I still don't get one thing: how could the attacker port OP's number without proving he owns the sim? Where I live (in EU) it's mandatory, isn't it the same in the US?
The Most Expensive Lesson of My Life: Details of SIM Port Hack
171–180 of 251 posts
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#172Earlier quoted context omitted.
It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones. IMO its great to learn about what goes well but super valuable to learn when peo…
Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#173Earlier quoted context omitted.
It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones. IMO its great to learn about what goes well but super valuable to learn when peo…
Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…
This is a simplification. For all customer-present transactions cards use the secrets in a secure chip, and the transaction is authorised by the cryptographic processor in those chips signing the transaction data with a secret key. It's classic 2FA - Something you have (a card) and something you know (a PIN).
The type-in-a-number-on-a-website purchases are the weak link, and even they are usually protected by another layer of passwords (3D-secure, Verified by Visa etc).
It's quite a while (in most places outside the US) since the number on the front was the secret.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#174Earlier quoted context omitted.
> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…
> While sms 2FA is marginally better than not having any 2FA at all I used to believe this too. Until this morning. Then I realized something and now I'm not so sure: if I don't have SMS 2FA at all, then my phone line is less to become an attack target. Meaning I'm less likely to have to deal with the collateral damage of lost accounts, files, etc. So is it really better to have that SMS 2FA? Especially if you weren'…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#175Earlier quoted context omitted.
And yet if he'd kept it on his own machine there's myriad other vectors from compromised wallets to typos that would separate even the veteran "investor" from their crypto. And we'd be blaming him again, just as you are now, because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology. This is the fundamental problem with crypto, it's irreversible and decentralized. T…
>because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions. Af…
Possibly: see the numerous self-driving efforts underway.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#176Earlier quoted context omitted.
It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones. IMO its great to learn about what goes well but super valuable to learn when peo…
Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#1772FA by SMS is terribly insecure. Numerous security researchers recommended never using it. Using phone numbers as primary authentication mechanism is insecure and never should be used. Phone numbers can be spoofed, SMS messages can be intercepted, SIM port attacks can and will happen. If your email or banking accounts depend on 2FA by SMS, especially when SMS can be used to reset the password — disable it now. Avoid it like plague.
More than that — if your account has significant value that you absolutely can’t afford to lose, you shouldn’t use _any_ 2FA services linked to your phone, at all, including Google Auth. Your phone can be lost or stolen anytime. Use a dedicated device which you don’t take with you all the time.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#178I still don't get one thing: how could the attacker port OP's number without proving he owns the sim? Where I live (in EU) it's mandatory, isn't it the same in the US?
at least in germany ordering new sim cards to new addresses your provider never heard of before was a thing some years ago. I think porting a number is a lot easier if you know the detailed process though.
Here in Italy you must provide your ID card and wait a couple days for the carrier to check the data. Goverment websites even use 2fa as a proof of your physical identity
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#179It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…
BitGo should be treating this as a security incident and verifying the attacker didn’t also target them.