Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

41–50 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#41
post #5

This is frightening. If you're using texts for 2-factor auth you're at the mercy of your phone service provider's customer service. And they're trying to balance being helpful with security, which can be in opposition. Losing $100,000 with no hope of recovery is the kind of thing that could sink many people's finances. His summary of how to avoid having this happen to you: * Use a hardware wallet to secure your crypt…

Good list, and I would add using multisig for serious amounts.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#43
post #15

Large tech companies like Google push 2-factor auth to "increase" security, but this article shows that 2-factor auth with SMS verification opens up a huge security hole since the attacker can access your email if they can get your provider to port your SIM over to their device. Am I missing something and if not how did companies like Google not foresee this huge security hole?

Google offers many different 2 factor methods including Google Prompt, TOTP, and security key - all of which are better choices than SMS. The author is right to say that SMS is not enough but he didn't go far enough: only use SMS-based 2FA if it's your only 2FA choice for your critical accounts, and consider alternative services if it's your only choice.

The issue is that the forgot/lost device flow allows you to remove your more secure 2FA with only SMS verification.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#44
I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone.

I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted?

This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store, and the user had the last 4 of one of my family member's social security number, as well as a fake id. I'm not sure I believe this, but will request more info in writing.

I regained access to my account. The attacker came from IP 216.162.42.85 (santa clara california)

They entered my email and according to google activity logs immediately went after my coinbase account. They got in (joke's on them I didn't have anything). Then they searched my email for 'btc', and also made a visit to my bank website. They weren't able to get access.

As far as I can tell, they were in and out within 10 minutes. I wonder if this was related to the author's experience?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#45
post #9
post #7

How can a mobile carrier operate like this?? No authentication that the request isn't fraudulent? In Sweden I switched to another carrier, still keeping the number in the same name. To do that I got a text message with a code I had to input to initiate the process. When I ported my phone number from my father to me within the same carrier when I turned 18 that required the same confirmation to initiate the process an…

This is not about porting the number to a different carrier or even a different owner though. It's more analogous to getting a replacement SIM card. The last time I had a phone stolen, I went to the carrier's store, they checked my ID, and gave me a replacement SIM. And the things is, if the customer service representative is empowered to do that, they could also be bribed by the attacker.

I checked, to get a replacement sim my carrier sends out inactive cards that needs to be activated through their web service using the printed number on the card.

If you don't have an account you need to contact customer service, and to get through there they most likely authenticate you based on your SSN and an already active app on your phone (BankID) where you input your personal password.

This has actually created problems when people get their stuff stolen abroad. The ID application is authenticated using your bank and a device using your physical bank card, a generated number from the webpage and your pin and then the generated number is put into the webpage. So if you get both phone and card stolen it's essentially impossible to get into your accounts until you can get a new one posted to you. Especially fun if your bills end up in a digital mailbox requiring that login....

Using that app is how essentially all identification is done in Sweden since it's based on an already approved physical device and a personal password. With your bank as insurance that the information is correct based on your physical bank card and the account associated to it.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#46

Federal laws and the protections/insurances a US bank provides would have you without losses right now. Why do we want a decentralized currency again?

A non-federally controlled pseudo-anonymous currency similar to cash has the positive upside of enabling digital privacy in spite of the blockchain. That's why. There are still trustworthy tumbler services to obfuscate and hold your bitcoins similar to a bank. And with what some claim, inarguably so, of government overreach and corporate over-sharing of your personal data, it's something I can sympathize with.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#47
post #13
post #6

> Do not leave funds idle on exchanges or fiat on-ramps. This warning has been publicly repeated hundreds of times since 2010, yet people still insist on ignoring it. The author didn't lose anything. He gave Coinbase his bitcoin in exchange for a promise to pay it back. That deal backfired. > I knew the risks better than most, but never thought something like this could happen to me. There's knowing the risk, and the…

Do you also keep your cash under your mattress, instead of into a bank account?

This is the first analogy that sprang to my mind as well but as they noted Coinbase gets all the upside and you get little in return. When you put your money in a bank typically you earn interest in exchange for the bank having your money.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#49
post #22

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

Lots of places do this. Fidelity, for example, blocks withdrawals for a certain amount of time when some specific actions happen on an account. I believe address changes and adding people to your account with a certain level of access trigger the block.

One of those is Microsoft, which requires you to wait a month before changing your email, and there's no way that I can think of to get that expedited.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#50

> Google Voice 2FA Unfortunately many places are actively refusing to work with Google Voice. I got a message from Bank of America saying specifically that they're removing Google Voice support: > You can't enroll in Zelle with a landline, Google Voice or VOIP (voice over internet protocol) phone number. (Section 3.C.3 Enrolling in the Service) This follows with some other unnamed (because I don't remember them) serv…

If you ported a previous phone number to google voice, how would they know?
Post reply on HN