Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

121–129 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#121

He's got good evidence. The SIM-swappers have actually been convicted. ATT says it's "an industry" problem, but it's 100% their problem. They are doing nothing to stop employees from robbing their customers. Of course the victim could probably have protected his "life savings" better, but that's not the point.

AT&T's going to say "you don't own that phone number--it's ours--and we never said it was intended for verifying your identity. Take it up with whoever stole your number and your--wait, someone stole your cryptocurrency ? You realize banks are insured against mistakes like this and bitcoin wallets aren't, right?"

Except AT&T themselves use the phone number as a form of identity verification / 2nd factor so that argument doesn't really hold up.

Also insurance doesn't always hold up in cases like this, especially if the company was aware of the weakness and chose to do nothing about it.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#123
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

Are things like this usually targeted, I.e. the hackers know enough about you to know who you are and you probably know their names or at least know someone they know? How do hackers even pick their targets?

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#124
post #33

Earlier quoted context omitted.

It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.

And when you (unavoidably) get hacked, they tell you it's your fault and that it sucks to be you, because you are not getting that money back. https://www.cbc.ca/news/business/banks-deny-compensation-onl...

That's really surprising. In the US, the banks are responsible for fraudulent transactions.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#125
post #81

This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…

> Irreversible transactions are kind of the whole point of it Just as a sidenote, the problem isn't that the transactions are irreversible, they're also irreversible for banks. You never reverse the actual transaction, you just create another transaction in the opposite direction. Sometimes banks accidentally sent money to the wrong (foreign) bank and kissed them goodbye. The other bank had no obligation to send it b…

From the perspective of the bank customer, in the US, bank transactions are reversible, by fiat. It does not matter to the customer whether the bank is out money or not. All that matters is that you are made whole in the case of a fraudulent transaction.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#126

Earlier quoted context omitted.

AT&T's going to say "you don't own that phone number--it's ours--and we never said it was intended for verifying your identity. Take it up with whoever stole your number and your--wait, someone stole your cryptocurrency ? You realize banks are insured against mistakes like this and bitcoin wallets aren't, right?"

Except AT&T themselves use the phone number as a form of identity verification / 2nd factor so that argument doesn't really hold up. Also insurance doesn't always hold up in cases like this, especially if the company was aware of the weakness and chose to do nothing about it.

Well, most companies, AT&T including, do not have truly irreversible actions. If someone steals your account this way, with enough complaining you will likely get it back, mostly, eventually. Same thing with traditional banking.

This breaks down for internet giants which provide free services which can still be very valuable, like gmail, and that’s why they are moving away from it.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#127
post #104
post #103

Earlier quoted context omitted.

Are those stats across all arbitration, voluntary and compulsory, or just for contractually mandated arbitration?

I'd imagine there's virtually no cases of consumers and businesses voluntarily using arbitration when there was no contractual agreement. Both sides need to agree to use arbitration. I can dig through the data in a bit: they have the info under "source of authority", which will say whether it was in the contract or agreed upon later.

[deleted]

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#128
post #64

How do you know if someone has obtained a SIM card with your identity? Do you have a web site for this, like https://www.turkiye.gov.tr/mobil-hat-sorgulama ?

Usually your phone stops working because your old SIM card gets disabled.

What if they obtain a SIM card from another mobile provider with a different phone number?
Post reply on HN