The Most Expensive Lesson of My Life: Details of SIM Port Hack
131–140 of 251 posts
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#132"I treated Coinbase like a bank account and you have absolutely zero recourse in the case of an attack." Now that's the real problem. Coinbase acts like a bank or a broker/dealer, but isn't regulated like one.
That and Bitcoin is specifically designed to not give you a recourse in case of an attack. Cryptocurrency designers seem to think that banking was designed as a mistake without anyone thinking. That laws people wanted were just unfortunate side effects.
Coinbase will pay out via PayPal, so someone with access to an account's credentials could pull of this scam without involving cryptocurrency at all.
Now if Coinbase was regulated by the SEC as a "broker/dealer", which is what they really are, they'd be subject to SEC regulations on fraud, and would have SIPC insurance to protect the customer up to $250K.[2]
Coinbase does, in fact, have a New York State "BitLicense", which makes them subject to various New York State regulations. Among other things, transactions larger than US$10,000 have to be reported to the New York State Department of Financial Services within 24 hours, and Coinbase is subject to rules about cybersecurity, fraud, and its activity as a custodian of the funds of others. You can complain to the New York State Department of Financial Services.
DFS pulled Bittrx's license last month and gave them one day to get out of New York State.
[1] https://www.westernunion.com/us/en/fraudawareness/fraud-ques...
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#133It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…
Moreover, why wouldn't he be using his own company's "industry-leading comprehensive secure" wallet solution which he recommends in the article, for his $100K worth of Bitcoin?
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#134Earlier quoted context omitted.
>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…
What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#135Seems like 2FA in this case is significantly weaker than 1FA if you have a long password. I suppose it depends on if it is easier to answer the security questions or to convince a customer support rep, but my security questions are pretty obscure and I have a security question salt that I always append to the answer.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#136I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…
> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…
I used to believe this too. Until this morning. Then I realized something and now I'm not so sure: if I don't have SMS 2FA at all, then my phone line is less to become an attack target. Meaning I'm less likely to have to deal with the collateral damage of lost accounts, files, etc. So is it really better to have that SMS 2FA? Especially if you weren't ever having problems securing your stuff before it came along?
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#137Earlier quoted context omitted.
> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…
Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead. This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out. Note that all telcos will prevent the number being ported out if you owe them any money on the account.
Wait really? Is there a way to force yourself to perpetually owe them a small amount of money then? Could be really worth the money.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#138Earlier quoted context omitted.
> And while we are doing PSAs, I'd like to give one piece of seemingly conflicting advice: make sure you have backups of your multi-factor authentication systems. Yes! Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. The underlying keys can be manually shown and entered elsewhere if needed, and can be backed up with everything else that's valuable. > Print out 2-factor backu…
>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…
I feel you're not portraying the trade-off accurately so I'll try to clarify.
It's not merely better because it's just "another layer to figure out". That's what you would get with 2 passwords. It's not what you get with 1 password + 1 OTP.
With OTP you're protected against your password being logged and used later on e.g. an untrusted or breached machine (say, at a library). I'd hazard to guess that dealing with a passive adversary who's time-separated from you is FAR more common/likely than having your actual password database stolen or cracked somehow. Meaning it's still quite a significant benefit to having OTP.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#139Earlier quoted context omitted.
And yet if he'd kept it on his own machine there's myriad other vectors from compromised wallets to typos that would separate even the veteran "investor" from their crypto. And we'd be blaming him again, just as you are now, because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology. This is the fundamental problem with crypto, it's irreversible and decentralized. T…
>because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions. Af…
More aptly though, I would declare it problematic if I couldn't drive 10 feet without someone carjacking me in my ostensibly armored car, or if pressing the button on my radio caused the car to explode. I'd call that 'problematic' because if it were my fault, I'd be in jail, and if not, the automaker would be on the wrong end of a huge lawsuit.
You know who we have to thank for their current level of safety? The DOT, NHTSA and legal system.
> The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions.
He had his coins on probably the only legitimate exchange in all of crypto. He had 2fac. He had 2fac on his gmail. If this isn't sufficient to keep your money protected, we need to stop blaming the victim. He's probably one of the most competent technical individuals owning crypto. If he can't keep it safe how on earth would your grandmother?
> After all, you can be pretty reckless with your credit card numbers or bank login and still be fine, because the finance system has an undo button for everything.
Isn't that awesome? We've recognized people make mistakes and created for them a path to remedy said mistakes. Pretending they don't happen and that it's the victims fault if they do isn't a replacement.
> What if you want to make an irreversible payment.
Wire transfer. You can opt in to irreversibility, it's not the default, and that's completely reasonable IMO.
> ...or want to be able to send money to whomever you want without the government stepping in the way.
AKA breaking the law. Yes, you shouldn't be able to send money to people on the OFAC list, to terrorists, or to sanctioned countries. That's fine with me, and all your fellow citizens. That's why we have those laws. Let's not mince words, "sending money to people the government doesn't want" is financing international terrorism, narcotics trafficking, human trafficking and so on. No, you shouldn't be able to do that.
> ...all while being trustless?
Again, why do you need this without the illegal use cases? Either way PoW cryptos aren't trustless, Beijing has over 80% of the hash power one strongly worded memo away. Decentralized and trustless are not a feature of Bitcoin or most other cryptocurrencies. They are centralized in the PRC. You would give up sovereign control of your money system to the PRC?
> Is there a way to achieve that, and still being able to hit undo when you make a mistake?
No, you shouldn't be able to break the law. An open challenge to all crypto advocates: Provide me one legal use case better suited to cryptocurrency than the US dollar.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#140In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…