Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

21–30 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#22

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

Lots of places do this. Fidelity, for example, blocks withdrawals for a certain amount of time when some specific actions happen on an account. I believe address changes and adding people to your account with a certain level of access trigger the block.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#23
That's interesting, I did not know it was possible to have a coinbase acct without working google authenticator.

I found out the hard way it takes over a week of time and multiple verifications and contacts to reset my authenticator when my old phone was broken; as it should be.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#25
> Google Voice 2FA

Unfortunately many places are actively refusing to work with Google Voice. I got a message from Bank of America saying specifically that they're removing Google Voice support:

> You can't enroll in Zelle with a landline, Google Voice or VOIP (voice over internet protocol) phone number. (Section 3.C.3 Enrolling in the Service)

This follows with some other unnamed (because I don't remember them) services which also refuse to work with Google Voice.

That's really unfortunate because I've been using Google Voice for nearly 10 years without issue until recently (when companies specifically remove support...)

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#26

I have a question related to this that someone expert in Bitcoin could answer. Could the victim monitor where the bitcoin (we assume) went to using the public blockchain record? Then, trace it every step of the way (and in whatever chunks it divides into) until it reaches the account of a publicly identifiable entity? At that point, there might be legal recourse in recouping stolen goods (at least, this is how it wor…

[deleted]

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#27

> Google Voice 2FA Unfortunately many places are actively refusing to work with Google Voice. I got a message from Bank of America saying specifically that they're removing Google Voice support: > You can't enroll in Zelle with a landline, Google Voice or VOIP (voice over internet protocol) phone number. (Section 3.C.3 Enrolling in the Service) This follows with some other unnamed (because I don't remember them) serv…

Same with my bank, and I ported my Voice number to my carrier.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#28

I have a question related to this that someone expert in Bitcoin could answer. Could the victim monitor where the bitcoin (we assume) went to using the public blockchain record? Then, trace it every step of the way (and in whatever chunks it divides into) until it reaches the account of a publicly identifiable entity? At that point, there might be legal recourse in recouping stolen goods (at least, this is how it wor…

Truly big heists like the Mt. Gox collapse have received research attention, yes. There are some firms which will follow the transactions and try to find patterns. However, for a relatively small amount like this it's probably futile. It's trivial (though costly) to run the funds through a public mixer several times, or to trade it for Monero, which has a ledger that's much more difficult to analyze.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#29
post #9
post #7

How can a mobile carrier operate like this?? No authentication that the request isn't fraudulent? In Sweden I switched to another carrier, still keeping the number in the same name. To do that I got a text message with a code I had to input to initiate the process. When I ported my phone number from my father to me within the same carrier when I turned 18 that required the same confirmation to initiate the process an…

This is not about porting the number to a different carrier or even a different owner though. It's more analogous to getting a replacement SIM card. The last time I had a phone stolen, I went to the carrier's store, they checked my ID, and gave me a replacement SIM. And the things is, if the customer service representative is empowered to do that, they could also be bribed by the attacker.

It's worse than this though. My colleague had his sim replaced by an attacker in October of last year even though his account had a note on it specifically to prevent this without the account holder being present and showing photo id. Not only can the customer service rep at your carriers store do this but so can the phone reps at all the other stores that sell phones for your carrier such as best buy. The bottom line is that SMS/phone numbers shouldn't be an identifying factor for security purposes.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#30
This is frightfully common in South Africa except aimed at banks - they use SMS as their 2FA. ("SIM swap")

Another common tactic to watch out for: Repeated calling of your phone to annoy you enough so that you switch it off/silent it. That can give the attacker enough time where you don't notice the swap.

Post reply on HN