Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

201–210 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#201

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

>Number porting is a huge and easily performed attack vector, it requires very, very little information

Does it need to be? Seems most of it could be avoided if the cellular service required a visit at the store with an ID card to clone a SIM card.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#202
post #130

Earlier quoted context omitted.

>because in the land of Crypto anything bad that happens is your fault, not the insanely problematic technology Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? The problem here is that people are not aware of the risks associated with cryptocurrencies and so are not taking the required precautions. Af…

> Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? More aptly though, I would declare it problematic if I couldn't drive 10 feet without someone carjacking me in my ostensibly armored car, or if pressing the button on my radio caused the car to explode. I'd call that 'problematic' because if it were my…

> Provide me one legal use case better suited to cryptocurrency than the US dollar.

Sending money to people overseas without extortionate fees. Surprisingly not everyone overseas is linked with international terrorism as you imply.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#203

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

2FA has no place over phone networks for account recovery. It's far easier to obtain access to 2FA texts or doing SIM ports like this, than it is to break some gmail account password (even a weak one).

So many people don't seem to understand this - I was trying to use U2F yubikeys on gitlab a while back only to discover they force you to enable 2FA first for account recovery, this completely defeats the purpose of hardware auth, it's not supposed to be for convenience, security is only as strong as the weakest link, 2FA is very weak.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#204

Earlier quoted context omitted.

For any significant crypto holdings you should be using a hardware wallet, and for serious holdings you should also use a multisig setup.

Right but what if the blocks fill up and transactions are taking forever right when you (and others) have the most interest in selling?

This is why you do long term holding in BTC or any coin that may take longer to confirm on the chain and the money you are playing/trading with should be in an asset like XLM which transfers in seconds.

Now if the whole thing is tanking and you want to transfer your entire savings to try and ride the wave you are already too late if your money is not already on an exchange and you shouldn't be 100% swing trading anyway.

Just my opinion on how I handle it.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#205

Earlier quoted context omitted.

No, you are not liable when someone robs the bank you use.

IF someone managed to rob your account entirely through a mistake of the bank, it is the govt pointing the gun at the banks head (figuratively and literally) to give you your monetary assets. With crypto the government can't get involved so you're screwed

The banks know this, and they don't like losing money, so they have made most of their transactions reversible. There was an article on this a few years ago exploring why bank account credentials are worth little on the black market. Basically, there isn't an easy, safe way to just steal money out of a bank account.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#206

Earlier quoted context omitted.

> Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? More aptly though, I would declare it problematic if I couldn't drive 10 feet without someone carjacking me in my ostensibly armored car, or if pressing the button on my radio caused the car to explode. I'd call that 'problematic' because if it were my…

> Provide me one legal use case better suited to cryptocurrency than the US dollar. Sending money to people overseas without extortionate fees. Surprisingly not everyone overseas is linked with international terrorism as you imply.

Stellar and IBM's WorldWire are hoping to tackle the remittances issue! Check it out if you haven't.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#207
post #173
post #165

Earlier quoted context omitted.

Traditional financial regulation and compliance is a joke and mostly security theatre from the perspective of a security engineer or cryptographers. - credit cards with secrets printed and shared in plain sight - hacked banks - hacked atms It only works because most involved are somewhat trustworthy and the damages are small enough that it’s still worth to have the system. But the latter also seems to be true for cry…

> credit cards with secrets printed and shared in plain sight This is a simplification. For all customer-present transactions cards use the secrets in a secure chip, and the transaction is authorised by the cryptographic processor in those chips signing the transaction data with a secret key. It's classic 2FA - Something you have (a card) and something you know (a PIN). The type-in-a-number-on-a-website purchases are…

Most chip credit transactions in the US dont use a pin yet.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#208

I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…

> My 2FA for gmail is now my iphone and ipad

sorry - how does that work? what's the platform / messaging service?

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#209

Earlier quoted context omitted.

> Cars are designed to travel at lethal speeds. If you were reckless and killed someone or yourself, do you also declare it to be an "insanely problematic technology"? More aptly though, I would declare it problematic if I couldn't drive 10 feet without someone carjacking me in my ostensibly armored car, or if pressing the button on my radio caused the car to explode. I'd call that 'problematic' because if it were my…

> Provide me one legal use case better suited to cryptocurrency than the US dollar. Sending money to people overseas without extortionate fees. Surprisingly not everyone overseas is linked with international terrorism as you imply.

> Surprisingly not everyone overseas is linked with international terrorism as you imply.

Unless you're trying to send money to North Korea that wasn't my implication at all, I have family overseas to whom I manage to send money without crypto or getting overcharged.

There are tons of international remittance services already including Andreesen-backed TransferWise which charges ~0.85% or less to move money internationally. Much less than the sum total of the cost of buying coins on an exchange in one country, paying an on-network transaction fee, risk of huge swings in the asset value and fraud along the way and one more exchange transaction fee in the destination country.

Generally even WU is quite competitive. In markets where they appear pricey the cost is usually to de-risk things like political issues which are all borne by crypto too but opaquely.

For instance, the USD-INR corridor is almost fee-free on all services.

If you've got a ton of money to move, you may be best off opening an Interactive Brokers account and performing the exchange there. They take a commission minimum of $2, or 0.002% ($2000 per million) for the trade. [1] It's a $5.1T per day (legitimate) market after all.

This is not a particularly good example, it's a solved problem.

[1] https://www.interactivebrokers.com/en/index.php?f=1590&p=fx

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#210
Here in India pretty much every online banking transaction requires an SMS OTP. To get a SIM card changed, you need to provide govt ID + you don't get any text messages for 24 hours. IIRC, if you go into a store asking for a SIM swap they also send you an OTP, and ask you to text the new SIM's serial number to a special number to activate it.
Post reply on HN