numbers can be fidgeted with. But having a phone number be the only thing guarding your entire identity is a whole next level of weak.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#126
post #41

Are there any phone companies that have decent security practices? As far as I can tell switching is pointless because they're all awful in this regard.

That's the wrong question to ask. There are no financial institutions that have proper 2FA. I don't know of a single bank in the US that uses any standard 2FA. They all use SMS. Recently, I found that you can make paypal (US) use TOTP 2FA with a workaround. I recommend everyone to do that.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#127
post #60

Earlier quoted context omitted.

A "baseless allegation" is one with no evidence or reason. This guy has a reason and presumably evidence, so his allegations are not baseless. A baseless allegation would be if I were suing AT&T for losing all my crypto investments. I have none and am not an AT&T customer. An "allegation without merit" means no rational interpretation of the law would result in a guilty conviction of the allegations. Baseless ones ar…

You think that lawyers say an allegation is "baseless" iff it is baseless? That's an interesting epistemic outlook.

No, I'm providing definitions and using myself in an example. Please do not put words in my mouth.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#128
post #97

Earlier quoted context omitted.

Which gets to the frivolity of the lawsuit. The primarily responsible party, the exchange, is likely a less lucrative target than AT&T.

Which would be the case if Kerckhoff's principle was enshrined in law, which it's not.

But it is deeply central for designing any secure system that one can really argue that it is a disregard of due diligence when not followed.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#129
post #105

Earlier quoted context omitted.

Exactly. You can always debate specific security practices. But there's definitely a tradeoff between resistance to social engineering and related attacks on the one hand and convenience on the other hand. You give one example. It also applies when people lose the password for an account, no longer have access to their original or backup email, etc. The most secure thing to do is probably to tell the customer "tough.…

What if carriers created an "enhanced security mode," which users can opt-in to if they want more security and are okay with sacrificing convenience in case of account recovery? It would be similar to the account recovery aspect of Google's Advanced Protection Program: "A common way that hackers try to access your account is by impersonating you and pretending they have been locked out of your account. To give you th…

Mr. Terpin had enrolled to such enhanced security program from AT&T. AT&T broke their own rules. Thus, the lawsuit.

Thread https://twitter.com/stephendpalley/status/102973234509876428...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#130
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

  our phone numbers are more a part of 
  our identity than ever before
Okay, great idea: phone numbers are the new social security number.

Oh but wait, not really. Not when I can set up a prepaid phone for $30. Or three for $90. Or what about office phones and VOIP services that accept text messages on office desktop phones. Or virtual services like twilio, and on and on.

Yeah, not really. Phones aren’t quite anyone’s identity at all.

Don’t pretend like the world is so beholden to some AOL homepage instagram vanity account, signed up with a free email address.

Post reply on HN