Earlier quoted context omitted.
Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead. This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out. Note that all telcos will prevent the number being ported out if you owe them any money on the account.
> Note that all telcos will prevent the number being ported out if you owe them any money on the account. Wait really? Is there a way to force yourself to perpetually owe them a small amount of money then? Could be really worth the money.
The Most Expensive Lesson of My Life: Details of SIM Port Hack
151–160 of 251 posts
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#152In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…
So what’s the alternative? Especially financial institutions insist on using SMS in addition to even hardware keys. It’s crazy.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#153It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#154Earlier quoted context omitted.
> Note that all telcos will prevent the number being ported out if you owe them any money on the account. Wait really? Is there a way to force yourself to perpetually owe them a small amount of money then? Could be really worth the money.
An attacker could just pay the balance.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#155Tying all security to only an email is dumb for important services.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#156It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…
BitGo also secured the wallets for Bitfinex leading to a hack in 2015, never fully explaining the circumstances. https://en.m.wikipedia.org/wiki/BitGo#Bitfinex_hack
Edit: I should've clicked the link there, it says pretty much the same. It doesn't seem to me there was much left to explain - the attacker gained access to Bitfinex's keys and that was enough to withdraw. The idea of using BitGo was that a compromise of Bitfinex couldn't lead to loss of user funds, but Bitfinex holding two keys completely undermined that goal.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#157Sucks to be the OP but storing any crypto in an exchange is idiotic and literally the first thing on any list of "how to secure your crypto" is to not do it. This shows the OP is just being willfully ignorant. Exchanges get hacked or are victims of internal fraud at a level that is far beyond any acceptable risk. https://coinsutra.com/biggest-bitcoin-hacks/ If you have any kind of serious crypto holdings, you should…
For any significant crypto holdings you should be using a hardware wallet, and for serious holdings you should also use a multisig setup.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#158Earlier quoted context omitted.
And yet if he'd kept it on his own machine there's myriad other vectors from compromised wallets to typos that would separate even the veteran "investor" from their crypto. And we'd be blaming him again, just as you are now, because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology. This is the fundamental problem with crypto, it's irreversible and decentralized. T…
>because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions. Af…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#159Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#160Earlier quoted context omitted.
Similar to a bank as in a guaranteed insurance of my funds, like the FDIC in the US?
FDIC is the government overreach the parent was talking about. It's also a relatively new thing. People who cry about government overreach seem to rarely ponder why it is there in the first place. Well, TFA shows why.