Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

51–60 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#51
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

How did they know your email password and phone number at the same time?

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#52
I’ve mostly disabled 2fa via phone where alternatives exist. Unfortunately some services (such as twitter) require you to verify a number (you can sign up, but you’ll quickly be account-locked without providing a number)

I’m still wondering why I can’t use Touch ID to do U2F...

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#53

He's got good evidence. The SIM-swappers have actually been convicted. ATT says it's "an industry" problem, but it's 100% their problem. They are doing nothing to stop employees from robbing their customers. Of course the victim could probably have protected his "life savings" better, but that's not the point.

AT&T's going to say "you don't own that phone number--it's ours--and we never said it was intended for verifying your identity. Take it up with whoever stole your number and your--wait, someone stole your cryptocurrency ? You realize banks are insured against mistakes like this and bitcoin wallets aren't, right?"

Losing your life’s savings in an irrevocable way is a feature of crypto currency. Not a bug!

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#54
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

How did they know your email password and phone number at the same time?

The main e-mail they targeted was included in several breaches, specifically of note the CafePress and Yahoo breaches, but various others as well. I would wager they just compiled data from each until they found something that worked.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#55
post #10

This is exactly why I’m only faithful to FIDO U2F keys. Got a couple and ensure they’re safe. No one’s hacking my accounts unless they crack both my passwords and rob me physically... which at this point doesn’t seem like it’s going to happen.

“Hello thanks for calling. I understand you want to reset your password. To verify it’s really you may I have your cryptographically impregnable super token? Oh it’s lost, I see, how about can you verify your billing zip? Splendid you’re all reset.”

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#56
post #10

This is exactly why I’m only faithful to FIDO U2F keys. Got a couple and ensure they’re safe. No one’s hacking my accounts unless they crack both my passwords and rob me physically... which at this point doesn’t seem like it’s going to happen.

“Hello thanks for calling. I understand you want to reset your password. To verify it’s really you may I have your cryptographically impregnable super token? Oh it’s lost, I see, how about can you verify your billing zip? Splendid you’re all reset.”

I think he's saying that the private keys to his crypto never leave physical hardware. There is no phone number to call if he loses them, but on the other hand what you are describing is impossible.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#57
post #56

Earlier quoted context omitted.

“Hello thanks for calling. I understand you want to reset your password. To verify it’s really you may I have your cryptographically impregnable super token? Oh it’s lost, I see, how about can you verify your billing zip? Splendid you’re all reset.”

I think he's saying that the private keys to his crypto never leave physical hardware. There is no phone number to call if he loses them, but on the other hand what you are describing is impossible.

The joke is a thief will get ahold a live person and still be easily able to social engineer account access, despite best efforts to lock it down with technology.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#58

I’ve mostly disabled 2fa via phone where alternatives exist. Unfortunately some services (such as twitter) require you to verify a number (you can sign up, but you’ll quickly be account-locked without providing a number) I’m still wondering why I can’t use Touch ID to do U2F...

Touch ID support for WebAuthn is live in the latest Chrome!

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#59
post #56

Earlier quoted context omitted.

I think he's saying that the private keys to his crypto never leave physical hardware. There is no phone number to call if he loses them, but on the other hand what you are describing is impossible.

The joke is a thief will get ahold a live person and still be easily able to social engineer account access, despite best efforts to lock it down with technology.

That’s not how private keys work...
Post reply on HN