Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

61–70 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#61
post #6

Earlier quoted context omitted.

Authy / Google Authenticator / 1Password have built-in TOTP generators. They have great UX and are much more secure.

Don't save your TOTP codes in your password manager if you are going for the "best" security. That turns multi-factor auth back into "single factor auth" and leaves you one exploit away from having your password and TOTP code from getting stolen.

How could one save a TOTP code in a password manager and use it later? It would be useless in 30 seconds time.

Am I misunderstanding something? Or did you mean OTP rather than TOTP?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#62
post #41

Earlier quoted context omitted.

How does this work? You have to send in your old sim before you can receive a new one? What if you lose your old sim?

> What if you lose your old sim? I'd say it's pretty simple then: you can't transfer your number and just need to get a new one. I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary. But at some point you have to draw a line - key's lost? Access is lo…

I think this is going too far. It's easy to lose your SIM - in particular, whenever you lose your phone (you left it somewhere, it fell into a river, etc.).

Why not just require that if you don't have your old SIM on you, you have to jump through extra hoops involving physically showing government-issued documents and otherwise leaving enough paper trail for the police to find and jail you if it turns out you were a fraud?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#63
> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T

Those seem like excellent litigation targets, and I’m surprised that that fact alone hasn’t fixed this bug. Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#64
post #23
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

In Poland it is also used, I heard stories (e.g. https://niebezpiecznik.pl/tag/sim-swap-fraud/ polish website) about sim card swapping and stealing funds from bank accounts. After reading those I switched authentication from a sms text to my bank app.

Unfortunately, the current corporate thinking in Poland is that 2-factor authentication means SMS. I see banks and other companies introduce this in spite of known vulnerabilities.

SMS is NOT a secure second factor!

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#65
post #52
post #4

These places need to stop using SMS for 2FA.

Unfortunately the EU regulation mandating 2FA[1] is only just starting to be adopted by the banks, in the UK at least. And they're doing it using SMS codes[2]. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... [2] https://www.nationwide.co.uk/support/security-centre/interne...

2FA has always been a requirement in my country, as far as I remember all the way from the start. The new EU legislation made things worse: one-time pad paper key list isn't accepted any more. My second factor now needs to be my phone (app or SMS).

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#66
post #61

Earlier quoted context omitted.

Don't save your TOTP codes in your password manager if you are going for the "best" security. That turns multi-factor auth back into "single factor auth" and leaves you one exploit away from having your password and TOTP code from getting stolen.

How could one save a TOTP code in a password manager and use it later? It would be useless in 30 seconds time. Am I misunderstanding something? Or did you mean OTP rather than TOTP?

The setup string which generates the time codes is basically a second password. If something can read that setup string, they can generate their own TOTP codes for your account whenever they want.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#67

Earlier quoted context omitted.

> What if you lose your old sim? I'd say it's pretty simple then: you can't transfer your number and just need to get a new one. I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary. But at some point you have to draw a line - key's lost? Access is lo…

I think this is going too far. It's easy to lose your SIM - in particular, whenever you lose your phone (you left it somewhere, it fell into a river, etc.). Why not just require that if you don't have your old SIM on you, you have to jump through extra hoops involving physically showing government-issued documents and otherwise leaving enough paper trail for the police to find and jail you if it turns out you were a…

> Why not

Maybe the laws don’t consider that a serious enough crime to even investigate the cases?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#68

Isn't texting usually used in 2-factor-authentification? What was the other factor? I thought the whole idea behind 2-factor-auth is that two somewhat secure authentification methods combined make a stronger one.

IMO the idea behind 2-factor is that an attacker requires physical access to a physical object. Which reduces the number potential attackers to the small number that are able and willing to finance a targeted theft.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#69
post #46

Any word on whether using Google-Voice would be a good safeguard against this? Presumably, because your google-voice account is so intrinsically linked to your Google account, which is much harder to hack, that should mitigate this threat tremendously. Especially if you're using google-voice to forward all calls to a number that no one else knows about.

I would not use Google voice. I'm not sure, but I doubt Google controls the major component in the international mechanism responsible for routing telephone calls. I would expect that they outsource some of the mechanisms to 3rd parties.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#70
post #41

Earlier quoted context omitted.

How does this work? You have to send in your old sim before you can receive a new one? What if you lose your old sim?

> What if you lose your old sim? I'd say it's pretty simple then: you can't transfer your number and just need to get a new one. I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary. But at some point you have to draw a line - key's lost? Access is lo…

We keep keys safe at home in the closet or under the mattress. We take our phones everywhere. Such a policy would be a usability nightmare.

Even if someone's phone is locked and useless, you could steal it, dispose of it, and cause a lot of grief.

Post reply on HN