Live data from Hacker News

Ask HN: Twitter account stolen by presumed vulnerability

news.ycombinator.com

21–30 of 39 posts

Re: Ask HN: Twitter account stolen by presumed vulnerability

#21
post #11

Your mobile phone number might have been cloned [1] to impersonate you in two-factor authentication, password reset or other means of accessing your e-mail or twitter account. This is a serious concern of mine and I'd love for a security expert to chime in and answer how can I prevent this from happening to me other than being insignificant enough that I'm not a worthy target? [1] https://en.wikipedia.org/wiki/Phone_…

The common advice is to have a second phone number that isn't public if you have to use SMS as a 2nd factor. Like a Google voice number (assuming that's still around) or other virtual account.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#22

These big tech companies are unaccountable to anyone except shareholders (and even then, not always). Your only hope is having a friend in the company, which is a ridiculous way of solving problems. Given a bad situation, the best solution is to just stop using Twitter. A week without it and you won't miss it.

I fear you are correct regarding the accountability unfortunately.

For me, I wasn't active on Twitter as far as tweeting [0] but I was actively reading what my connections were posting.

I've already come to the conclusion that if I don't get my account back I will not be using Twitter for personal use.

[0] - https://web.archive.org/web/20190428220642/https://twitter.c....

Re: Ask HN: Twitter account stolen by presumed vulnerability

#24
post #3

Twitter doesn't care. This time it seems you were hacked, but Twitter themselves routinely decide to give your handle to someone else.

Yeah. If this happened to me, I would just completely withdraw from Twitter. Byeeee. :) I actually prefer rss for news and irc for chat.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#25
post #4

Did you have a phone number associated with your Twitter account? If so call your mobile provider and ask if any changes have been made recently, especially by store employees. If you have two factor set up they most likely removed it and reset your email address using phone verification and intercepted the text message. For everyone else... go check your Google, Github, etc. accounts and make sure you do not have a…

Does anyone know if it's safe to leave a voice-only landline phone number associated to an account? Are these as susceptible to being hijacked as cell numbers?

Landline numbers are still vulnerable, it just isn't as common of an attack.

You can go to specific forums and pay $10-15 for a change to be made to a cellular account, usually by rouge employees or hacked point of sale terminals. A landline requires you to get some additional details like the account number, photoshop a bill, and submit that to port the number to somewhere that you control.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#26
post #4

Did you have a phone number associated with your Twitter account? If so call your mobile provider and ask if any changes have been made recently, especially by store employees. If you have two factor set up they most likely removed it and reset your email address using phone verification and intercepted the text message. For everyone else... go check your Google, Github, etc. accounts and make sure you do not have a…

Yes I did. I will call my mobile provider to see if any changes were recently made. I originally didn't suspect a SIM swap attack as I received a text message from one of my contacts around the time the e-mail address was changed. I was out of town of course and did not have my data on. I saw the Twitter e-mail notification the following day. Checking with my mobile provider will be a safe bet for sure. Thank you for…

I thought about this a bit further. Wouldn't the join date of May 2019 on the account [0] signify that the user may not have actually reset my password/e-mail address but rather created a new account?

Ether way, I am still going to contact my mobile provider to be sure.

[0] - https://twitter.com/scott

Re: Ask HN: Twitter account stolen by presumed vulnerability

#27
post #25

Earlier quoted context omitted.

Does anyone know if it's safe to leave a voice-only landline phone number associated to an account? Are these as susceptible to being hijacked as cell numbers?

Landline numbers are still vulnerable, it just isn't as common of an attack. You can go to specific forums and pay $10-15 for a change to be made to a cellular account, usually by rouge employees or hacked point of sale terminals. A landline requires you to get some additional details like the account number, photoshop a bill, and submit that to port the number to somewhere that you control.

Interesting...thanks!

Re: Ask HN: Twitter account stolen by presumed vulnerability

#28

I assume that Twitter's security team isn't dumb. But, I wish companies would stop even allowing users to use phone numbers to validate identities -- it's actively less secure than using an email address, and literally everyone on the platform has an email address. There is zero reason for Twitter/Paypal/etc to ever use a phone number to contact me -- email will always be more secure. Privacy concerns aside, this is…

> literally everyone on the platform has an email address.

This may be true in nations that have had ubiquitous internet access, but in many quickly-growing markets this is not true.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#29
post #28

I assume that Twitter's security team isn't dumb. But, I wish companies would stop even allowing users to use phone numbers to validate identities -- it's actively less secure than using an email address, and literally everyone on the platform has an email address. There is zero reason for Twitter/Paypal/etc to ever use a phone number to contact me -- email will always be more secure. Privacy concerns aside, this is…

> literally everyone on the platform has an email address. This may be true in nations that have had ubiquitous internet access, but in many quickly-growing markets this is not true.

I was referring specifically to Twitter -- it's been a while since I checked, but doesn't Twitter require an email address for every account on signup?

If you're offering a service that doesn't rely on email, I do see a gray area there for using SMS as a fallback; but most services I use don't fall into that category. I've even seen banks go down this direction -- banks that both require me to have an email to make an online account, and that are only operating within the US.

Lyft in particular weirds me out, because (third-party services excluded) Lyft only works via an app and a web interface. And yet there's no option to sign into the Lyft website using anything other than SMS. I'm required to use an insecure SMS login even though I literally can't request a Lyft ride without an Internet connected device.

I understand having options for developing nations, I don't understand using those options as a default, or even going so far as requiring users to leave them open.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#30
post #28

Earlier quoted context omitted.

> literally everyone on the platform has an email address. This may be true in nations that have had ubiquitous internet access, but in many quickly-growing markets this is not true.

I was referring specifically to Twitter -- it's been a while since I checked, but doesn't Twitter require an email address for every account on signup? If you're offering a service that doesn't rely on email, I do see a gray area there for using SMS as a fallback; but most services I use don't fall into that category. I've even seen banks go down this direction -- banks that both require me to have an email to make a…

> I was referring specifically to Twitter -- it's been a while since I checked, but doesn't Twitter require an email address for every account on signup?

I see, I misunderstood. it does not require an email address on signup, they’ve been pushing more and more aggressively to force new accounts to have numbers tied to them in fact[1]. https://mobile.twitter.com/i/flow/signup in a private browser tab in fact defaults to phone number and the email flow is deprioritised.

I agree that it should never be required, much less the only factor. Nothing good can come of it but these companies get to lean on Trust and Safety as an excuse to collate this information for nonconsensual purposes.

[1] https://www.reddit.com/r/privacy/comments/8e5m73/twitter_is_... and some other stuff that I’m too tired to search hn for

Post reply on HN