Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

81–90 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#81

More than myself I am concerned when POTUS is hit. Imagine seeing bunch of tweets showing up at 4am announcing to everyone that USA is in process of launching nukes against Russia right at this moment. By the time the whole thing is explained as a hack-in, Russia may be sending their nukes this way and for a darn good reason, because no country takes nukes threats against them as a joke or "you know perhaps they were…

Surely countries rely on detection systems and spies rather than just believe public messages on the internet?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#82

Earlier quoted context omitted.

I feel like a time delay would help with this too. If it takes an extra 24 hours and you get notifications by SMS and email during that period with the chance to call "fraud" it stops most of these attacks which take control of e-mail and phone simultaneously. I get that makes life much more difficult when you are travelling and have your phone (and therefore SIM) stolen, but given the severity of the current issues…

Porting takes over a week in Russia. You get a new SIM instantly, but it has a temporary number. Then you get notifications via SMS on your old SIM, you usually get a call from your old carrier trying to get you to stay, offering discounts and shit. Then after 7-14 days the new SIM gets the old number and the old SIM stops working. The U.S. system sounds horrifically irresponsible. // Replacement with the same carrie…

Same in Turkey (takes 2-6 days), but you get your replacement SIM after the transfer is cleared, you still use your old carrier and SIM during porting porting. Old one simply gets inoperable by a remote command.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#83
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

Very easy. I have a UK sim with Giffgaff. I lost the original sim and ordered a new one (not linked to me, it was a freebie for distributing to get a referral). I could log into my account, activate the new sim and it was done in about ten minutes.

That's really nice in some respects, but in theory if your account gets hacked, goodbye phone number. There may have been some additional work involved, eg confirm via email, but I believe other networks make it a lot more difficult. Eg you need to request it specifically through customer services and they need actual ID.

My mum is with EE and she had to go to a physical store and prove she was the account holder. Three is similar, you have to request a new sim but in theory if your mobile account is broken then that can be done online (though it never worked when I tried it, the sim didn't arrive).

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#85
post #47

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

Passwords don't work these days for sophisticated attacks. Phishing is too easy. I repeat, they don't work. No 2FA means you'll experience many successful account takeover attacks on your customers. 2FA does not mean you won't, though. Coinbase had a great talk about account takeover attacks on the recent DefCon. They receive some of the most sophisticated attacks, sometimes when attackers already have control of eve…

Phishing, as in entering your password into a field pwnd by a hacker, seems like the problem to solve: how can we avoid giving out our password to a rogue player?

There are simple and complex solutions out there, we should keep taking small steps in the direction of safer password authentication, like how browsers showing the users the certificate validity, or things requiring a secret, individualized secret question so that you know the the host is not phishing.

I agree passwords are far, far from ideal and that 2FA is probably just adding complexity for the hackers, hence making it appear to be a better option, but this is just for the time being. Phone-based 2FA is flawed at the root (of how SIM cards work), so we should keep working on improving password security [1] instead of throwing ourselves into the arms of a flawed phone 2FA.

[1] https://a16z.com/2019/07/25/passwords-are-dead-again/

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#86
post #30

Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID. I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself…

eavesdrop ? the WhatsApp I use agrees to work only on one phone, if yo move it it stops working on the original.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#87

Are SIM-based IoT devices at risk too? Say a connected car?

risk to what ? you can probably clone the SIM (unless your carrier is aware that it's a "special" SIM, probably not) but then what ? you leave the car unconnected and that's it. You can't steal anything from it or the car itself.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#88

Earlier quoted context omitted.

> What if you lose your old sim? I'd say it's pretty simple then: you can't transfer your number and just need to get a new one. I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary. But at some point you have to draw a line - key's lost? Access is lo…

I think this is going too far. It's easy to lose your SIM - in particular, whenever you lose your phone (you left it somewhere, it fell into a river, etc.). Why not just require that if you don't have your old SIM on you, you have to jump through extra hoops involving physically showing government-issued documents and otherwise leaving enough paper trail for the police to find and jail you if it turns out you were a…

The last time I got my SIM reissued (the old one was too big for my new phone), I had the old SIM with me and I still had to show government-issued documents matching the registered SIM owner.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#89
post #52

Earlier quoted context omitted.

Unfortunately the EU regulation mandating 2FA[1] is only just starting to be adopted by the banks, in the UK at least. And they're doing it using SMS codes[2]. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... [2] https://www.nationwide.co.uk/support/security-centre/interne...

2FA has always been a requirement in my country, as far as I remember all the way from the start. The new EU legislation made things worse : one-time pad paper key list isn't accepted any more. My second factor now needs to be my phone (app or SMS).

The written list of one-time passwords (not a "pad" the One Time Pad is a specific crypto design that largely exists to compare things to rather than as a practical gizmo) fails the requirement in 2018/389 because it doesn't end up verifying the specific transaction.

Suppose you have password '47BF-38AP-3M99' on the list. You get a plausible email from your friend Barry saying he needs €40 urgently. You send €40 using that password and instructions Barry gave about some web site for transferring money.

Oops. That wasn't Barry, crooks used Barry's email account to send the message and the €40 transfer turns out to have been a transaction to empty your account of €5830.26 but '47BF-38AP-3M99' was correct so the bank OK'd it.

The regulation aims to arrange that the second factor involves the transaction value 5830.26 which is weird for you because you are trying to send Barry €40. You would probably realise something is wrong when typing 5830.26 into an authenticator, or else, the crooks only get €40 which is a bad pay-off for such a sophisticated attack.

My good bank gave me a weird chiclet keypad device years ago that I have to type stuff into while doing online transactions. So I'd have to type the amount into that device. It whitelists certain actions, so if I keep sending Barry money, I think I don't have to type the amount in every time or something.

The EU rules definitely don't forbid your bank doing something better here, but I can see that the way that bank chose to implement them hasn't helped you which sucks.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#90
post #73

Disappointed they didn’t do something like use it to manipulate the stock market. Then it would have got much more coverage and something might actually get fixed as a result.

"I'm pleased to announce that Twitter is becoming a part of the Alphabet family for $X", where $X is a bit more or less than the current value.

"Am considering taking Twitter private at $420. Funding secured."

Just a single tweet from Musk, caused a big wave in the value of Tesla + a serious bollocking from the SEC.

Post reply on HN