Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

61–70 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#61
post #10
post #7

How can a mobile carrier operate like this?? No authentication that the request isn't fraudulent? In Sweden I switched to another carrier, still keeping the number in the same name. To do that I got a text message with a code I had to input to initiate the process. When I ported my phone number from my father to me within the same carrier when I turned 18 that required the same confirmation to initiate the process an…

In your case, a dedicated attacker could socially engineer the carrier into changing you and your father's contact details and then port the number. $100k is a lifetime's worth of money in some countries, and it can justify a few months worth of recon.

How? I still get a text to my physical phone with the active number being ported and use the code supplied to initiate the process.

Somehow making them change my contact details would just end up with the bills being sent to the wrong place, if you still have paper bills and don't have it automatically paid or goes to a digital mailbox.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#62

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

> And while we are doing PSAs, I'd like to give one piece of seemingly conflicting advice: make sure you have backups of your multi-factor authentication systems. Yes! Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. The underlying keys can be manually shown and entered elsewhere if needed, and can be backed up with everything else that's valuable. > Print out 2-factor backu…

>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs.

Personally I don't really like this feature and urge people to avoid it for "high security accounts".

It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password).

That's not to say it's useless, at the very least it's another layer that attackers have to figure out. But the true benefits of 2FA come from needing multiple devices to access accounts. If all of the factors are stored in one program on one device, then in the situation where that device/program is cracked, the attackers have everything.

Still, if you are going to choose between no 2FA and "2FA stored in your password manager", choose the password manager! And if you are going to choose between SMS-2FA, and the password manager, choose the password manager! But if you really want better security for not much more work, store your 2FA on a different device!

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#63
post #18

"I treated Coinbase like a bank account and you have absolutely zero recourse in the case of an attack." Now that's the real problem. Coinbase acts like a bank or a broker/dealer, but isn't regulated like one.

That and Bitcoin is specifically designed to not give you a recourse in case of an attack.

Cryptocurrency designers seem to think that banking was designed as a mistake without anyone thinking. That laws people wanted were just unfortunate side effects.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#64

Federal laws and the protections/insurances a US bank provides would have you without losses right now. Why do we want a decentralized currency again?

A non-federally controlled pseudo-anonymous currency similar to cash has the positive upside of enabling digital privacy in spite of the blockchain. That's why. There are still trustworthy tumbler services to obfuscate and hold your bitcoins similar to a bank. And with what some claim, inarguably so, of government overreach and corporate over-sharing of your personal data, it's something I can sympathize with.

Similar to a bank as in a guaranteed insurance of my funds, like the FDIC in the US?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#65
post #13
post #6

> Do not leave funds idle on exchanges or fiat on-ramps. This warning has been publicly repeated hundreds of times since 2010, yet people still insist on ignoring it. The author didn't lose anything. He gave Coinbase his bitcoin in exchange for a promise to pay it back. That deal backfired. > I knew the risks better than most, but never thought something like this could happen to me. There's knowing the risk, and the…

Do you also keep your cash under your mattress, instead of into a bank account?

Coinbase is not regulated like a bank. Just to pick a relevant point, if someone makes an unauthorized withdrawal from your bank account, that is fraud and your liability is limited. The bank has responsibility for making sure they identify you. https://budgeting.thenest.com/banks-liability-there-identity...

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#66
post #5

This is frightening. If you're using texts for 2-factor auth you're at the mercy of your phone service provider's customer service. And they're trying to balance being helpful with security, which can be in opposition. Losing $100,000 with no hope of recovery is the kind of thing that could sink many people's finances. His summary of how to avoid having this happen to you: * Use a hardware wallet to secure your crypt…

There may not be a choice. Vanguard refused to log me in until I configured 2-factor SMS.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#67

I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out. Hence, avoiding the sim hack. They can port out if they hack my "shadow" google account. The trick is to never use the shadow account for anything. Hence, the attackers have no way to get to your google voice.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#68
post #5

This is frightening. If you're using texts for 2-factor auth you're at the mercy of your phone service provider's customer service. And they're trying to balance being helpful with security, which can be in opposition. Losing $100,000 with no hope of recovery is the kind of thing that could sink many people's finances. His summary of how to avoid having this happen to you: * Use a hardware wallet to secure your crypt…

[deleted]

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#69
post #13
post #6

> Do not leave funds idle on exchanges or fiat on-ramps. This warning has been publicly repeated hundreds of times since 2010, yet people still insist on ignoring it. The author didn't lose anything. He gave Coinbase his bitcoin in exchange for a promise to pay it back. That deal backfired. > I knew the risks better than most, but never thought something like this could happen to me. There's knowing the risk, and the…

Do you also keep your cash under your mattress, instead of into a bank account?

Someone please correct me if I'm wrong, but at least in the US banks take on all risk of fraud. If someone starts writing bad checks in your name, that's ultimately the bank's problem rather than yours.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#70

Earlier quoted context omitted.

> And while we are doing PSAs, I'd like to give one piece of seemingly conflicting advice: make sure you have backups of your multi-factor authentication systems. Yes! Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. The underlying keys can be manually shown and entered elsewhere if needed, and can be backed up with everything else that's valuable. > Print out 2-factor backu…

>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…

What's a good secondary service to store the TOTP codes separate from passcodes?

Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method

Google authenticator can't be backedup, which is royally annoying when you change/lose devices

Lastpass has some security issues, and one well known comment here has recommended no one use it.

I heard someone say they use Duo security: does that let you store codes? When I looked it just seemed to lock various services

Post reply on HN