Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

71–80 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#71
post #41

Earlier quoted context omitted.

How does this work? You have to send in your old sim before you can receive a new one? What if you lose your old sim?

> What if you lose your old sim? I'd say it's pretty simple then: you can't transfer your number and just need to get a new one. I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary. But at some point you have to draw a line - key's lost? Access is lo…

That kinda ruins the main utility of the system for most people. People aren't switching service providers often or SIM sizes at all these days (the latter especially with larger SIMs just being the same nanoSIM but with an adapter of sorts around it).

For the average person, the best utility of it is being able to retain your number on losing your device. Usually you aren't expecting to lose your device, so imagine how much more complicated everything gets when not only do you have to worry about getting a new one unexpectedly, but then also have to get a new number, inform everyone you know about that, and then update all your accounts.

All of that just to protect people from being targeted by fraud that is not only very unlikely to happen to them unless they're well known, but is also better resolved by making authentication systems smarter.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#72
post #58

Earlier quoted context omitted.

Yes. Of course it works, if it was not possible for you to move your phone number to a different device then you'd be trapped and of course the mobile phone companies would take advantage of that to gouge you. The problem is your cell provider doesn't have a very good way to be sure it's Svip asking them to do this transfer. They are mostly going to rely on low paid call center or shop floor staff to decide. Fortunat…

There are still ways to make the system more secure. For example, you have to physically go to a store to port the number unless you have the old SIM. Then it's not done immediately - there's a 72 hour period in which multiple texts and calls are sent to the old SIM asking for confirmation. If you physically have the old SIM this is instant, but if you claim to have lost it you need to wait 72 hours and provide a sig…

Sure, you could have a national "reality" TV show, everybody who lost their SIM has to go on the TV show for six months with it showing on screen which number they claim is theirs - so this way there's no chance they're a crook.

Or make anyone who claims they lost their SIM wrestle a bear first before they get a replacement. Won't see many crooks take that on.

But, I put it to you that this all seems very disproportionate when you remember that you're punishing the phone company and its customers for not securing Twitter. These are the wrong people!

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#73

Disappointed they didn’t do something like use it to manipulate the stock market. Then it would have got much more coverage and something might actually get fixed as a result.

"I'm pleased to announce that Twitter is becoming a part of the Alphabet family for $X", where $X is a bit more or less than the current value.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#74
More than myself I am concerned when POTUS is hit. Imagine seeing bunch of tweets showing up at 4am announcing to everyone that USA is in process of launching nukes against Russia right at this moment. By the time the whole thing is explained as a hack-in, Russia may be sending their nukes this way and for a darn good reason, because no country takes nukes threats against them as a joke or "you know perhaps they were hacked so let's go sleep". This is more serious than my little 15,000 followers twitter handle.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#75

I'm not at risk, because I deleted my Twitter account when they started nagging at me to tell them my phone number. Demanding more information from users than the company understandably needs to provide its service, is a huge red flag for me. It's good to know that they're now getting the medial backlash they deserve.

You've missed the point. It's not that his twitter was hacked, it's that an attacker can get control of your phone number.

I'm well aware of that and don't use my phone number for security-related tasks when I can. My operator or the authorities (with IMSI-catchers, also available to criminals) could gain control of it at any time after all.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#76
post #5
post #4

These places need to stop using SMS for 2FA.

You didn't provide a secure and practical alternative, please enlighten people unaware of them.

My bank uses an app, Symantec VIP, to generate a 6 digit code.

This works on vacation when I can't receive SMS. It was much cheaper to buy a 4G SIM in Barcelona (for Google Maps etc) than enable international roaming from Australia ($AU5/day).

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#77

Earlier quoted context omitted.

Or do it like Turkey, and require central clearance with physical SIM replacement (this is required both for ownership and porting transfers). One of the few things we got right.

I feel like a time delay would help with this too. If it takes an extra 24 hours and you get notifications by SMS and email during that period with the chance to call "fraud" it stops most of these attacks which take control of e-mail and phone simultaneously. I get that makes life much more difficult when you are travelling and have your phone (and therefore SIM) stolen, but given the severity of the current issues…

Porting takes over a week in Russia.

You get a new SIM instantly, but it has a temporary number. Then you get notifications via SMS on your old SIM, you usually get a call from your old carrier trying to get you to stay, offering discounts and shit. Then after 7-14 days the new SIM gets the old number and the old SIM stops working.

The U.S. system sounds horrifically irresponsible.

// Replacement with the same carrier is quick, but requires physical presence with government ID (passport)

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#78
post #38
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

> “Never transfer my Number” flag what if you actually want to transfer your number?

The Swedish solution for physical address change (yes, we all must be registered at an address which is then used for everything formal) is to lock it using Mobile Bank ID

> BankID is a citizen identification solution that allows companies, banks and governments agencies to authenticate and conclude agreements with individuals over the Internet.

You need your phone to use it but it can be recovered using other means like ID card or a digipass from you bank

https://www.adressandring.se/private/watch

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#79
post #50
post #38

Earlier quoted context omitted.

> “Never transfer my Number” flag what if you actually want to transfer your number?

Make it a lock like domains. https://www.icann.org/resources/pages/locked-2013-05-03-en

This seems like the best solution. Introduce an opt-in security feature, whereby any attempt to port the number, or swap sims, is subject to a ~72h cooldown period. During that period, notify the account holder through numerous communication channels of the pending change.

Email, SMS, automated phone call.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#80

Disappointed they didn’t do something like use it to manipulate the stock market. Then it would have got much more coverage and something might actually get fixed as a result.

I couldn't agree more. Sadly, only this kind of thing will prompt the government to crack down on the telecommunication companies.

Who are more than negligent here.

Post reply on HN