Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

101–110 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#101

I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…

I don't think so. This guy is the second (or third or whatever) person to sue AT&T over a SIM swap. The first case is already moving to trial: https://www.coindesk.com/att-fails-to-win-dismissal-in-24-mi....

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#102
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

Did you have a PIN setup with ATT? I am trying to figure out which of their employees can modify the account without the PIN.

As of a year or two ago when I worked at a authorized att dealer, manager logins can access any account without a pin and any employee can access prepaid accounts without a pin.

Edit:for whatever its worth att does keep a record of what employees accessed an account and when, and notes when managers bypass the pin, so doing this an an employee seems really stupid to me.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#103
post #95
post #79

Earlier quoted context omitted.

.. but is guaranteed to rule in favor of the bigger party.

https://levelplayingfield.io/ For 2015, it shows the majority of cases settle, about 3k out of 5k. Out of the remaining, more than half get some kind of award.

Are those stats across all arbitration, voluntary and compulsory, or just for contractually mandated arbitration?

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#104
post #103
post #95

Earlier quoted context omitted.

https://levelplayingfield.io/ For 2015, it shows the majority of cases settle, about 3k out of 5k. Out of the remaining, more than half get some kind of award.

Are those stats across all arbitration, voluntary and compulsory, or just for contractually mandated arbitration?

I'd imagine there's virtually no cases of consumers and businesses voluntarily using arbitration when there was no contractual agreement. Both sides need to agree to use arbitration.

I can dig through the data in a bit: they have the info under "source of authority", which will say whether it was in the contract or agreed upon later.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#105
post #103
post #95

Earlier quoted context omitted.

https://levelplayingfield.io/ For 2015, it shows the majority of cases settle, about 3k out of 5k. Out of the remaining, more than half get some kind of award.

Are those stats across all arbitration, voluntary and compulsory, or just for contractually mandated arbitration?

Looking at att in particular, they settle most of their cases. https://levelplayingfield.io/party/non-consumer-att

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#106
post #77

Earlier quoted context omitted.

I don't think you completely understand the concept behind the Google Authenticator App, i.e. the standard it implements. Which keys is it supposed to backup? Everything else you said is sadly true.

You would expect that if you restore the full backup of your iOS device to a new one, because you lost it for instance, that on the new device you could open the Authenticator app and see the same keys as you had on your old device. That is not the case though. Under the hood Google Authenticator uses keys to generate the codes you see on screen and these keys are not backed up. It’s a difficult decision of course. I…

I think they do backup if you do an offline (e.g. iTunes) full backup and restore on the same device, which of course is never what people do.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#107

Earlier quoted context omitted.

You would expect that if you restore the full backup of your iOS device to a new one, because you lost it for instance, that on the new device you could open the Authenticator app and see the same keys as you had on your old device. That is not the case though. Under the hood Google Authenticator uses keys to generate the codes you see on screen and these keys are not backed up. It’s a difficult decision of course. I…

I think they do backup if you do an offline (e.g. iTunes) full backup and restore on the same device , which of course is never what people do.

No, I know because that’s what I do and I had this fail on me when I migrated to a new phone. I switched to a different app that does backup keys when you use an encrypted iTunes backup.

Edit: oh you wanted to restore on the same device. Well that might work but it doesn’t help when migrating or if your phone is not available.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#108

Earlier quoted context omitted.

I think they do backup if you do an offline (e.g. iTunes) full backup and restore on the same device , which of course is never what people do.

No, I know because that’s what I do and I had this fail on me when I migrated to a new phone. I switched to a different app that does backup keys when you use an encrypted iTunes backup. Edit: oh you wanted to restore on the same device. Well that might work but it doesn’t help when migrating or if your phone is not available.

[deleted]

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#109
post #64

Earlier quoted context omitted.

Usually your phone stops working because your old SIM card gets disabled.

You can also add an authorized user or open up an entirely new line. You won't notice until you receive your bill.

Wouldn't a new line have a different phone number which wouldn't allow these hacks?

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#110
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

Did you have a PIN setup with ATT? I am trying to figure out which of their employees can modify the account without the PIN.

Yes, we have a PIN on the account. They did ask for it in store when I went to get a new SIM card.
Post reply on HN