Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

1–10 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#3
If we want to authenticate a user, what is the best way to do it?

best: a great balance between convenience, security and cost.

Lately, it bothers that we cannot be sure that we are interacting with real people or the people that we are interacting with are not the same people with different accounts.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#6
post #5
post #4

These places need to stop using SMS for 2FA.

You didn't provide a secure and practical alternative, please enlighten people unaware of them.

Authy / Google Authenticator / 1Password have built-in TOTP generators. They have great UX and are much more secure.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#7
While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed.

The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system like that can never be secure.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#9
Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown.

But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

Post reply on HN