Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

231–240 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#231

Earlier quoted context omitted.

> Provide me one legal use case better suited to cryptocurrency than the US dollar. Sending money to people overseas without extortionate fees. Surprisingly not everyone overseas is linked with international terrorism as you imply.

> Surprisingly not everyone overseas is linked with international terrorism as you imply. Unless you're trying to send money to North Korea that wasn't my implication at all, I have family overseas to whom I manage to send money without crypto or getting overcharged. There are tons of international remittance services already including Andreesen-backed TransferWise which charges ~0.85% or less to move money internati…

Uh sorry, Interactive Brokers is so cheap my math was off. They charge 0.2 basis points which is 0.2/100 of 1% (0.002%, minimum $2). So a $100,000 exchange would cost $2.00 and a $1,000,000 would cost $20.00

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#232
post #79

Earlier quoted context omitted.

FDIC is the government overreach the parent was talking about. It's also a relatively new thing. People who cry about government overreach seem to rarely ponder why it is there in the first place. Well, TFA shows why.

TFA?

The eFfing Article (as in RTFA, "read the effing article"). I.e. the thing we're all discussing here.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#233
post #227
post #167

Earlier quoted context omitted.

Google Authenticator does not help prevent against a compromised device (as all TOTP secrets and seeds are on device) and is truly a pain when working with multiple phones. Personally I use Yubico Authenticator as all the TOTPs live on my Yubikey. That, in combination with a password then clicking on a totp i want and tapping my yubikey provides me with only that code. When I first seed the yubikey with a new TOTP i…

Doesn't this mean your password manager is still single factor? Access that, access everything. That's the problem I was trying to avoid.

I use pass for my password manager which links to my yubikey that has my gpg key on it. My yubikey has touch enabled which means that even if someone got access to my machine with my yubikey on it and asked me to tap they would only get that single password. As far as TOTP is concerned it's the same thing. The TOTP section of my yubikey has it's password and also requires a tap

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#234
post #59

Earlier quoted context omitted.

because they can (usually) revert it. Because reversibility is a good thing.

Fraudulent transactions made with a regular bank account are pretty irreversible too. There's a whole extra layer of infrastructure on top of the 'core' banking services that allows them (banks) to 'reverse' a fraudulent transaction. But I'd be very very surprised if fraudulent charges are 'reversible' in any other way than the bank reimbursing the account holder. In other words, crypto-currency exchanges could do th…

Real banks have been hacked (e.g. full mainframe root access), and the hackers have made international transfers which were reversed.

Sure. When bank accounts get hacked sometimes the bank just eats the cost, but if $100k goes to another bank they'll contact that bank to have the money be clawed back.

Now I say "reversed", but the end goal I mean is "the money was transferred back" because it's traceable and doesn't require the cooperation of the receiving account holder. Not that it gets "undone" in double-entry bookkeeping.

Indeed bank hacks have lost some money when the "reversal" incurred currency fluctuation effects. (which could have gone the other way, too).

Also no, regular bank transfers are very reversible because courts can order it so. The justice system can order accounts frozen. With cryptocurrency the illusion is "math is the ultimate arbiter", but of course "math" can't solve "so what happens if one party broke the law", but is forced to answer "well... I guess they win, then".

Also compare smart contracts. You can make an illegal contract. Say the equivalent of selling yourself into slavery. Smart contracts want there to be no court that says "actually, that's slavery, and this contract is void, also the money must be returned". To think that "math" can provide justice better than a justice system is not just holding low esteem for justice systems in general. It's anarchy, and tyranny by exploitation.

"People" are not lawyers, which is why some things are not allowed in contracts. "People" are not coders, which is why smart contracts are also not a thing that will happen (on a scale cryptocurrency people dream of).

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#235
post #57

Earlier quoted context omitted.

See recent Tele2 attacks. This is a problem in Sweden too. Maybe the Tele2 attacks made them finally sort things out.

What Tele2 attacks?

https://computersweden.idg.se/2.2683/1.710395/google-konto-h...

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#236
post #71
post #57

Earlier quoted context omitted.

See recent Tele2 attacks. This is a problem in Sweden too. Maybe the Tele2 attacks made them finally sort things out.

Googled. Is it regarding using social engineering to enable call forwarding last autumn? Can't find anything else.

Yeah. Which is how this guy got hacked, too. Whether it's by forwarding or new sim card is a detail. It's the same social engineering vulnerability.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#238

Earlier quoted context omitted.

Neither of those solutions need or benefit from BlockChain.

Your comment couldn't be more asinine. Did you even bother to google search them? Here I'll help. https://www.stellar.org/ https://www.ibm.com/blockchain/solutions/world-wire

Personal attacks will get you banned here. Would you please read https://news.ycombinator.com/newsguidelines.html and follow the rules?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#239
post #70

Earlier quoted context omitted.

What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…

Personally I use Google Authenticator. The lack of a backup is a feature not a con IMO. Every account I have setup with TOTP I also make sure to print out the recovery codes and put them in a safe, and use them if my device is ever destroyed. When I switch phones (which for me happens maybe once every 2-3 years at most), I go through the shitty process of transferring the TOTP codes over to the new device, but it doe…

You can use Authenticator Plus, which cloud syncs your 2FA DB on every add/delete/update you make to any of your 2FA accounts.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#240
post #142

Earlier quoted context omitted.

> Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Funny because that's exactly what happens in France when you do so. I must have sounded a bit dumb when I asked when my number would be active when I changed from Tello to Verizon. I couldn't believe it was…

It's been a while since I ported a number but the last time I did it took days here in the UK too. I just assumed it was typical inefficiency by the mobile operators rather than a security thing, however.

It takes days in the UK because we have a crappy system where instead of having a central register of number -> provider, calls are still routed to a ported number via the "donor" network, i.e. the network the number range belongs. So I just ported from O2 to EE, and my calls and texts will still go through o2, and then sent on to EE. Not very efficient.
Post reply on HN