Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

11–20 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#11
This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck!

Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with crypto credentials than, say, your bank password or credit card.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#12
post #2

Wasn’t there a pin on his account?

Exactly. I have a pin on my account after identity thieves opened a bunch of AT&T and Verizon accounts under my name (thanks Equifax!). Since this happened I’ve been in the AT&T stores when I bought an unlocked phone on two occasions. The employees at the store weren’t able to do a thing until I spoke with a special call center on the phone and did verifications.

One time there was something wrong on their end and no one could do anything until the system to verify my pin was back up.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#13

I am not condoning or justifying criminal behaviour but I have to wonder why on earth he would have his life savings in cryptocurrency, protected only by SMS 2FA, if he knew someone else this had happened to?

He clearly isn’t educated enough (not to be mean).

Especially if you’re going around with that much crypto always always remember:

Not your keys, not your coins.

Always store cold storage and set aside some for trading if you want. And if you’re trading, always use FIDO U2F physical keys.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#14

This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…

And they'll just hide their binding arbitration clauses.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#16
post #2

Wasn’t there a pin on his account?

It’s better than nothing that AT&T finally allows pins at all, but one thing that’s insane about it is every time you log in on the web there’s a checkbox to never ask for your pin again. It’s exactly where you’d expect a checkbox for something like “remember me”, except it opens up a huge security hole in your account if you accidentally check it.

Pins obviously have other issues that make no sense, like the incredibly low complexity allowed that would never be acceptable for a password. But even aside from that I guess AT&T also want everyone to turn their pin off? I hope they do lose a lawsuit and actually have to start giving a shit about pin swapping and make things more secure by default.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#18
post #10

This is exactly why I’m only faithful to FIDO U2F keys. Got a couple and ensure they’re safe. No one’s hacking my accounts unless they crack both my passwords and rob me physically... which at this point doesn’t seem like it’s going to happen.

What happens if the keys get lost or destroyed? It seems like a never ending problem.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#20

I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…

> (including when signing up for HN-backed services run by people who know they can get away with it)
Post reply on HN