Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

51–60 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#51
post #36
post #30

Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID. I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself…

AFAIK there is a feature in WhatsApp Settings that tells you whenever a contact in an ongoing conversation changes their device. So no protection, but a notification. https://faq.whatsapp.com/en/android/28030014/?category=52452...

You can (should?) protect the verification step with a pin:

https://faq.whatsapp.com/general/26000021/?category=5245245

You can do the same in Signal.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#52
post #4

These places need to stop using SMS for 2FA.

Unfortunately the EU regulation mandating 2FA[1] is only just starting to be adopted by the banks, in the UK at least. And they're doing it using SMS codes[2].

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... [2] https://www.nationwide.co.uk/support/security-centre/interne...

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#53
post #48

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

How does adding a second factor of authentication to an already good password make it less secure?

because they let you use the phone number to reset the password

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#54
post #6
post #5

Earlier quoted context omitted.

You didn't provide a secure and practical alternative, please enlighten people unaware of them.

Authy / Google Authenticator / 1Password have built-in TOTP generators. They have great UX and are much more secure.

Don't save your TOTP codes in your password manager if you are going for the "best" security.

That turns multi-factor auth back into "single factor auth" and leaves you one exploit away from having your password and TOTP code from getting stolen.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#55
post #41

Earlier quoted context omitted.

Or do it like Turkey, and require central clearance with physical SIM replacement (this is required both for ownership and porting transfers). One of the few things we got right.

How does this work? You have to send in your old sim before you can receive a new one? What if you lose your old sim?

> What if you lose your old sim?

I'd say it's pretty simple then: you can't transfer your number and just need to get a new one.

I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary.

But at some point you have to draw a line - key's lost? Access is lost.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#56
post #32
post #29

Earlier quoted context omitted.

This was a problem before Twitter allowed 2FA via SMS, so I'd argue this is very much a Twitter problem. Afaict this all stems from mixing verification with authentication, where verification may be required when creating an account and authentication (and possibly more verification) when using the account.

And even more simply, verifying the user is a "real person" in contrast to verifying the user is the "right person".

How does that help? Surely the attacker is a real person too.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#58
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

Yes. Of course it works, if it was not possible for you to move your phone number to a different device then you'd be trapped and of course the mobile phone companies would take advantage of that to gouge you. The problem is your cell provider doesn't have a very good way to be sure it's Svip asking them to do this transfer. They are mostly going to rely on low paid call center or shop floor staff to decide. Fortunat…

There are still ways to make the system more secure.

For example, you have to physically go to a store to port the number unless you have the old SIM.

Then it's not done immediately - there's a 72 hour period in which multiple texts and calls are sent to the old SIM asking for confirmation. If you physically have the old SIM this is instant, but if you claim to have lost it you need to wait 72 hours and provide a signature and mugshot at the store.

If a member of staff "forgets" to do this stuff, they go to jail.

People don't usually lose their SIM card, so this process wouldn't happen very often.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#59
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

Or do it like Turkey, and require central clearance with physical SIM replacement (this is required both for ownership and porting transfers). One of the few things we got right.

I feel like a time delay would help with this too. If it takes an extra 24 hours and you get notifications by SMS and email during that period with the chance to call "fraud" it stops most of these attacks which take control of e-mail and phone simultaneously.

I get that makes life much more difficult when you are travelling and have your phone (and therefore SIM) stolen, but given the severity of the current issues it seems minimal disruption. You get a burner phone for 24 hours?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#60
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

Yes. Of course it works, if it was not possible for you to move your phone number to a different device then you'd be trapped and of course the mobile phone companies would take advantage of that to gouge you. The problem is your cell provider doesn't have a very good way to be sure it's Svip asking them to do this transfer. They are mostly going to rely on low paid call center or shop floor staff to decide. Fortunat…

To be more specific, I live in Denmark. Last time I had to transfer my number, it was quite a hassle. I had to show up physically in a store, and they needed to scan two ID cards of mine. In addition, because I have a legally hidden address, the guy in the store needed to contact someone inside to confirm me. Essentially, he was not able to do it on his own.

In fairness, that was me moving from one carrier to another. I assume, if I were to get a new SIM with the same carrier, it would be a lot easier. I have been trying to figure out what it would require for me to change SIM within the carrier, but their help articles aren't clear on this, besides mentioning it is possible (my impression is that they will ship the SIM card by postal services).

Post reply on HN