Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

191–200 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#191
post #165

Earlier quoted context omitted.

It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones. IMO its great to learn about what goes well but super valuable to learn when peo…

Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…

In Europe it's more common to have an EC card, which doesn't have any necessary secrets printed in plain sight (you need a TAN to complete a transaction over 25€ or total 100€ per day).

We also have SEPA Inst which allows me to send people money instantly for no fees (atleast at my bank), faster than Bitcoin ever could.

I'm insured against the bank being hacked. I'm also insured against the ATM's being hacked.

If I'd open my bank account today and found 0€ via hacks, I'd get it all back in 99.9% of cases. If I loose my card I get back everything too.

If I loose my bitcoin wallet, I'm SOL and should be sorry for not making backups and using a multisig wallet with 2FA!

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#192

Earlier quoted context omitted.

It's a reminder that crypto is fundamentally dangerous due to its lack of regulation and compliance requirements, its fundamental irreversibility and lack of authority/censorship. It's a lesson we should all take to heart about what makes for a functional financial system and what doesn't. It's also a lesson about the security of phones. IMO its great to learn about what goes well but super valuable to learn when peo…

If a bank uses SMS to confirm operations and doesn't check that card was recently reissued then this attack would work against traditional bank too.

And you would have a chance (actually, be legally entitled) to recover your money as opposed to people on the internet telling you sorry for your loss.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#193
post #124

It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…

I think this is related to the "normalization of deviance" which permeates all domains.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#194
post #165

Earlier quoted context omitted.

Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…

When I was a student 15 years ago my debit card was skimmed (here in the UK) and someone in the middle east completely emptied my bank account. I called my bank, they explained what had happened and what little money I had was back the very next day. So while the infrastructure may be fundamentally insecure, quite frankly that's not my problem. If it was a crypto wallet I would have had zero legal recourse and of cou…

Ouch. Sucks to read that. For anyone who might be interested in a possible alternative to this, I keep two bank accounts with the same bank with only one being connected to my debit card. I keep a tiny balance in the account connected to the debit card so that even if I lose it, the damage is minimal. Whenever my balance is running low, I do a quick transfer via online banking.

No idea how feasible this might be in other countries, but wanted to share in case its helpful. It's really helped me have ease of mind in using my card when I've been abroad.

Doesn't stop me from attempting to dismantle any ATM though whenever I use one :')

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#195

Earlier quoted context omitted.

> While sms 2FA is marginally better than not having any 2FA at all I used to believe this too. Until this morning. Then I realized something and now I'm not so sure: if I don't have SMS 2FA at all, then my phone line is less to become an attack target. Meaning I'm less likely to have to deal with the collateral damage of lost accounts, files, etc. So is it really better to have that SMS 2FA? Especially if you weren'…

Thank you. I've been waiting years now for someone else to notice this as well.

Good to know! I feel like it stems from the notion that protecting whatever particular account they want you to protect must be the most important priority in your life. Even security folks don't always seem inclined to think in terms of trade-offs... too often they seem to see things as black and white. If something protects your account or computer better then it must be better and you have to do it. They don't care if you might lose your job or if it might burn down your home as a side effect; that's just not part of their threat models...

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#196

Earlier quoted context omitted.

at least in germany ordering new sim cards to new addresses your provider never heard of before was a thing some years ago. I think porting a number is a lot easier if you know the detailed process though.

Oh, my bad, I thought US was the exception Here in Italy you must provide your ID card and wait a couple days for the carrier to check the data. Goverment websites even use 2fa as a proof of your physical identity

Why is it so common for some people to use "EU"/"Europe" when talking about a quirk about their country? Americans do it too, though the states are far less unique than countries.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#197

Earlier quoted context omitted.

Oh, my bad, I thought US was the exception Here in Italy you must provide your ID card and wait a couple days for the carrier to check the data. Goverment websites even use 2fa as a proof of your physical identity

Why is it so common for some people to use "EU"/"Europe" when talking about a quirk about their country? Americans do it too, though the states are far less unique than countries.

Because many of the rules are made on the EU level, not by the individual country.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#198
post #191
post #165

Earlier quoted context omitted.

Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…

In Europe it's more common to have an EC card, which doesn't have any necessary secrets printed in plain sight (you need a TAN to complete a transaction over 25€ or total 100€ per day). We also have SEPA Inst which allows me to send people money instantly for no fees (atleast at my bank), faster than Bitcoin ever could. I'm insured against the bank being hacked. I'm also insured against the ATM's being hacked. If I'd…

I’ve read somewhere that regarding the way the cards, checks and transfers work the U.S. is not only behind Europe but even the African countries.

And that the chip cards were invented and used in Europe decades before they started to be spread in the UK and the U.S.

I don’t know why but somebody with more insider information can maybe explain?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#199

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

The „time lock” approach is exactly what Apple is doing if you try to recover your Apple ID (without password and second factor).

Unfortunately, when you search on Twitter, people are going bananas over having to wait a few days to get their Apple account reset... so I definitely get why not more companies are doing this.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#200

Earlier quoted context omitted.

If a bank uses SMS to confirm operations and doesn't check that card was recently reissued then this attack would work against traditional bank too.

No, you are not liable when someone robs the bank you use.

IF someone managed to rob your account entirely through a mistake of the bank, it is the govt pointing the gun at the banks head (figuratively and literally) to give you your monetary assets.

With crypto the government can't get involved so you're screwed

Post reply on HN