Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

131–137 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#131
post #121

Earlier quoted context omitted.

That's a good point in general; NIST recommends not using SMS for challenge-response authentication. I don't know whether in this case the victim was using SMS codes, or whether the attacker used their phone number as part of a more involved attack (e.g. calling customer support and impersonating the victim). Even if you don't use SMS codes, there are a number of attacks that are opened up if someone seizes your cell…

I work in fraud prevention. While it's not yet a typical attack, it is does happen regularly. Usually the attack is done against an individual who is known to have significant crypto assets and is using Gmail. By default if you enable 2fa on your Gmail account, sms based 2fa is activated as backup. The attacker social engineers the phone provider to port the victims number, then resets the victims Gmail account, uses…

The previous best option I was aware of with Gmail was to add a pair of Yubikeys, then explicitly remove your cellphone from the account, to close the gap you mention.

Now there is https://landing.google.com/advancedprotection/, which might be a better option -- interested to know if you've got any opinions on that scheme.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#132
post #127

Earlier quoted context omitted.

You think that lawyers say an allegation is "baseless" iff it is baseless? That's an interesting epistemic outlook.

No, I'm providing definitions and using myself in an example. Please do not put words in my mouth.

You provided unnecessary and unhelpful definitions, from my perspective.

I assume as axiomatic (and required by HN guidelines) that you intended to be helpful and relevant, so I asked a question to determine what you were thinking.

If you do not think lawyers use the "baseless" language in a totally transparent, sincere way, then I would've expected you to be more interested in when and how they do that, which is the discussion I was looking for, if any.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#133
post #127

Earlier quoted context omitted.

No, I'm providing definitions and using myself in an example. Please do not put words in my mouth.

You provided unnecessary and unhelpful definitions, from my perspective. I assume as axiomatic (and required by HN guidelines) that you intended to be helpful and relevant, so I asked a question to determine what you were thinking. If you do not think lawyers use the "baseless" language in a totally transparent, sincere way, then I would've expected you to be more interested in when and how they do that, which is the…

Wow, if that's how you really feel. Your eagerness to fall back to rules lawyering to justify your behavior instead of reflecting where our misunderstanding is and working to resolve it, is the kind of toxic online behavior I will gladly get dinged for.

I will help you and go ahead and flag all of my posts in this thread so dang and others can take moderative actions against me.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#135

How can he prove he did posses this amount of crypto currency and is not making everything up? With a system without any regulation nor oversight where you have to play your own bank, this is exactly what you’ve signed up for...

He still has the private keys that control addresses that can be shown from the blockchain to have had the coins until the hack.

What is harder to prove is that he doesn't also control the new addresses where the funds were transferred to.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#136

Given the revelation that phone number security just isn't that secure, I have changed my online accounts that allow 2FA to use a crypto key. However, I have found that most seem to only allow crypto keys in addition to a cell phone number. You can't turn it off. Has anyone else noticed this? What is the point of moving to something more secure if you can't get rid of the weak link?

Yeah it really makes you think of all the other methods you might not even know about. My bank has an mobile app to connect that I'm not using because I don't trust it, but what if it's indeed insecure and someone else exploit it...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#137

Earlier quoted context omitted.

Sure.. you can sue for whatever you want. There is no guarantee that you will be awarded the damages though.

This kind-of comment would have been clever in elementary school. Here, you're just being a dick.

Sorry I really wasn't trying to be a dick here. The original post asked whether one party could sue instead of being responsible. It is possible that this is why my post seems childish.

The point I was trying to make was about conflating the damages being sought in a lawsuit by one party and the actual damages owed by other other in a lawsuit. I think it is pretty common practice for the plaintiff pick a high number out of somewhat thin air to prevent themselves from pricing themselves from leaving money on the table.

Post reply on HN