Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

81–90 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#81

This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…

> Irreversible transactions are kind of the whole point of it

Just as a sidenote, the problem isn't that the transactions are irreversible, they're also irreversible for banks. You never reverse the actual transaction, you just create another transaction in the opposite direction. Sometimes banks accidentally sent money to the wrong (foreign) bank and kissed them goodbye. The other bank had no obligation to send it back and if the 2 don't have a relationship and don't plan on having one it's free money for the recipient.

The difference with crypto is that you're basically dealing with "untrustworthy" parties since there's no central trustworthy authority over the whole network. The advantage is that nobody can control the network. The disadvantage is that you have no leverage over the receiving party.

It's like a private individual ad-hoc lending money to a friend vs. lending money to a total stranger. There's probably no legal obligation to return it but friends most likely will.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#82
post #66

Earlier quoted context omitted.

> Keep two or three, put one in a bank or a safe at home. That should be enough redundancy for most people. Yeah, good luck. I don't know of any system that lets me enroll 3 security keys for an account.

Doesn't Google let you set an arbitrary amount?

Yes, as does Github and Facebook. I forget whether AWS does.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#83
post #67

Earlier quoted context omitted.

Suppose we take Coinbase (I don't use it, but I've heard SIM swapping is done regularly with Coinbase): Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email). Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I…

Try it. Most companies don’t mind. The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.

That's why I use Authy (able to have backup keys).

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#84
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

How did they know your email password and phone number at the same time?

A scary amount of services will let you reset a password over SMS.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#85
post #77

Earlier quoted context omitted.

Try it. Most companies don’t mind. The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.

I don't think you completely understand the concept behind the Google Authenticator App, i.e. the standard it implements. Which keys is it supposed to backup? Everything else you said is sadly true.

You would expect that if you restore the full backup of your iOS device to a new one, because you lost it for instance, that on the new device you could open the Authenticator app and see the same keys as you had on your old device. That is not the case though.

Under the hood Google Authenticator uses keys to generate the codes you see on screen and these keys are not backed up.

It’s a difficult decision of course. If you back them up in iCloud Apple and people who hack your Apple account have access. If you don’t the keys are lost if the device breaks or is lost and you need a workaround.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#87
post #19

> and within minutes, the hackers had stolen $1.8 million in cryptocurrency from him > It essentially destroyed our financial future, our entire life savings was stolen Who keeps their entire life savings in crypto?

When they say 'life savings' (conjuring the image of money saved slowly, over a lifetime), what they really mean is 'gambling profits'.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#88
post #25
post #18

Earlier quoted context omitted.

What happens if the keys get lost or destroyed? It seems like a never ending problem.

I have one at work/keep on my computer and one at home. Some websites allow TOTP which is still safer than SMS, but if I lose one, I'll get another one while I use the 2nd.

> I have one at work

This seems really easy to steal.

> one at home

Most people I know have been burgled too.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#89
post #79
post #32

Earlier quoted context omitted.

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

.. but is guaranteed to rule in favor of the bigger party.

Why do you think so? Not what the data shows.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#90
post #32

Earlier quoted context omitted.

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

Binding arbitration is almost unilaterally bad for consumers. See: https://www.nytimes.com/2015/11/01/business/dealbook/arbitra...

Unilaterally is not an accurate description. Your link has exactly one relevant sentence:

>Roughly two-thirds of consumers contesting credit card fraud, fees or costly loans received no monetary awards in arbitration, according to The Times’s data.

Note that

1. This excludes non monetary awards

2. The categories are cherry picked and they give us no data on arbitrations overall

And even under those conditions they show a third of consumers win something, which is hardly a unilateral loss. And of course it's impossible to know how many of those cases were frivolous, and they didn't bother to compare to small claims court and see how consumers fare there.

Anyway it's not relevant to this case, because he's not suing for one of those categories, plus he presumably has a lawyer (lots of arbitrations are done without lawyers and I'd bet that they have lower success rates).

Post reply on HN