This is a serious concern of mine and I'd love for a security expert to chime in and answer how can I prevent this from happening to me other than being insignificant enough that I'm not a worthy target?
Ask HN: Twitter account stolen by presumed vulnerability
11–20 of 39 posts
Re: Ask HN: Twitter account stolen by presumed vulnerability
#12Privacy concerns aside, this is one of the primary reasons why I try not to give my phone number to websites I sign up for. I can't trust them not to treat it like an authentication mechanism. OP didn't want to use his phone number as authentication. This was a setting somewhere that got enabled by default, even though for the most part, nobody should ever have it enabled.
Why does this setting exist?
It really feels like a juvenile security mistake to me, and I don't understand the reasoning behind Twitter's security team being OK with it. To me, this seems like a mistake on the same level as using security questions or mandating password expiration. Maybe there's some justification I'm missing, but right now it's difficult for me to imagine what it would be.
Re: Ask HN: Twitter account stolen by presumed vulnerability
#13Re: Ask HN: Twitter account stolen by presumed vulnerability
#14Re: Ask HN: Twitter account stolen by presumed vulnerability
#15Did you have a phone number associated with your Twitter account? If so call your mobile provider and ask if any changes have been made recently, especially by store employees. If you have two factor set up they most likely removed it and reset your email address using phone verification and intercepted the text message. For everyone else... go check your Google, Github, etc. accounts and make sure you do not have a…
Re: Ask HN: Twitter account stolen by presumed vulnerability
#16Did you have a phone number associated with your Twitter account? If so call your mobile provider and ask if any changes have been made recently, especially by store employees. If you have two factor set up they most likely removed it and reset your email address using phone verification and intercepted the text message. For everyone else... go check your Google, Github, etc. accounts and make sure you do not have a…
I originally didn't suspect a SIM swap attack as I received a text message from one of my contacts around the time the e-mail address was changed. I was out of town of course and did not have my data on. I saw the Twitter e-mail notification the following day. Checking with my mobile provider will be a safe bet for sure.
Thank you for the info.
Re: Ask HN: Twitter account stolen by presumed vulnerability
#17I've had my twitter account for 10 years https://twitter.com/mkrn and then one day I decided to follow a few people from an article I've read all at once. Then twitter blocked by account and removed all my followers. Have no ability to DM them either. I filed complaints but no response
If I make any headway with my case and I am able to forward you contact info I will happily do so.
Re: Ask HN: Twitter account stolen by presumed vulnerability
#18I had a similar story on Twitter. I had been using Twitter for a few years. One day I noticed a user with a handle trying to impersonate someone else (handle was close to another handle, with i/l switched). That handle was posting links to a crypto “giveaway” that really was a credential fishing website. I reported those tweets, and posted replies to those tweets to warn people. A few days later Twitter sent me an em…
Re: Ask HN: Twitter account stolen by presumed vulnerability
#19I enjoyed using Twitter for 9 years with my firstnamelastname account. Then I lost access to the email address and there is no support to help me regain access. I'd even pay them something to verify my identity and account. Oh well i havent used Twitter in years and wont unless I gain access back to my account.
For me, somebody actually tried to extort me with my firstnamelastname account on Twitter. To this day they have it registered still with no tweets.
Re: Ask HN: Twitter account stolen by presumed vulnerability
#20I assume that Twitter's security team isn't dumb. But, I wish companies would stop even allowing users to use phone numbers to validate identities -- it's actively less secure than using an email address, and literally everyone on the platform has an email address. There is zero reason for Twitter/Paypal/etc to ever use a phone number to contact me -- email will always be more secure. Privacy concerns aside, this is…
IIRC at the time I was going to setup two-factor authentication on my device (and to this day), I had an issue with the camera where I could not scan a QR code. On most other platforms I am able to enter in the secret code for my authentication app manually. On Twitter (not sure if this is still true) they did not provide the secret code for me to enter manually.
[0] - https://help.twitter.com/en/managing-your-account/two-factor...