Live data from Hacker News

Ask HN: Twitter account stolen by presumed vulnerability

news.ycombinator.com

11–20 of 39 posts

Re: Ask HN: Twitter account stolen by presumed vulnerability

#11
Your mobile phone number might have been cloned [1] to impersonate you in two-factor authentication, password reset or other means of accessing your e-mail or twitter account.

This is a serious concern of mine and I'd love for a security expert to chime in and answer how can I prevent this from happening to me other than being insignificant enough that I'm not a worthy target?

[1] https://en.wikipedia.org/wiki/Phone_cloning

Re: Ask HN: Twitter account stolen by presumed vulnerability

#12
I assume that Twitter's security team isn't dumb. But, I wish companies would stop even allowing users to use phone numbers to validate identities -- it's actively less secure than using an email address, and literally everyone on the platform has an email address. There is zero reason for Twitter/Paypal/etc to ever use a phone number to contact me -- email will always be more secure.

Privacy concerns aside, this is one of the primary reasons why I try not to give my phone number to websites I sign up for. I can't trust them not to treat it like an authentication mechanism. OP didn't want to use his phone number as authentication. This was a setting somewhere that got enabled by default, even though for the most part, nobody should ever have it enabled.

Why does this setting exist?

It really feels like a juvenile security mistake to me, and I don't understand the reasoning behind Twitter's security team being OK with it. To me, this seems like a mistake on the same level as using security questions or mandating password expiration. Maybe there's some justification I'm missing, but right now it's difficult for me to imagine what it would be.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#14
I had a similar story on Twitter. I had been using Twitter for a few years. One day I noticed a user with a handle trying to impersonate someone else (handle was close to another handle, with i/l switched). That handle was posting links to a crypto “giveaway” that really was a credential fishing website. I reported those tweets, and posted replies to those tweets to warn people. A few days later Twitter sent me an email that I had been violating the terms and conditions (without any more precise explaination), and had disabled my account. I still don’t know whether it was the scammy handle that somehow managed to get me blocked or whether it was a Twitter algorithm that had incorrectly classified my account. Anyway, the Twitter email contained a link to a procedure to appeal the decision. I appealed the decision, but received another Twitter email a few days later that the decision was final because I had violated the T&C (it was again missing any further explanation). That was the end of the story, and since then I just stopped using Twitter.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#15
post #4

Did you have a phone number associated with your Twitter account? If so call your mobile provider and ask if any changes have been made recently, especially by store employees. If you have two factor set up they most likely removed it and reset your email address using phone verification and intercepted the text message. For everyone else... go check your Google, Github, etc. accounts and make sure you do not have a…

Does anyone know if it's safe to leave a voice-only landline phone number associated to an account? Are these as susceptible to being hijacked as cell numbers?

Re: Ask HN: Twitter account stolen by presumed vulnerability

#16
post #4

Did you have a phone number associated with your Twitter account? If so call your mobile provider and ask if any changes have been made recently, especially by store employees. If you have two factor set up they most likely removed it and reset your email address using phone verification and intercepted the text message. For everyone else... go check your Google, Github, etc. accounts and make sure you do not have a…

Yes I did. I will call my mobile provider to see if any changes were recently made.

I originally didn't suspect a SIM swap attack as I received a text message from one of my contacts around the time the e-mail address was changed. I was out of town of course and did not have my data on. I saw the Twitter e-mail notification the following day. Checking with my mobile provider will be a safe bet for sure.

Thank you for the info.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#17
post #8

I've had my twitter account for 10 years https://twitter.com/mkrn and then one day I decided to follow a few people from an article I've read all at once. Then twitter blocked by account and removed all my followers. Have no ability to DM them either. I filed complaints but no response

I'm sorry to hear about your experience. I hope that you are someday able to get your account back. If that is truly the reason your account was suspended, that just isn't right.

If I make any headway with my case and I am able to forward you contact info I will happily do so.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#18

I had a similar story on Twitter. I had been using Twitter for a few years. One day I noticed a user with a handle trying to impersonate someone else (handle was close to another handle, with i/l switched). That handle was posting links to a crypto “giveaway” that really was a credential fishing website. I reported those tweets, and posted replies to those tweets to warn people. A few days later Twitter sent me an em…

I'm sorry to hear of your experience with Twitter. I really wish they would give you a precise explanation. Many large companies have humans replying to support requests on a regular basis. It would be nice if Twitter would do the same to provide some context. I don't blame you for quitting Twitter after that.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#19
post #7

I enjoyed using Twitter for 9 years with my firstnamelastname account. Then I lost access to the email address and there is no support to help me regain access. I'd even pay them something to verify my identity and account. Oh well i havent used Twitter in years and wont unless I gain access back to my account.

I understand your frustration. I offered to provide my ID to Twitter for verification if it would help. I never heard anything from them in regards to that.

For me, somebody actually tried to extort me with my firstnamelastname account on Twitter. To this day they have it registered still with no tweets.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#20

I assume that Twitter's security team isn't dumb. But, I wish companies would stop even allowing users to use phone numbers to validate identities -- it's actively less secure than using an email address, and literally everyone on the platform has an email address. There is zero reason for Twitter/Paypal/etc to ever use a phone number to contact me -- email will always be more secure. Privacy concerns aside, this is…

You're absolutely right that SMS two-factor authentication isn't secure and that it is the default on Twitter [0].

IIRC at the time I was going to setup two-factor authentication on my device (and to this day), I had an issue with the camera where I could not scan a QR code. On most other platforms I am able to enter in the secret code for my authentication app manually. On Twitter (not sure if this is still true) they did not provide the secret code for me to enter manually.

[0] - https://help.twitter.com/en/managing-your-account/two-factor...

Post reply on HN