Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

41–50 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#41
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

Or do it like Turkey, and require central clearance with physical SIM replacement (this is required both for ownership and porting transfers). One of the few things we got right.

How does this work? You have to send in your old sim before you can receive a new one? What if you lose your old sim?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#42
post #38
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

> “Never transfer my Number” flag what if you actually want to transfer your number?

OP's intent was clear, at least to me: never transfer my number on the phone. Require it to be in person with some stronger form of identification.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#44

I'm not at risk, because I deleted my Twitter account when they started nagging at me to tell them my phone number. Demanding more information from users than the company understandably needs to provide its service, is a huge red flag for me. It's good to know that they're now getting the medial backlash they deserve.

You've missed the point. It's not that his twitter was hacked, it's that an attacker can get control of your phone number.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#45
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

Yes. Of course it works, if it was not possible for you to move your phone number to a different device then you'd be trapped and of course the mobile phone companies would take advantage of that to gouge you.

The problem is your cell provider doesn't have a very good way to be sure it's Svip asking them to do this transfer. They are mostly going to rely on low paid call center or shop floor staff to decide. Fortunately for them this is a low-value transaction. If I get them to transfer Svip's number, I don't cost them very much money and I don't inconvenience you all that much really. Why would I bother...

Unless some idiot decides to rest the authentication scheme for their valuable service on control over a phone number.

In the UK in particular for example the person doing the authentication in an actual store will usually be a teenager working part time for the mobile phone company to get some spending money or during tertiary education. When a hot guy approaches them saying they can make twice their weekly wage if they just "forget" to do a proper ID check for a few friends of his, why wouldn't they say "Yes" ? They might get fired? They have never had a serious job, they're treated like shit, unless they're unusually upright and honest or they think it's a trap they're going to agree.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#46
Any word on whether using Google-Voice would be a good safeguard against this? Presumably, because your google-voice account is so intrinsically linked to your Google account, which is much harder to hack, that should mitigate this threat tremendously. Especially if you're using google-voice to forward all calls to a number that no one else knows about.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#47

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

Passwords don't work these days for sophisticated attacks. Phishing is too easy.

I repeat, they don't work. No 2FA means you'll experience many successful account takeover attacks on your customers. 2FA does not mean you won't, though.

Coinbase had a great talk about account takeover attacks on the recent DefCon. They receive some of the most sophisticated attacks, sometimes when attackers already have control of every other account that the target has. Email, Facebook, Apple Cloud - you name it, now they come for the coins, to cash out.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#48

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

How does adding a second factor of authentication to an already good password make it less secure?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#49

It was not a SIM swap, but a spoofed sender number. You can have whatever as your sender number in SMS, same as with email.

Solving spoofed callerid would help reduce robocalls also. I don't understand why the telcos can't make this happen. If they don't figure this out, we're all going to drop SMS and voice forever; the trend away from SMS has already started and people already have stopped answering all calls they don't know.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#50
post #38
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

> “Never transfer my Number” flag what if you actually want to transfer your number?

Make it a lock like domains. https://www.icann.org/resources/pages/locked-2013-05-03-en
Post reply on HN