Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

31–40 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#31
I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it.

I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2FA and... my phone number.

Apparently 2FA for Apple ids cannot be rolled back! Now everytime I want to upgrade something in my Macbook I have to get an SMS code on my (vulnerable) phone to access my Apple account. This is a very unfortunate decision by Apple.

Like I said I'm a big fan of passwords. Just give me 2 or 3 passwords or passphrases (or secret patterns) as backup for my main password. Require them to be long and complex. Something that is inside my brain and only Leonardo di Caprio can steal. Not my dad's middle name or pet name or school teacher's name. I'm not a security expert, but I still feel that's the most secure way to protect an account.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#32
post #29

This is mobile operator problem, not Twitter. How on earth the mobile operator can hand a SIM card to someone else?!

This was a problem before Twitter allowed 2FA via SMS, so I'd argue this is very much a Twitter problem. Afaict this all stems from mixing verification with authentication, where verification may be required when creating an account and authentication (and possibly more verification) when using the account.

And even more simply, verifying the user is a "real person" in contrast to verifying the user is the "right person".

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#34
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

There's a scandal being reported by Glenn Greenwald in Brazil, which is centered around the minister of Justice and his actions as a judge in the Lava Jato operation that led to Lula (ex president) being arrested. He helped prosecutors by coordinating strategies with them. These conversations took place on telegram and were stolen using sim swap.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#36
post #30

Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID. I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself…

AFAIK there is a feature in WhatsApp Settings that tells you whenever a contact in an ongoing conversation changes their device.

So no protection, but a notification.

https://faq.whatsapp.com/en/android/28030014/?category=52452...

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#38
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

> “Never transfer my Number” flag

what if you actually want to transfer your number?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#39

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

If you type in the same passwords every time that's already a possible security breach. Single use 2FA is good because it you need one separate code for each transaction.

SIMs and phones being vulnerable is different from 2FA not working.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#40
I'm not at risk, because I deleted my Twitter account when they started nagging at me to tell them my phone number. Demanding more information from users than the company understandably needs to provide its service, is a huge red flag for me. It's good to know that they're now getting the medial backlash they deserve.
Post reply on HN