Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

31–40 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#31
Sorry for his loss, and the mobile providers do need to do something about this known attack vector. But with cryptocurrencies you need to "be you own bank", and extending his own analogy how many legitimate or long lasting banks would store USD24 million in cash in a hotel room safe?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#32
post #15
post #9

Earlier quoted context omitted.

In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.

How does it work? Why is it so easy?

Well there's a few issues.

The SS7 (https://en.wikipedia.org/wiki/Signalling_System_No._7) does not have any authentication so anything over the telephone networks can be easily MITM'd.

And at provider's stores they are too eager to please a "customer" so social engineering is very effective at swapping SIM cards out and hijacking your number.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#33
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

Exactly. I was able to get into my Verizon account at the store by showing the sales guy my number on my phone. I was moving my number to my non-work billing account.

When I was surprised that this is all the authn they needed, the sales guy joked with the rhetorical question “well, you are , right?” i.e. “well, it ain’t a problem at the moment, right?”

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#34

If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?

> If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information

By Kerckhoffs's principle

> https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr...

a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#35
post #15
post #9

Earlier quoted context omitted.

In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.

How does it work? Why is it so easy?

Search for SS7, it's a swiss cheese of vulnerabilities.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#37
post #31

Sorry for his loss, and the mobile providers do need to do something about this known attack vector. But with cryptocurrencies you need to "be you own bank", and extending his own analogy how many legitimate or long lasting banks would store USD24 million in cash in a hotel room safe?

Following this analogy, would the bank sue the builder or vault manufacturer if they gave someone a key to the vault without the bank's knowledge and it was used to rob the vault? Or might the bank sue a armored carrier for irresponsibly storing monies that were stolen in transit between banks?

Maybe you can be your own bank, but banks have to depend on external factors/entities to do what they're supposed to do as well.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#39
post #14

I hope he wins, mainly so cell operators will perhaps take security more seriously. Not long ago, I was with T-Mobile. My username was my phone number, and the password, you could request and they'd send it to you in an email. With the climb of social media, our phone numbers are more a part of our identity than ever before, and carriers lack of security is being thrust into the spotlight.

Are you saying that they will send the password to ANY email if you just provide the phone number ?

Other poster is correct, sorry if it wasn't clear. Essentially, they were storing passwords either in plaintext or a reversable encryption scheme. Now, this was a few years ago, so I don't know the current setup, but not so far back that not storing plaintext passwords wasn't common knowledge...

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#40
post #36

Phone numbers are specifically designed to serve as public identifiers. I don't think you can expect a security mechanism that is supposed to work counter to that to work very well.

The validation mechanism is control over the phone number, not knowledge of it.

Verification by knowledge of numbers intended to remain secret (social security, credit card) is also never okay.

Post reply on HN