Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

41–50 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#41
post #36

The amazing thing is with Wells Fargo that if you have a RSA SecurID 2FA FOB for access to your bank accounts, and you have a phone number configured for the account, you can use EITHER the 2FA RSA one-time pin, OR SMS verification to log into your bank account web page. I mean this is a bank, are these guys for real?

Yes, although there is actually a lower transaction limit on sessions initiated with SMS 2FA vs SecurID.

Which almost furthers the point that this is bad, isn’t this an acknowledgement by them that SMS 2FA is less secure? If it’s less secure and you have SecurID, why can’t I disable SMS?

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#43
post #41

Earlier quoted context omitted.

Yes, although there is actually a lower transaction limit on sessions initiated with SMS 2FA vs SecurID.

Which almost furthers the point that this is bad, isn’t this an acknowledgement by them that SMS 2FA is less secure? If it’s less secure and you have SecurID, why can’t I disable SMS?

There is support cost for disabling sms. While you may be technically inclined to be comfortable with disabling sms, they have to balance the cost of hacking vs support cost for all users.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#44
post #33
post #21

Earlier quoted context omitted.

Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.

It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.

And when you (unavoidably) get hacked, they tell you it's your fault and that it sucks to be you, because you are not getting that money back.

https://www.cbc.ca/news/business/banks-deny-compensation-onl...

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#46

He's got good evidence. The SIM-swappers have actually been convicted. ATT says it's "an industry" problem, but it's 100% their problem. They are doing nothing to stop employees from robbing their customers. Of course the victim could probably have protected his "life savings" better, but that's not the point.

Their employees and their systems.

Ideally it wouldn't be possible for a single employee to do this.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#47
post #32

I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

If by “him” you mean AT&T, definitely.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#48

He's got good evidence. The SIM-swappers have actually been convicted. ATT says it's "an industry" problem, but it's 100% their problem. They are doing nothing to stop employees from robbing their customers. Of course the victim could probably have protected his "life savings" better, but that's not the point.

AT&T's going to say "you don't own that phone number--it's ours--and we never said it was intended for verifying your identity. Take it up with whoever stole your number and your--wait, someone stole your cryptocurrency? You realize banks are insured against mistakes like this and bitcoin wallets aren't, right?"

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#49
post #21

This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…

Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.

Sad that one of my current banks (Chase) won't add TOTP to their login.

Edit: https://twitter.com/skunkworker/status/1131297869703438337

@ChaseSupport Hey Chase, when will offline TOTP be added for a more secure login?

Thank you for reaching out! What we have is the multi-factor authentication on all online accounts. You can visit https://tinyurl.com/y7r2fztd for more info on how we protect and secure your information. ^AA

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#50
Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't make.

Currently working on finishing moving passwords from a Google account to my password manager and resetting them all, as well as replacing anything that uses an SMS 2FA with a time based authenticator or other alternative where possible. Planning on getting a FIDO key to use where I can. Also setting up a Voice number on an account that's used for nothing else besides 2FA in the instances where there is no better form of authentication.

Post reply on HN