Live data from Hacker News

Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

cnbc.com

61–70 of 137 posts

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#62
post #34

Earlier quoted context omitted.

> If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information By Kerckhoffs's principle > https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr... a cryptosystem has to stay secure even if everything about the system, except the key, is public knowledge. So Bank A is at fault, because it neglected basic guiding principles for designing security systems.

Which gets to the frivolity of the lawsuit. The primarily responsible party, the exchange, is likely a less lucrative target than AT&T.

Suing the people with the money is rule #1 of lawsuits.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#63
post #15
post #9

Earlier quoted context omitted.

In the US it is trivial to hijack any mobile number's SMS traffic. It takes less than a minute. SMS as 2FA should never ever be used by anyone.

How does it work? Why is it so easy?

It's easy because a) the signaling system in use is pathetically insecure, b) the wireless protocols are pathetically insecure.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#64
post #6

Wasn't it like a year ago that famous YouTubers and such were getting their accounts stolen the exact same way and AT&T promised they would tighten up security measures?

Yes, you have to opt-in to this type of security

Opt-in security is the best form of security, after security by obscurity /s

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#65
post #56

If Bank A makes my PIN number automatically the last 4 of my SSN, and Company B discloses that information, is Company B responsible for 9 times whatever losses I incur if my ATM is stolen?

It's still absurd to me that it's nearly impossible to prevent BofA and other institutional banking companies from sharing this information.

I think that ship has already sailed. We need to be moving to a world where those magic strings aren't valuable, and punish companies that use them. It seems unfair; punishment feels it should be directed at the leakers, but you can't put toothpaste back in a tube, at least not cleanly, and the toothpaste is still likely contaminated regardless.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#66
post #27

Earlier quoted context omitted.

SMS is not exactly the most secure protocol. But you do not need to use SMS for 2fa, that's a misconception.

Isn't it effectively plaintext? I don't know too much about the SMS protocol. But I do know that most protocols do start out plaintext because programmers are lazy and optimistic.

That’s one part of the problem. The other part is that it’s actually quite easy to convince most cell phone carriers to change the SIM card associated with a given phone number. Once you’ve pulled that off hijacking the account is easy.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#67
post #45

Earlier quoted context omitted.

> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel

And then increase it again by arguing that AT&T should never have made it possible for employees to do this.

And then diminish it to zero again because yes it should be possible for employees to do that. The economic value for most people of being locked out of your phone number and not being able to easily fix the problem or easily upgrade a phone exceeds the cost imposed when some of those people are morons and assume ability to receive an SMS message sent to a particular phone number is any sort of security factor.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#68
post #54

While I was working at a blockchain forensics company (we built one of the first AI backed block-explorers both for Bitcoin and Ethereum & our service was also used to identify the DAO hack), both myself and my boss were targeted multiple times a year with this kind of attack even though we held no crypto through the company. It seemed that just since my name was on the web with the word crypto I was a target. To thi…

> Most also don't know that accounts such as Authy and other non-SMS 2FA authenticators can still be stolen if your mobile number is stolen.

I was under the impression that apps like Authy and Google Authenticator have no connection with the telephone network/phone number. Do you have any reference that claims otherwise?

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#69
post #45

Earlier quoted context omitted.

> AT&T would be at most 50% responsible You could reduce that further by arguing AT&T aren't at fault because third-parties built authentication and identity protocols ontop of what was never guaranteed to be a secure or authenticated channel

And then increase it again by arguing that AT&T should never have made it possible for employees to do this.

Accountability yes, but holding them responsible for what their service was used for is a slippery slope.

Re: Cryptocurrency investor robbed via his cellphone account sues AT&T for $224M

#70
post #49

Earlier quoted context omitted.

I'm going by the content of the story, which describes acquiring the phone number as the key issue. > After the first hack, Terpin alleged that an impostor was able to get his phone number from an "insider cooperating with the hacker" without an AT&T store employee requiring him to show valid identification or provide a required password. That phone number was later used to access Terpin's cryptocurrency accounts, ac…

“Acquiring the phone number” means getting it mapped to the attacker’s phone/SIM card. Overview of SMS hijacking (copy paste link, JWZ doesn’t line HN referrer headers): https://www.jwz.org/blog/2018/07/two-factor-auth-and-sms-hij...

What you say must be the real story.

It's just that the article says, "was able to get his phone number".

Getting a phone number, to me, has always had a pretty universal meaning, which is to simply learn its digits. But I suppose you must be right and they actually mean a deeper compromise.

Post reply on HN