Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

81–90 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#81

I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…

This is awesome. Thank you for sharing.

I wish more people knew that their entire identity hinges on a store clerk at AT&T.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#82
post #21

Is there a mobile carrier focusing on security? something like what CF (and others) are doing with domains

I would think that an online-only MVNO like Ting.com would be harder to fool - even if their call agent fell for the trick, they'd still have to mail a new sim out. But you'd have to log in yourself to swap the sim using the Ting website. As I understand it, attacker would have to fool you and coax you to swap the sim.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#84
post #70

Earlier quoted context omitted.

>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…

What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…

I use Authenticator Plus (https://play.google.com/store/apps/details?id=com.mufri.auth...) which has encrypted cloud backup (Google Drive or Dropbox). The encryption is done client-side. When I get a new phone, all I do is set up A+'s cloud sync on the new phone, enter the passphrase I've used previously, and it syncs all my TOTP codes.

As a bonus, the backup is just an encrypted sqlite DB (with dirt-simple schema), so you're not tied to some inscrutable proprietary format, and can easily extract the tokens if you want to use a different app/service.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#85
post #6

> Do not leave funds idle on exchanges or fiat on-ramps. This warning has been publicly repeated hundreds of times since 2010, yet people still insist on ignoring it. The author didn't lose anything. He gave Coinbase his bitcoin in exchange for a promise to pay it back. That deal backfired. > I knew the risks better than most, but never thought something like this could happen to me. There's knowing the risk, and the…

And yet if he'd kept it on his own machine there's myriad other vectors from compromised wallets to typos that would separate even the veteran "investor" from their crypto. And we'd be blaming him again, just as you are now, because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology. This is the fundamental problem with crypto, it's irreversible and decentralized. These aren't features, they're bugs.

If this were real money or real assets, he'd be able to call his bank and be made whole by the close of business, I wager. Instead he's out a down-payment, SFYL.

I can't believe these shenanigans are allowed to play out as though we're all okay with this being the future of currency.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#86
post #70

Earlier quoted context omitted.

>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…

What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…

You can disable "multi device" mode in Authy, this prevents adding new devices via SMS auth.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#87

Federal laws and the protections/insurances a US bank provides would have you without losses right now. Why do we want a decentralized currency again?

Because it covers the use cases of cash but for online. Sometimes you're willing to have no safety guarantees but also not have to deal with paypal etc. Send a small tip to a content creator, pay content creators in small amounts in a patreon-like setting without having to deal with rules against content payment processors don't like (I saw recently this was being launched but I forget the name), lots of use cases.

I really need to call out crypto shill when I see it. As it stands, bitcoin is utterly unusable for micropayments, the transaction fees are way too high for that. There has been attempts at creating micropayment services on top, these all have failed to gain traction.

I still maintain as I did several times here in the past: bitcoin (and in general, crypto"currencies" because they are not currencies) are a scam, a new kind of scam for sure but a scam nonetheless. There are simply no (legit) use cases.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#89

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

> Sure, having your accounts taken over is awful, and it can happen to anyone, but something just as bad is losing your 2-factor systems and being locked out of accounts with no way to recover them.

+1. I lost a phone and with it my Cloudflare 2FA. For some reason, Cloudflare won't let you contact tech support without logging in. There is no contact info for support on their website, AT ALL, so if you can't log in, you're fucked.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#90
post #86
post #70

Earlier quoted context omitted.

What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…

You can disable "multi device" mode in Authy, this prevents adding new devices via SMS auth.

Even when you authenticate via SMS in multi device mode, the imported tokens still have to be decrypted via a master password. SMS is just your account identifier on Authy, hijacking it will not allow access to your tokens on its own.
Post reply on HN