Earlier quoted context omitted.
Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. As long as you can still get in to revoke/enroll stuff you should be okay. It’s not so much a problem as it is a balance of security, redundancy, and effort. You decide where you want to be on that balance of considerations.
> Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. Yeah, good luck. I don't know of any system that lets me enroll 3 security keys for an account.
Man sues AT&T over 'SIM Swap' hack allegedly involving employees
71–80 of 129 posts
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#72Earlier quoted context omitted.
What happens if the keys get lost or destroyed? It seems like a never ending problem.
Get 2 keys, keep one in a safe place. Add both to your important accounts. Then also setup TOTP, so if you lose both keys and have a working cell phone with the app installed you can still login.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#73Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#74Earlier quoted context omitted.
“Hello thanks for calling. I understand you want to reset your password. To verify it’s really you may I have your cryptographically impregnable super token? Oh it’s lost, I see, how about can you verify your billing zip? Splendid you’re all reset.”
Suppose we take Coinbase (I don't use it, but I've heard SIM swapping is done regularly with Coinbase): Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email). Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I…
The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#75Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#76I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…
So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.
See: https://www.nytimes.com/2015/11/01/business/dealbook/arbitra...
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#77Earlier quoted context omitted.
Suppose we take Coinbase (I don't use it, but I've heard SIM swapping is done regularly with Coinbase): Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email). Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I…
Try it. Most companies don’t mind. The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.
Which keys is it supposed to backup?
Everything else you said is sadly true.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#78This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…
Exactly. Cryptocurrency, in my view, are meant to be intermediary currency. Keeping a lot of it is just too risky.
Tech nerds seem to like cryptocurrencies because it's a cool and fancy gadget, but the reality is that normal banks are more secure. If your money gets stolen, banks can trace it, cancel transactions, and there are insurances in place to recover your money. Governments are involved in bank security.
Currencies are not trivial things. Only libertarians and anti-government, anti-federal-reserve people will actually prefer cryptocurrencies to their own risk.
I get that the AT&T employee is guilty, but the victim was asking for it.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#79I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…
So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#80Earlier quoted context omitted.
Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.
It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.