Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

91–100 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#91

Isn't texting usually used in 2-factor-authentification? What was the other factor? I thought the whole idea behind 2-factor-auth is that two somewhat secure authentification methods combined make a stronger one.

Isn't texting usually used in 2-factor-authentification?

Unfortunately it is also used far too often as 1-factor authentication for password resets, making 2-factor authentication essentially pointless.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#94
Have Twitter stated that this is how the hack was accomplished? When I first read that SMS was used I assumed someone had just spoofed the phone number. My assumption was that the Twitter account has a verified phone number and that any SMS sent to the SMS->Tweet service would be published as long as the senderid was the same as the account phone number. That there was need to begin the SMS with a secret code/password to authenticate each SMS. And that is why the shut down the whole service because anyone can just spoof the senderid in a SMS.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#95
post #53
post #48

Earlier quoted context omitted.

How does adding a second factor of authentication to an already good password make it less secure?

because they let you use the phone number to reset the password

Which effectively reduces it back to 1-factor authentication. There's an adage somewhere that is probably worded better but which boils down to your security is only as good as your weakest link.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#96
post #50

Earlier quoted context omitted.

Make it a lock like domains. https://www.icann.org/resources/pages/locked-2013-05-03-en

This seems like the best solution. Introduce an opt-in security feature, whereby any attempt to port the number, or swap sims, is subject to a ~72h cooldown period. During that period, notify the account holder through numerous communication channels of the pending change. Email, SMS, automated phone call.

Yup. Authy does a good job of this if you need to reset your access. They (automatically) harass the shit out of you for 24h before doing it. I think I got 10+ calls/texts plus emails.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#97
post #3

If we want to authenticate a user, what is the best way to do it? best: a great balance between convenience, security and cost. Lately, it bothers that we cannot be sure that we are interacting with real people or the people that we are interacting with are not the same people with different accounts.

Authenticate a user as _what_ / _who_ ? That's the most important question you need to figure out the answer to before setting off on this journey.

If I "authenticate" a $1 postcard of the Mona Lisa, does that mean it's the real Mona Lisa? A real postcard? Really worth a dollar? Really a physical object that exists?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#99
post #64
post #23

Earlier quoted context omitted.

In Poland it is also used, I heard stories (e.g. https://niebezpiecznik.pl/tag/sim-swap-fraud/ polish website) about sim card swapping and stealing funds from bank accounts. After reading those I switched authentication from a sms text to my bank app.

Unfortunately, the current corporate thinking in Poland is that 2-factor authentication means SMS. I see banks and other companies introduce this in spite of known vulnerabilities. SMS is NOT a secure second factor!

What's the universally accepted alternative?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#100
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

The problem is when a phone number is the only factor that is used. That is what Twitter allows.

If you truly use an SMS only as a second factor - and don't provide recovery options only by phone, like Twitter - then you have much less of a problem. In that case, a compromised phone number does not give the attacker the password or other factor. SMS is still extremely imperfect for 2FA, but it's still a lot better than no 2FA [1].

[1]:https://security.googleblog.com/2019/08/understanding-why-ph...

Post reply on HN