Then take some basic steps to discourage 2FA! AT&T knew it was an issue, so taking some basic measures like at least asking the likes of Twitter and Coinbase to stop doing it would be reasonable. Sounds like they didn't.
-
-
They don't have to study this issue. They simply have to observe the obvious fact that lots of people are getting hurt in this way. That requires no special knowledge. And after all, this is an issue that extends to more than just cryptocurrency: e.g. stolen gmail accounts.
-
It's not at all obvious to them. They are in a completely different business and they don't keep track of vast majority of stats in the dizzying variety of other businesses including ours. Even experts in our own industry don't keep good track of these novel risks and losses.
-
Lol, that's just silly. A company the size of AT&T can figure that out by just reading the popular technical press, and listening to their customer's complaints. You're just making excuses at this point; that's not even remotely a valid argument.
-
Regardless of their size, they don't read stuff like Bitcoin Magazine et. al that is extremely far outside their business of providing phone service, and you can't seriously expect them to have learned this kind of thing from common mainstream media.
-
This stuff has had plenty of coverage in very mainstream tech media: https://arstechnica.com/information-technology/2017/05/thieves-drain-2fa-protected-bank-accounts-by-abusing-ss7-routing-protocol/ … Again, that's a ridiculous argument.
-
...and we *know* they're aware of these problems, because phone companies offer services like account PINs to prevent them!
-
That only prevents a proper subset of the problems, of which they probably actually know only about a small fraction. It doesn't imply they have a solution or even know about the dizzying variety of other possible problems.
- 2 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.