Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

61–70 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#61
post #59

Earlier quoted context omitted.

The joke is a thief will get ahold a live person and still be easily able to social engineer account access, despite best efforts to lock it down with technology.

That’s not how private keys work...

But it is how authentication works in the real world.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#62
post #2

Wasn’t there a pin on his account?

It’s better than nothing that AT&T finally allows pins at all, but one thing that’s insane about it is every time you log in on the web there’s a checkbox to never ask for your pin again. It’s exactly where you’d expect a checkbox for something like “remember me”, except it opens up a huge security hole in your account if you accidentally check it. Pins obviously have other issues that make no sense, like the incredi…

Pretty sure that's only for the current device, not for the account.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#63
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

Did you have a PIN setup with ATT? I am trying to figure out which of their employees can modify the account without the PIN.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#65
post #62

Earlier quoted context omitted.

It’s better than nothing that AT&T finally allows pins at all, but one thing that’s insane about it is every time you log in on the web there’s a checkbox to never ask for your pin again. It’s exactly where you’d expect a checkbox for something like “remember me”, except it opens up a huge security hole in your account if you accidentally check it. Pins obviously have other issues that make no sense, like the incredi…

Pretty sure that's only for the current device, not for the account.

[deleted]

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#66
post #18

Earlier quoted context omitted.

What happens if the keys get lost or destroyed? It seems like a never ending problem.

Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. As long as you can still get in to revoke/enroll stuff you should be okay. It’s not so much a problem as it is a balance of security, redundancy, and effort. You decide where you want to be on that balance of considerations.

> Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people.

Yeah, good luck.

I don't know of any system that lets me enroll 3 security keys for an account.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#67
post #10

This is exactly why I’m only faithful to FIDO U2F keys. Got a couple and ensure they’re safe. No one’s hacking my accounts unless they crack both my passwords and rob me physically... which at this point doesn’t seem like it’s going to happen.

“Hello thanks for calling. I understand you want to reset your password. To verify it’s really you may I have your cryptographically impregnable super token? Oh it’s lost, I see, how about can you verify your billing zip? Splendid you’re all reset.”

Suppose we take Coinbase (I don't use it, but I've heard SIM swapping is done regularly with Coinbase):

Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email).

Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I know as a fact you can't social hack my email provider.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#68
post #35
post #26

Earlier quoted context omitted.

I guess you can call most cryptocurrencies volatile but some like BTC and ETH have so much marketcap that it's getting a bit better. Some people truly believe in crypto (and even institutions are... they store in Bakkt) and I guess you have to respect that (pretty sure they understand the risk as well).

Yes, BTC is "only" down 23% in the last month.

I don't want to argue, but it's up 15% since last year (if you bought/sold right you could've also make 400% since last year. I don't personally have anything in crypto, but am watching enthusiastically from the sidelines (and given it's down 23% in the last month is one reason why).

At the end of the day you have to look at it from a bigger picture. Since the next halfing is happening in a year, prices will most likely go up (speculation).

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#69

This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…

No matter how careful you are, the service(bank, SNS and everything) you're using aren't. If you hand over them a phone number and they think phone number alone can identity you, you're done for.

The only solution is not using the phone. The phone reached it's limit. It's not trustworthy communication method.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#70
post #18

Earlier quoted context omitted.

What happens if the keys get lost or destroyed? It seems like a never ending problem.

Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. As long as you can still get in to revoke/enroll stuff you should be okay. It’s not so much a problem as it is a balance of security, redundancy, and effort. You decide where you want to be on that balance of considerations.

Safe deposit boxes aren’t safe: https://www.google.com/amp/s/www.nytimes.com/2019/07/19/busi...
Post reply on HN