Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

71–80 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#71
post #66

Earlier quoted context omitted.

Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. As long as you can still get in to revoke/enroll stuff you should be okay. It’s not so much a problem as it is a balance of security, redundancy, and effort. You decide where you want to be on that balance of considerations.

> Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. Yeah, good luck. I don't know of any system that lets me enroll 3 security keys for an account.

Doesn't Google let you set an arbitrary amount?

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#72
post #23
post #18

Earlier quoted context omitted.

What happens if the keys get lost or destroyed? It seems like a never ending problem.

Get 2 keys, keep one in a safe place. Add both to your important accounts. Then also setup TOTP, so if you lose both keys and have a working cell phone with the app installed you can still login.

That's if important accounts allow you to do that. For example AWS only allow one MFA key

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#73
To me this is more about the lack of internal controls and auditing of those controls at ATT. I know someone who is a supervisor fairly high up with them and I suspect has abused that power to spy on an ex, but she assures me "he can't because of the internal flags"... I figure there are a multitude of ways around that. Events like this don't give me confidence that I am wrong.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#74
post #67

Earlier quoted context omitted.

“Hello thanks for calling. I understand you want to reset your password. To verify it’s really you may I have your cryptographically impregnable super token? Oh it’s lost, I see, how about can you verify your billing zip? Splendid you’re all reset.”

Suppose we take Coinbase (I don't use it, but I've heard SIM swapping is done regularly with Coinbase): Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email). Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I…

Try it. Most companies don’t mind.

The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#75
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

One thing I've noticed lately is that Google Voice numbers are working with fewer and fewer companies. For example, I don't think that they work with Wells Fargo or Chase. Wells Fargo said flat out that the phone number can't be validated.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#76
post #32

I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

Binding arbitration is almost unilaterally bad for consumers.

See: https://www.nytimes.com/2015/11/01/business/dealbook/arbitra...

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#77
post #67

Earlier quoted context omitted.

Suppose we take Coinbase (I don't use it, but I've heard SIM swapping is done regularly with Coinbase): Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email). Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I…

Try it. Most companies don’t mind. The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.

I don't think you completely understand the concept behind the Google Authenticator App, i.e. the standard it implements.

Which keys is it supposed to backup?

Everything else you said is sadly true.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#78

This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…

> Also, don't have your life savings in crypto

Exactly. Cryptocurrency, in my view, are meant to be intermediary currency. Keeping a lot of it is just too risky.

Tech nerds seem to like cryptocurrencies because it's a cool and fancy gadget, but the reality is that normal banks are more secure. If your money gets stolen, banks can trace it, cancel transactions, and there are insurances in place to recover your money. Governments are involved in bank security.

Currencies are not trivial things. Only libertarians and anti-government, anti-federal-reserve people will actually prefer cryptocurrencies to their own risk.

I get that the AT&T employee is guilty, but the victim was asking for it.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#79
post #32

I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

.. but is guaranteed to rule in favor of the bigger party.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#80
post #33
post #21

Earlier quoted context omitted.

Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.

It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.

The banks already know what happens when you issue every customer a 2FA token, because they issue you a bank card. You have to verify the customer is who they say they are before giving them the token, and have processes for dealing with a lost or stolen token.
Post reply on HN