Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

211–220 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#211
post #198
post #191

Earlier quoted context omitted.

In Europe it's more common to have an EC card, which doesn't have any necessary secrets printed in plain sight (you need a TAN to complete a transaction over 25€ or total 100€ per day). We also have SEPA Inst which allows me to send people money instantly for no fees (atleast at my bank), faster than Bitcoin ever could. I'm insured against the bank being hacked. I'm also insured against the ATM's being hacked. If I'd…

I’ve read somewhere that regarding the way the cards, checks and transfers work the U.S. is not only behind Europe but even the African countries. And that the chip cards were invented and used in Europe decades before they started to be spread in the UK and the U.S. I don’t know why but somebody with more insider information can maybe explain?

Same-day ACH took a while AFAIK because of fraud risk especially to smaller banks and credit unions, although we've moved into phase 3 of the work last year so that's happening now. I think the push-to-debit functionality pioneered by the likes of Square Cash helped hurry this along but I'm only speculating.

It's not particularly insider information, the reason America was slow to the chip card game was pragmatic. The US is a very low fraud rate market, and re-issuing all 1.43 billion credit cards [1] and 14M payment terminals [2] was going to cost an awful lot of money. Further, major industry players like McDonalds weren't interested in seeing line speeds go down at point of sale as they switch from mag stripe payments which happen real fast to EMV chip transactions which, at the time, were really slow. Think tl:dr; it wasn't until a few years ago that the cost of the transition outweighed the cost of the fraud that would be mitigated as a result.

[1] https://wallethub.com/edu/cc/number-of-credit-cards/25532/

[2] https://gomedici.com/steady-growth-in-nfc-pos-terminals-in-t...

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#212
post #207
post #173

Earlier quoted context omitted.

> credit cards with secrets printed and shared in plain sight This is a simplification. For all customer-present transactions cards use the secrets in a secure chip, and the transaction is authorised by the cryptographic processor in those chips signing the transaction data with a secret key. It's classic 2FA - Something you have (a card) and something you know (a PIN). The type-in-a-number-on-a-website purchases are…

Most chip credit transactions in the US dont use a pin yet.

Correct, and they won't any time soon. This US is a Chip + Signature market, which still incorporates cryptographic elements on the card itself as the secret.

In a Chip + PIN transaction, the second factor is your digital PIN, whereas in the Chip + Signature transaction the second factor is your signature. It's still 2fac, but more importantly, in neither case is the secret on the front of the card.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#213
post #166

Earlier quoted context omitted.

Many carriers let you set an "account password" or "account pin" - changes can't be made to the account without it (even with personal info like SSN, bday, etc) Financial institutions offer it to sometimes - my credit union requires the account password, or a visit to a branch to show ID - no amount of personal info will allow you access.

Any carrier will allow you to change your password or pin using other information . Otherwise, what would happen in the frequent case where users forget their pin?

> Any carrier will allow you to change your password or pin using other information .

If by "other information" you mean "come into a store and show a government issued photo ID" you are correct. That's a fairly high bar to clear.

That's the way my carrier does it, and I assume if they violate their own procedures I could evaluate my legal options... though as a practical matter I use a VOIP # which requires a 2FA protected login to port out for vendors that force me to use SMS 2FA.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#214

Earlier quoted context omitted.

>It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new I remember first hearing about them in 2016: https://www.ftc.gov/news-events/blogs/techftc/2016/06/your-m...

I recall case in Russia back in 2005, it was used to gain access to regular bank account.

Very cool, if you have a source that would be very interesting to read about.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#215
post #57
post #45

Earlier quoted context omitted.

I checked, to get a replacement sim my carrier sends out inactive cards that needs to be activated through their web service using the printed number on the card. If you don't have an account you need to contact customer service, and to get through there they most likely authenticate you based on your SSN and an already active app on your phone (BankID) where you input your personal password. This has actually create…

See recent Tele2 attacks. This is a problem in Sweden too. Maybe the Tele2 attacks made them finally sort things out.

What Tele2 attacks?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#217

Earlier quoted context omitted.

For any significant crypto holdings you should be using a hardware wallet, and for serious holdings you should also use a multisig setup.

Right but what if the blocks fill up and transactions are taking forever right when you (and others) have the most interest in selling?

That’s not really a security issue. It sounds like a speculation issue. Treat custodial services like a porta-potty at a shitty music festival: do your business then GTFO

For Bitcoin you should always aim to use the lowest fee possible, and use replace-by-fee (RBF) if a transaction is taking too long.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#218
post #165

Earlier quoted context omitted.

Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…

When I was a student 15 years ago my debit card was skimmed (here in the UK) and someone in the middle east completely emptied my bank account. I called my bank, they explained what had happened and what little money I had was back the very next day. So while the infrastructure may be fundamentally insecure, quite frankly that's not my problem. If it was a crypto wallet I would have had zero legal recourse and of cou…

How many hours did you spend resolving the issue? That’s your damage.

And while you were reimbursed, the damage to the whole community was still done and just covered by an insurance fee that everyone pays on every transaction.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#219

Earlier quoted context omitted.

IF someone managed to rob your account entirely through a mistake of the bank, it is the govt pointing the gun at the banks head (figuratively and literally) to give you your monetary assets. With crypto the government can't get involved so you're screwed

The banks know this, and they don't like losing money, so they have made most of their transactions reversible. There was an article on this a few years ago exploring why bank account credentials are worth little on the black market. Basically, there isn't an easy, safe way to just steal money out of a bank account.

Also caps.

My debit card is capped at $400? Cash a day. So cool you get $400 if you steal it. Very different from 100k

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#220

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

>Number porting is a huge and easily performed attack vector, it requires very, very little information Does it need to be? Seems most of it could be avoided if the cellular service required a visit at the store with an ID card to clone a SIM card.

... which is how it actually works in many countries. In USA "something you know" is enough to impersonate you, elsewhere you'd actually show up with a good quality forgery of passport or gov't ID card, which would cost you more than you might steal from a random person.

Since USA has this "root of trust" problem, it's also unreasonably easy to obtain fake USA IDs since you (again) can impersonate people simply with "something you know" even for the purposes of obtaining legitimate IDs. It's not so easy elsewhere (e.g. if you claim you're me and have lost all ID, they'd just check biometrics before reissuing ID). Proper checks of IDs (+ verification of lost&stolen IDs databases) can ensure that identity theft cases are very rare. The identity theft epidemic isn't general worldwide, it's mostly a regional issue specific to USA and some similar countries.

Post reply on HN