Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

21–30 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#21

This is mobile operator problem, not Twitter. How on earth the mobile operator can hand a SIM card to someone else?!

Because people get new sims and legitimately transfer their numbers _all the time_.

I'm not saying they shouldn't put more effort into verifying the transfer, I'm just explaining why its quick and easy and they don't invest in checking much.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#23
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

In Poland it is also used, I heard stories (e.g. https://niebezpiecznik.pl/tag/sim-swap-fraud/ polish website) about sim card swapping and stealing funds from bank accounts.

After reading those I switched authentication from a sms text to my bank app.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#24
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

Or do it like Turkey, and require central clearance with physical SIM replacement (this is required both for ownership and porting transfers). One of the few things we got right.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#26

Well, MAYBE, just maybe Twitter should stop require new users to enter their phone number in order to validate their account.

I assume companies don’t give the option for TOTP and require phone numbers to identify their users to collect more precise data about them, for possible advertising revenue.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#29

This is mobile operator problem, not Twitter. How on earth the mobile operator can hand a SIM card to someone else?!

This was a problem before Twitter allowed 2FA via SMS, so I'd argue this is very much a Twitter problem.

Afaict this all stems from mixing verification with authentication, where verification may be required when creating an account and authentication (and possibly more verification) when using the account.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#30
Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID.

I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself out of my own Gmail account. I guess apps like Authy as mentioned in the other comments are an alternative. In any case I guess there are (or should be) some special codes you can write down in case you lose access to your second-factor info.

Post reply on HN