Hackers Have Stolen Millions of Dollars in Bitcoin Using Only Phone Numbers
forbes.com
forbes.com
It would be great if online services showed a clear matrix of authentication methods so you can see which combinations are sufficient and necessary to access your account. Simply adding a 2nd factor is a bad idea because it means if you lose either one, you're locked out of your account, so you also need a 3rd factor to protect you from yourself. I personally have 4 factors for my gmail account - regular SMS 2FA, a friend's phone number for password recovery and paper backup codes. This way, I can lose almost any two factors and still have access. If I forget my password and also lose access to my friend's phone for password recovery, then perhaps I'll be in trouble but Google doesn't make it clear if they'll let you in using only your backup codes and 2nd factor phone number.
Why is this ridiculous? Isn't this the same thing that Gmail offers for your own account? If you lose your password, Gmail will only send the recovery info to your friend's phone?
A simple automated SMS from your current provider that requires a "YES" response would be a lot securer and shouldn't be hard to implement.
Stop commenting on things you know nothing about.
Many landline and voip providers really do just require a signature.
Phone companies seem to be starting to take the issue more seriously as of the last few months due to the aforementioned bad press. Verizon just forced me to create a PIN by Jan 24th, 2017. So I didn't have a PIN until less than a month ago.
Me: Hi, my phone number is X. I put my phone in the wash, please transfer my number and minutes to this new phone.
Telco: Ok what was your old serial number?
Me: I don't know, my old phone went through the wash.
Telco: Um...ok you're all set.
Generally, if the CSR partially matches what the new provider gives, the port will be approved as the old CLEC doesn't want any escalation of a port.
Because support teams aren't coordinated with call attempts you can essentially brute force the process
Also the online portals for number transfer are notoriously weak. There was one MVNO i used for years because their website did no server side auth and I could transfer numbers to new SIMs at will
SMS as an authentication transport is beyond useless - nobody should be implementing it
They can't even hold it over an unpaid debt. Worse, a lot of these laws have government SLAs in them that say x% of transfers have to happen within 2-3 hours (usually 90-99%)
There is zero incentive from any party to add friction to the process for authentication purposes
It really got easy when I noticed the process was automated by a lot of providers a few years ago. I really don't think there was any human oversight on many of these transfers (perhaps a rubber stamp from a cheap offshore pair of eyes for compliance purposes)
But it seems secure enough. It is not easy to get an IMSI for a random phone number.
This is easy if you have an SS7 network connection. Comparable to the difficulty of resolving a DNS name to an IP address using an internet connection.
Tack this on to the list of reasons why no normal person will use bitcoin in any quantity.
[1] https://www.namecheap.com/support/knowledgebase/article.aspx...
The major crux of this article is the paragraph where it talks about how regulations essentially allow phone carriers to do whatever they want, with no guarantees of security, no indemnity, and if anything goes wrong there's no repercussions whatsoever.
There is literally nothing you can do to prevent this, any kind of "flags" or "extra security" you request are entirely enforced at the whim of individual call center personnel, and it only takes one person to ignore them. My case was similar to the article, I had some basic security flags enabled on the account but they were buried in notes from calls years ago and obviously no CS rep is going to read through years of notes on every call.
In my case the attackers called Sprint customer service over 100 times over a 5 day span. On the day I was breached they called 12 times within 3 hours before a weak link allowed them to transfer my number. No alerts to myself or the account holder, no notifications, nothing. The first rep I called after this occurred gave me great detail into the calls and what they had asked, apparently some of the numbers even came from different European countries. I immediately tried to escalate to their fraud department and was stonewalled hard. The fraud people denied any pattern of calling into their support lines, denied any transfer of my number (even though reps later happily helped transfer it back from Google Voice), and denied any action on the part of Sprint that caused this to happen.
Lawyers essentially told me I was out of luck, there was no recourse unless I was willing to go to war in the courtroom and unfortunately I don't have _that_ many old BTC.
It is absurd that such telecommunications backbones have such lax policies, much less no repercussions when they screw up. This will continue to be an attack vector until we force some sort of regulation that requires extraordinary damages to be paid per case... something tells me even low fines and slaps on the wrist won't incentivize the telecoms to provide actual customer service.
So, in a word, phone carriers are actually unregulated when it comes to the relevant facts in here.
Isn't that a paradox then? Using bitcoin in order to deregulate the financial system and then ask more regulation for phone carriers in order to protect your unregulated bitcoin?
The OP was asking that the phone companies should have more regulations in place to go beyond the contract being offered.
Beyond that, the pros and experts who have a lot do cold storage. Putting the keys offline.
I know in the UK I would have spoken to OFCOM or CISAS.
This exact scenario happened last week to a friend of mine, I wrote a little article about it: http://gregschlom.com/misc/2017/01/29/hacking-paypal-account...
Super fragmented, but Nexus 5X had it.
Granted, the unauthorized porting issue makes it a faulty possession factor in the first place.
In the UK, the first step in porting a number is to request a 'Porting Authorisation Code' from your current provider. They don't give you that over the phone, but send you an SMS. So AFAIK you need to be able to receive SMS on the number already, in order to transfer the number to another provider.
So, was this hack enabled by a weakness in the US number porting process?
(In China, where I live, number porting isn't possible. Getting a new SIM requires you to physically present yourself and your passport or national ID card. If passport, the passport number must match the passport number they have on file, so a replacement passport wouldn't get around this requirement.)
here = UK?
That story got him quite significant press at the time, I found thousands of deviations of the original Bloomberg story - people LOVE the "darwin award" story category.
I was going to crack a joke about this being a Paul Graham submarine strategy (2) but it's just too sad and I believe him, 2FA is a mess.
(1) https://www.bloomberg.com/news/articles/2013-04-10/meet-the-...
The apps are actually more secure.
> But 2FA via SMS is ubiquitous because of its ease of use. “Not everyone is running around with a smartphone. Some people still have dumb phones,” says Android security researcher Jon Sawyer. “If Google cut off 2FA via SMS, then everybody with a dumb phone would have no two-factor at all. So what’s worse — no two-factor or two-factor that is getting hacked?”
The thing is, SMS is worse than a reasonably good password. So it's a bit annoying that Google strongly encourages me to register my phone number with my gmail account for recovery.
And many services, including Google, make it difficult or impossible to enable TOTP without first registering a phone number. They really really push the SMS route. Brings up the average security level for the average person, I'm sure. Very annoying for me.
So (for me) it's a real PITA when places require a mobile phone number and there's no way to skip it. Obviously, can't use those services.
Does anyone know if Google Authenticator would run on a wifi iPad? As a potential workaround for the "no mobile network" situation.
That being said, it hadn't clicked that a non mobile (eg laptop/desktop) version of it could exist.
The wikipedia page for it says it's strictly mobile only[1], as does the Google install info page[2].
[1]: https://en.wikipedia.org/wiki/Google_Authenticator
[2]: https://support.google.com/accounts/answer/1066447
Oh well.
Apparently I had disabled my device's (the one with the authenticator app) "automatically set time from NTP" feature. Over time this resulted in my device's clock drifting X seconds away from the providers' clock(s), which in turn resulted in my occasionally using codes that were already X seconds expired.
A reasonably trustworthy APK download can be found on f-droid: https://f-droid.org/repository/browse/?fdfilter=freeotp&fdid...
How the hell did they even get on his him computer in the first place? I don't see how 2FA breaches could accomplish that.
edit: apparently you can have Microsoft make your online Microsoft cloud password be tied to your machine login. That's such a bad idea. One Microsoft customer support moron can effectively kill you computer. Also, even if they got this guy's computer password, how the hell did they get into it remotely? He made his computer visible for remote login on the Internet. I can't believe that.
I really do not condone ripping people off or hacking but I have to admire the tenacity of these hackers, nothing is out of bounds, every opportunity to steal or rip people off is a naked call option where only their time is the currency that can be lost with a failed heist.
It's the new bank robbers of our age but without films or hollywood glamourizing it (yet) the same bank robbers.
Crime does pay but it's a shame smart talent is being used to destroy not build. We can't point fingers at specific regions or countries with a depressed economy and expect them to find honest work-they may not exist there when government corruption has already robbed their citizens of the livelihood they were owed. This is not a justification for criminal action but a mere observation of the structural environment giving rise to such behaviours.
I don't see how to stop it though. For areas of the world with few economic opportunities, and little resources to chase you...the risk/reward profile is just too tempting.
but this is just fucked up and repulsive. it's sad how poverty can dehumanize people into doing inhuman things for money.
I think one of the biggest factors is culture. If you live in this "skype scam city" and all of your friends are doing it, then no one is judging you and you won't have too much trouble sleeping at night. On the other hand if you're in a very moral place you probably wouldn't do it.
https://www.wired.com/2008/11/valve-tricked-h/
https://arstechnica.com/gaming/2016/06/what-drove-one-half-l... (better story)
I definitely won't be buying Half Life 3.
TIL Gabe Newell is actually very narrow minded and not a nice guy. Hacking and leaking is also bad but it's not clear that the action led to losses when Half Life 2 was a phenomenal success. It's the deceptive tactic of pretending to offer an olive branch and going back on your word. He should be fucking ashamed of himself.
Tony Montana said it the best: all you really have at the end of your life is your word and your balls and how well you kept them.
[1] https://en.wikipedia.org/wiki/Shut_Up_and_Dance_(Black_Mirro...
If the amount is above say, $500 or so, it should be stored in something like a Trezor, where only you have the keys to access it.
This post [1] from Kraken covers how to protect yourself from this kind of attack. It's quite thorough. Interesting even if this isn't a concern for you directly.
1 - http://blog.kraken.com/post/153209105847/security-advisory-m...
A 40-step instruction "how to make your google account secure" as a proof of the sad state of internet security. No way my parents can do it.
Ledger Nano s, Trezor, and KeepKey all stop this sort of attack.
[1] https://en.bitcoin.it/wiki/Hardware_wallet#TREZOR_The_Bitcoi... [2] https://doc.satoshilabs.com/trezor-faq/threats.html#what-hap...
If you want to be really secure you can engrave your recovery seed into a piece of metal that won't melt in typical house fire temps like brass.
With a hardware wallet your private keys never touch your computer so they can't be stolen. Even if you are the kind of person that can't resist clicking on every piece of malware you encounter your Bitcoins can't be stolen from a hardware wallet.
Bottom line hardware wallets are easy to get right.
The windows 10 experience
But Macs work similarly IIRC; if someone has access to your iCloud account, they own your machine as well.
I think this is more of a comment on the cloud-centric-everything-must-live-in-the-cloud-now mentality than anything else.
But there's good reason these OSes tie local logins to online accounts. The average user is more likely to get frustrated forgetting or not understanding why their email password is not their login password, than the (comparatively) rare scenario that someone will compromise the one-account-to-rule-them-all and wreck all their data. My grandmother confuses her Gmail login with every other online account because they all use the email address as a username.
Also, I'm continually amazed how little normal people care about the data on their computers. I still have all my files from when I was 5 years old on my main machine, but most people only care about bringing over whatever they're currently working on when they get a new machine.
Sort of misses the point when BTC was going from $0.08 a coin to $1000 a coin.
Most index funds don't offer a $64 to $800,000 trajectory even over 5 years.
It refers to the fact that people get rich from bitcoin if they don't fall off their bull by:
Losing their coins e.g. forgetting a password, throwing away a laptop.
Having their coins hacked from their computer by a Trojan or the mentioned attack.
An exchange loses them or shuts down.
Due to greed you wait it out and bitcoin plummets to zero
Due to greed day trade your stash into the ground.
Due to fear sold your 1000 btc at 10$ each back in the day.
Etc.
Great system.
As a result you probably aren't going to get the government failure guarantees on bitcoin as you would for fiat. Let alone governments wont want you using a different currency that they can't print.
I agree with your point about government failure guarantees, however.
"correct horse battery staple"
is 29 characters, but it's _much_ more likely to fall to hashcat than
"OckivpykophshifcuvTocJorj%opAd"
I've only got 4 truly random passwords stored solely in my head, and they're all down at 12 chars because I need to write them down much above that instead of being reliably able to remember them (and yeah, I've got stuff I no longer have access to because I've forgotten the password...). There's a serious tradeoff to be made with a password for "millions of dollars worth of bitcoin" - where do you balance the "it's super secure" against the "Shit! I forgot the password!" (And if your first answer is "that's what password safes are for", then you've just moved the problem to the password safe's password...)
(With a reasonable dictionary, "correct horse battery staple" will probably pop out from hashcat in under a second on a Raspberry Pi! ;-) )
Is this being reported correctly? This sounds completely nuts.
http://www.coindesk.com/facebooks-ben-davenport-leaves-bitco...
Lloyds isn't getting involved unless they have an incredibly high degree of satisifaction in security processes, in fact they stripped Elliptic of their first ever "vault" insurance shortly after awarding claiming they didn't like the "publicity".
http://www.coindesk.com/lloyds-back-bitcoin-insurance-deal-e...
Get a mobile wallet like Mycelium. It's very simple, and you back up your wallet forever with a short string of words. You also retain control of your private keys.
How is using Coinbase different from holding a balance with any other bank?
If you follow modest security practices (like spending $100 on a hardware wallet), you certainly don't need Lloyd's to insure your wallet.
> How is using Coinbase different from holding a balance with any other bank?
It's fairly similar. Half the point of Bitcoin is that you aren't obligated to use a bank. You can just take care of it yourself.
This Coinbase support article[0] succinctly describes what they are insured against. Important points are that only about 2% of their total Bitcoin deposits are insured, those that they keep "online". The insurance does _not_ apply to losses suffered due to an individual's account being compromised.
[0] https://support.coinbase.com/customer/portal/articles/166237...
If you want to store Bitcoin, use (in order of preference) a reasonably secure computer (not an obviously poorly secured windows machine), a secure cell phone (not a $50 backdoored Chinese android phone), or a hardware wallet. Don't use cloud services, web wallets, or anything else that very obviously sucks from a security perspective.
I would be more than willing to trust, say, $50,000 in Bitcoin to an iPhone with a good passcode, running an SPV wallet. Above that and you probably ought to put in the modest investment for a hardware solution.
Shame he didn't keep them in an exchange. Oh wait...
I always thought had I got in early in bitcoin I'd plan to sell off in tranches at $1, $10, $100 value etc. Then at least when the coins get stolen or worthless I'd have something to show for it.
My prediction: Bitcoin will become worthless in the long term once the crypto is cracked by mathematics, a backdoor or quantum computing
It places users in the position of either having to provide their own bank-level security, or to leave their bitcoin with a BTC bank (the exchanges). The latter has had a few issues.
multisignature wallet. shame an early adopter don't use it.
And how did they crack a 30 character password? Was it written down somewhere? Or extremely repetitive?
He had the bitcoins stored in an external encrypted hard drive. Then he plugged the hard drive in, and they somehow stole them. They were encrypted with a 30 character password. You can't do a password resent on encryption. I'm asking how did they get the file from his external hard drive, and how did they decrypt it?
Love it!!
I dont get how 2fa is supposed to prevent local hack btw
https://medium.com/@fpresencia/your-email-is-your-password-5...
Is there an app or service that does this without them having access to your bitcoins?
This is an incredibly bad idea. This publishes an unsalted, unhardened hash of your password to the blockchain to be cracked by anyone. There are bots with large precomputed tables that will instantly steal from especially weak ones.
If it's a large amount, do it on a cleanly installed Linux, and then secure-erase the partition after you're done.
Make sure your passwords are long and random.
Make sure you store your passwords securely.
Is this really correct? It sounds low.
Running a full node takes 100GB of disk space and some dozens of GB in bandwidth every month. It consumes a lot of ram as well, and if you are running a heavy OS you will often notice your computer is slower.
The cost of running a full node is one of the major reasons people oppose a bigger block size. Most wanting bigger blocks don't run their own full nodes.
http://blog.kraken.com/post/153209105847/security-advisory-m...
I regularly get aggravated about the sensitivity of my bank's fraud screening. I have to call them constantly just to spend my money. But, I am at least reassured about how difficult it is to siphon money from the account.