Live data from Hacker News

Man sues AT&T over 'SIM Swap' hack allegedly involving employees

foxla.com

91–100 of 129 posts

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#91
post #32

Earlier quoted context omitted.

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

If by “him” you mean AT&T, definitely.

Arbitration is cheaper for both parties than court, in general.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#92
post #36

The amazing thing is with Wells Fargo that if you have a RSA SecurID 2FA FOB for access to your bank accounts, and you have a phone number configured for the account, you can use EITHER the 2FA RSA one-time pin, OR SMS verification to log into your bank account web page. I mean this is a bank, are these guys for real?

Thats really bad. Chase doesn't even offer the option of non-phone 2FA

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#93
post #33

Earlier quoted context omitted.

It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.

And when you (unavoidably) get hacked, they tell you it's your fault and that it sucks to be you, because you are not getting that money back. https://www.cbc.ca/news/business/banks-deny-compensation-onl...

This is insane. How are banks not liable for fraud in Canada? The incentives couldn't be worse.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#94
post #32

Earlier quoted context omitted.

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

Binding arbitration is almost unilaterally bad for consumers. See: https://www.nytimes.com/2015/11/01/business/dealbook/arbitra...

https://levelplayingfield.io/

For 2015, it shows the majority of cases settle, about 3k out of 5k. Out of the remaining, more than half get some kind of award. But reporting this data goes against the NYTimes narrative so they cherry picked.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#95
post #79
post #32

Earlier quoted context omitted.

So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.

.. but is guaranteed to rule in favor of the bigger party.

https://levelplayingfield.io/ For 2015, it shows the majority of cases settle, about 3k out of 5k. Out of the remaining, more than half get some kind of award.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#96
post #21

Earlier quoted context omitted.

Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.

Sad that one of my current banks (Chase) won't add TOTP to their login. Edit: https://twitter.com/skunkworker/status/1131297869703438337 @ChaseSupport Hey Chase, when will offline TOTP be added for a more secure login? Thank you for reaching out! What we have is the multi-factor authentication on all online accounts. You can visit https://tinyurl.com/y7r2fztd for more info on how we protect and secure your informatio…

I'm still looking at how to best communicate with my bank too, to get actual answers. :D Not this cookie cutter kind of support.

No matter how precisely I describe the problem, I get copy paste or poorly thought out response. That's why I like smaller businesses, where there's still a connection between doers and support people, or where the doers are the support people.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#99
post #50

Had this happen to me last week. Thankfully they only tried to get into a few e-mail accounts, which I was quick enough to get into, kill their session, and recover them before any real damage was done. AT&T of course claimed it was impossible for that to happen, despite a different phone showing up in my account, a bunch of unexplained SMS messages I never received, and two calls accessing my voicemail that I didn't…

Did you have a PIN setup with ATT? I am trying to figure out which of their employees can modify the account without the PIN.

There are thousands of AT&T and Verizon accounts for sale online with PIN, SSN, DoB, email address, email password, etc. Some of them are paired with known bank account login information, credit report, etc. They're less than 300 USD.. Once you have the phone and information you can either use fake ID + SSN + phone to use established credit line at a retailer or if you have banking information perform a wire transfer. It's rampant.

Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees

#100
post #64

How do you know if someone has obtained a SIM card with your identity? Do you have a web site for this, like https://www.turkiye.gov.tr/mobil-hat-sorgulama ?

Usually your phone stops working because your old SIM card gets disabled.

You can also add an authorized user or open up an entirely new line. You won't notice until you receive your bill.
Post reply on HN