Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

31–40 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#31
post #15

Large tech companies like Google push 2-factor auth to "increase" security, but this article shows that 2-factor auth with SMS verification opens up a huge security hole since the attacker can access your email if they can get your provider to port your SIM over to their device. Am I missing something and if not how did companies like Google not foresee this huge security hole?

Google offers many different 2 factor methods including Google Prompt, TOTP, and security key - all of which are better choices than SMS. The author is right to say that SMS is not enough but he didn't go far enough: only use SMS-based 2FA if it's your only 2FA choice for your critical accounts, and consider alternative services if it's your only choice.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#32

I have a question related to this that someone expert in Bitcoin could answer. Could the victim monitor where the bitcoin (we assume) went to using the public blockchain record? Then, trace it every step of the way (and in whatever chunks it divides into) until it reaches the account of a publicly identifiable entity? At that point, there might be legal recourse in recouping stolen goods (at least, this is how it wor…

Kinda but it's hard and there are measures to counter this. There is one thing called coinjoin which attempts to tumble coins.

Imagine you stole 10 btc and you split it to 10 outputs of 1 btc each. Then you use 2 of them to perform a coinjoin with several other people where in a single transaction 10 inputs of 1 btc (2 of them yours) produce 10 outputs of 1 btc (again 2 of them yours). There is no way to tell which coin is which anymore. Of course this requires some degree of interaction with other people but in other coins such as grin that use the mimblewimble protocol this happens automatically for every block.

Another thing you can do is try to do an atomic swap with someone on another blockchain i.e Litecoin. In this case you send your coins to a specific script address, the other person sends his LTC to another script address and you effectively swap BTC with LTC.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#33
This is the kind of stuff that convinces me we'll never see mass adoption of cryptocurrency -- or that if we do, it will be only by replicating the existing financial system and slapping a cryptocurrency label on it.

If security engineers at cryptocurrency firms are getting hacked, what hope do mom & pop user have? And once your money is stolen, you have basically zero recourse and no way to reverse the transaction. I know many proponents consider that a feature, but I'm telling you for the average user, it is absolutely a bug.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#34
Sucks to be the OP but storing any crypto in an exchange is idiotic and literally the first thing on any list of "how to secure your crypto" is to not do it. This shows the OP is just being willfully ignorant.

Exchanges get hacked or are victims of internal fraud at a level that is far beyond any acceptable risk. https://coinsutra.com/biggest-bitcoin-hacks/

If you have any kind of serious crypto holdings, you should either be using hardware wallets or a PC that you only use for crypto. Nothing else. * Buy crypto, transfer to your PC, turn off PC.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#37

Federal laws and the protections/insurances a US bank provides would have you without losses right now. Why do we want a decentralized currency again?

Because it covers the use cases of cash but for online. Sometimes you're willing to have no safety guarantees but also not have to deal with paypal etc. Send a small tip to a content creator, pay content creators in small amounts in a patreon-like setting without having to deal with rules against content payment processors don't like (I saw recently this was being launched but I forget the name), lots of use cases.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#38
This person's Google account is likely still vulnerable to the attacker and if they used chrome password sync all of their other accounts are also likely owned. You can recover a google account if you know some basic details such as a previously used password or the creation date of an account. After having a google account owned enrollment in the advanced protection program and ensuring only the strongest recovery methods are enabled are best next steps.

https://landing.google.com/advancedprotection/

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#39

Federal laws and the protections/insurances a US bank provides would have you without losses right now. Why do we want a decentralized currency again?

Who doesn't want to learn the lessons of the last millennia of finance all over again?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#40

Sucks to be the OP but storing any crypto in an exchange is idiotic and literally the first thing on any list of "how to secure your crypto" is to not do it. This shows the OP is just being willfully ignorant. Exchanges get hacked or are victims of internal fraud at a level that is far beyond any acceptable risk. https://coinsutra.com/biggest-bitcoin-hacks/ If you have any kind of serious crypto holdings, you should…

For any significant crypto holdings you should be using a hardware wallet, and for serious holdings you should also use a multisig setup.
Post reply on HN