Earlier quoted context omitted.
BitGo also secured the wallets for Bitfinex leading to a hack in 2015, never fully explaining the circumstances. https://en.m.wikipedia.org/wiki/BitGo#Bitfinex_hack
IIRC their system with Bitfinex was a 2-of-3 key setup, with BitGo holding one key and Bitfinex, for some reason, holding two. At least that's what's stuck in my memory from Bitfinex/BitGo communications at the time, since the setup seemed to negate the point of using BotGo in the first place. Edit: I should've clicked the link there, it says pretty much the same. It doesn't seem to me there was much left to explain…
The Most Expensive Lesson of My Life: Details of SIM Port Hack
161–170 of 251 posts
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#162Earlier quoted context omitted.
>because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions. Af…
> Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? More aptly though, I would declare it problematic if I couldn't drive 10 feet without someone carjacking me in my ostensibly armored car, or if pressing the button on my radio caused the car to explode. I'd call that 'problematic' because if it were my…
Check your privilege, as some might say
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#163Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#164It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…
>It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new I remember first hearing about them in 2016: https://www.ftc.gov/news-events/blogs/techftc/2016/06/your-m...
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#165It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…
It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones. IMO its great to learn about what goes well but super valuable to learn when peo…
- credit cards with secrets printed and shared in plain sight
- hacked banks
- hacked atms
It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system.
But the latter also seems to be true for crypto. It shifts the responsibility further to the user. Some like it because they assume they can provide better opsec than their bank (which was easy in the past). Others don’t like to take responsibility and leave it with some exchange, which in some cases even lack behind banks.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#166Earlier quoted context omitted.
So what’s the alternative? Especially financial institutions insist on using SMS in addition to even hardware keys. It’s crazy.
Many carriers let you set an "account password" or "account pin" - changes can't be made to the account without it (even with personal info like SSN, bday, etc) Financial institutions offer it to sometimes - my credit union requires the account password, or a visit to a branch to show ID - no amount of personal info will allow you access.
Otherwise, what would happen in the frequent case where users forget their pin?
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#167Earlier quoted context omitted.
What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…
Personally I use Google Authenticator. The lack of a backup is a feature not a con IMO. Every account I have setup with TOTP I also make sure to print out the recovery codes and put them in a safe, and use them if my device is ever destroyed. When I switch phones (which for me happens maybe once every 2-3 years at most), I go through the shitty process of transferring the TOTP codes over to the new device, but it doe…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#168Earlier quoted context omitted.
> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…
Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead. This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out. Note that all telcos will prevent the number being ported out if you owe them any money on the account.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#169Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#170Earlier quoted context omitted.
Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead. This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out. Note that all telcos will prevent the number being ported out if you owe them any money on the account.
> Note that all telcos will prevent the number being ported out if you owe them any money on the account. Wait really? Is there a way to force yourself to perpetually owe them a small amount of money then? Could be really worth the money.
The comment you replied to appears to be discussing porting a number to a different provider which is very different and doesn't happen same-day.