Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

121–130 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#121
post #66
post #5

This is frightening. If you're using texts for 2-factor auth you're at the mercy of your phone service provider's customer service. And they're trying to balance being helpful with security, which can be in opposition. Losing $100,000 with no hope of recovery is the kind of thing that could sink many people's finances. His summary of how to avoid having this happen to you: * Use a hardware wallet to secure your crypt…

There may not be a choice. Vanguard refused to log me in until I configured 2-factor SMS.

Vanguard can work with Yubikeys now.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#122
>Do not leave funds idle on exchanges or fiat on-ramps. I treated Coinbase like a bank account and you have absolutely zero recourse in the case of an attack. I knew the risks better than most, but never thought something like this could happen to me

I wonder why he'd think that. Disregarding the risk of you getting phished/hacked (which you can prevent), there's nothing you can do about coinbase getting hacked (eg. mt gox), running away with the funds, losing their funds because of incompetence (eg. quadrigacx), or locking your account and taking months to unlock.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#123

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

[deleted]

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#124
It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack.

The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading cryptocurrency custody solution! His job is literally to secure and protect institutional cryptocurrency wallets, and to publicly tell the world how careless he was with his own personal account looks extremely poorly on his employer despite the fact that this was an unrelated incident.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#125

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

Oy, does that mean Authy is vulnerable to this?

https://authy.com/phones/reset/?proceed=true

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#126
post #125

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

Oy, does that mean Authy is vulnerable to this? https://authy.com/phones/reset/?proceed=true

Authy backups are encrypted with a password (at least, if you set them to), so you can't gain access with just the phone number.

However I believe their "OneTouch" system (e.g. Twitch & Namecheap) is linked to phone numbers only, so that could be breached via SMS.

I'd recommend using a standalone 2FA app which can be backed up to your own cloud storage. (e.g. Google Drive/Dropbox)

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#127
post #124

It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…

It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones.

IMO its great to learn about what goes well but super valuable to learn when people face-plant.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#128
post #87

Earlier quoted context omitted.

Because it covers the use cases of cash but for online. Sometimes you're willing to have no safety guarantees but also not have to deal with paypal etc. Send a small tip to a content creator, pay content creators in small amounts in a patreon-like setting without having to deal with rules against content payment processors don't like (I saw recently this was being launched but I forget the name), lots of use cases.

I really need to call out crypto shill when I see it. As it stands, bitcoin is utterly unusable for micropayments, the transaction fees are way too high for that. There has been attempts at creating micropayment services on top, these all have failed to gain traction. I still maintain as I did several times here in the past: bitcoin (and in general, crypto"currencies" because they are not currencies) are a scam, a ne…

> There has been attempts at creating micropayment services on top, these all have failed to gain traction.

I'd argue that Bitcoin's lightning network is gaining traction, and it accomplishes a lot of what you are asking for.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#129
post #124

It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…

Moreover, why wouldn't he be using his own company's "industry-leading comprehensive secure" wallet solution which he recommends in the article, for his $100K worth of Bitcoin?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#130
post #6

> Do not leave funds idle on exchanges or fiat on-ramps. This warning has been publicly repeated hundreds of times since 2010, yet people still insist on ignoring it. The author didn't lose anything. He gave Coinbase his bitcoin in exchange for a promise to pay it back. That deal backfired. > I knew the risks better than most, but never thought something like this could happen to me. There's knowing the risk, and the…

And yet if he'd kept it on his own machine there's myriad other vectors from compromised wallets to typos that would separate even the veteran "investor" from their crypto. And we'd be blaming him again, just as you are now, because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology. This is the fundamental problem with crypto, it's irreversible and decentralized. T…

>because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology

Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions. After all, you can be pretty reckless with your credit card numbers or bank login and still be fine, because the finance system has an undo button for everything.

>This is the fundamental problem with crypto, it's irreversible and decentralized. These aren't features, they're bugs.

I wouldn't call them "bugs", just design decisions or trade offs. Bug implies it's somehow fixable, but if it's not. What if you want to make an irreversible payment, or want to be able to send money to whomever you want without the government stepping in the way, all while being trustless? Is there a way to achieve that, and still being able to hit undo when you make a mistake?

Post reply on HN