Live data from Hacker News

For Ransom, Bitcoin Replaces the Bag of Bills

nytimes.com

41–47 of 47 posts

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#41
post #5

I know this is not 100% specific to this article, but this is happening right now to a friend of mine's gmail account. Scammer was able to social engineer the cell phone company to forward his number, then did a password reset, and locked him out of his account. 20BTC Ransom. He followed every single google customer service link/resource he could find and tried to reset link, which said they would contact him in 3-5…

I'm sorry if this sounds like me being a jerk - that's not my goal. I just want to point out cold hard facts. > but this is happening right now to a friend of mine's gmail account I can't stress this enough but please enable OTP on your accounts. Facebook, gmail, and even your Windows system if you are paranoid enough. Yeah it adds some hassle - but the value of increased security far outweighs the hassle. Also backu…

> I can't stress this enough but please enable OTP on your accounts. Facebook, gmail, and even your Windows system if you are paranoid enough. Yeah it adds some hassle - but the value of increased security far outweighs the hassle. Also backup the OTP codes somewhere.

It seems like the specific attack vector in this case was linking the gmail account with a cell phone number. Surely the most secure option is simply a very strong password with no TFA, OTP or any other auxilliary recovery options?

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#42
post #5

Earlier quoted context omitted.

I'm sorry if this sounds like me being a jerk - that's not my goal. I just want to point out cold hard facts. > but this is happening right now to a friend of mine's gmail account I can't stress this enough but please enable OTP on your accounts. Facebook, gmail, and even your Windows system if you are paranoid enough. Yeah it adds some hassle - but the value of increased security far outweighs the hassle. Also backu…

> I can't stress this enough but please enable OTP on your accounts. Facebook, gmail, and even your Windows system if you are paranoid enough. Yeah it adds some hassle - but the value of increased security far outweighs the hassle. Also backup the OTP codes somewhere. It seems like the specific attack vector in this case was linking the gmail account with a cell phone number. Surely the most secure option is simply a…

> It seems like the specific attack vector in this case was linking the gmail account with a cell phone number.

The whole story seems kind of farfetched really. If the attacker did get forwarding to work - it would only forward calls not text messages (which gmail would send a recovery code via text message). According to the story it was in the process of being ported which MAY send texts to the new number - but on most accounts that I've read with dealing with porting that takes at least 24 hours for them to start receiving text messages on the new provider. To my knowledge no carrier has implemented text message forwarding. Also it seemed my posts were downvoted right around the time of his responses.

There are certain holes in this story - first it was a gmail account, then it turned into a gmail + google apps account which are 2 completely different things.

Regardless - enable OTP period.

> Surely the most secure option is simply a very strong password

Arguably using a different strong (12+ characters) password for every site and service is a good approach - but then you should probably be generating those passwords and storing them into a password manager. Then that password manager becomes a target[1]. Using OTP is just a good layer of security.

[1] http://arstechnica.com/security/2015/06/hack-of-cloud-based-...

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#43

I know this is not 100% specific to this article, but this is happening right now to a friend of mine's gmail account. Scammer was able to social engineer the cell phone company to forward his number, then did a password reset, and locked him out of his account. 20BTC Ransom. He followed every single google customer service link/resource he could find and tried to reset link, which said they would contact him in 3-5…

i never activated google's 2factor authentication just out of fear of my phone being stolen. this ugly possibility never even occurred to me. i really cannot understand why this stupid sms-based scheme is pushed down our throats by google.

fingers crossed for your friend, i hope it works out!

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#44

To me this is a serious downside of cryptocurrencies - the fact that criminals have this secure channel of stealing from victims. Besides malware, one can be blackmailed with information disclosure (everyone has secrets), one can be physically bullied into transferring his BTC or forced to pay bribes by police or corrupt authorities. In western countries some of these may seem impossible, but in a lot of places, poli…

If we were running our economy on steam and gold we would have even less problems. Your life expectancy would be 2x lower, but Sherlock Holmes would be able to find the blackmailer.

Do you seriously blame the technology and instead of finding a technological solution propose to blame everyone using it for occasional consequences you do not like?

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#45
post #42

Earlier quoted context omitted.

> I can't stress this enough but please enable OTP on your accounts. Facebook, gmail, and even your Windows system if you are paranoid enough. Yeah it adds some hassle - but the value of increased security far outweighs the hassle. Also backup the OTP codes somewhere. It seems like the specific attack vector in this case was linking the gmail account with a cell phone number. Surely the most secure option is simply a…

> It seems like the specific attack vector in this case was linking the gmail account with a cell phone number. The whole story seems kind of farfetched really. If the attacker did get forwarding to work - it would only forward calls not text messages (which gmail would send a recovery code via text message). According to the story it was in the process of being ported which MAY send texts to the new number - but on…

Most services which use phone numbers for authentication helpfully offer to call you and read out the code using text-to-speech if they can't text you, including Google accounts. This is often exploited by attackers.

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#46
post #36
post #35

Earlier quoted context omitted.

Use the cryptography based 2FA (with Google Authenticator on your phone). SMS is too open to social engineering, and as a second factor might actually make your account less safe.

Think I read that Google Auth falls back to SMS, so that wouldn't help.

you can freely choose between enabled authentication methods.

so, its possible to disable the sms authentication by removing it in the security settings

Re: For Ransom, Bitcoin Replaces the Bag of Bills

#47

To me this is a serious downside of cryptocurrencies - the fact that criminals have this secure channel of stealing from victims. Besides malware, one can be blackmailed with information disclosure (everyone has secrets), one can be physically bullied into transferring his BTC or forced to pay bribes by police or corrupt authorities. In western countries some of these may seem impossible, but in a lot of places, poli…

If we were running our economy on steam and gold we would have even less problems. Your life expectancy would be 2x lower, but Sherlock Holmes would be able to find the blackmailer. Do you seriously blame the technology and instead of finding a technological solution propose to blame everyone using it for occasional consequences you do not like?

> If we were running our economy on steam and gold we would have even less problems.

Absolutely. I've lost a lot of coins in various hacks so this is experience talking, not theory ;).

> propose to blame everyone using it for occasional consequences you do not like.

Not blaming anyone and I'm still quite hopeful about crypto (albeit much less now than before), just saying this is a dark side of crypto which people are afraid to look at and it's not going away.

You may remember this discussion if god forbid somebody hacks the service were you hold your coins at (https://bitcointalk.org/index.php?topic=576337) or exploits a vulnerability in your OS and steals your wallet OR does the thing in the article.

Right, we are literate, we don't keep our wallets online or on our hard drives. For maximum safety we keep our public key pairs on a piece of paper or wood and hide it away in a dark place.

Post reply on HN