Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

151–160 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#151

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

If you have an Apple device logged in to the account then Apple uses its own push notification infrastructure instead of SMS. Apple calls it “Trusted Devices”:

https://support.apple.com/en-us/HT204915

Also, SMS is always in-addition to your password. If you forget your password and you don’t have a trusted device from which to reset it, then Apple uses a recovery procedure which requires more than just SMS for verification.

You can also enable a recovery key which will then prevent SMS from being used to reset your password. With a recovery key you need to either use a trusted device or the key to reset your password.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#152
What is amazing to me is that after this attack has been successfully mounted against the CEO of the company he still has not announced "I have directed our engineering to implement a non SMS-based 2FA. They have been provided all the necessary resources and authorizations. It will become available for all users on a platform in no more than 30 days."

Imagine if it was Amazon and Bezos' account got hacked because the company did not implement proper security. Plugging that hole properly would become not a priority one but a priority before priority one project.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#153
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

T-Mobile lets you set a PIN that you have to present if you want to port your number or get a new SIM. They sent out mass texts about it a couple of years ago.

The problem is that it is not enforced by the automated system. Instead it is enforced by sales people who have ability to override the system, including people like the blue shirts at Best Buy. Yes, they are not supposed to, but they can.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#154

Earlier quoted context omitted.

There is no universally accepted second factor. * SMS (and automated voice call) are bad for people who live in areas with poor phone coverage, people with international phone numbers, and people who want good security. * TOTP is bad for people who don't have smartphones. * FIDO U2F is bad for people who don't have $20, safari/iOS users, and people whose devices don't have USB. * Vendor-specific apps are bad for peop…

> TOTP is bad for people who don't have smartphones. This only true if you're willing to define everything beyond the most mundane "dumb phone" as a "smartphone". One of my friends has a long list of exciting problems which ends up meaning he doesn't own what anyone these days would consider a smartphone. But it's not like he uses carrier pigeons. His phone does have a (monochrome) screen and is quite capable of runn…

You're correct: You could TOTP from a java phone app, a tablet, an airgapped computer, a non-airgapped PC you were really confident of the security of, and so on.

That's why I said "bad for" rather than "impossible for" :)

After all, you'd still be excluding all the people who don't have any of those. Like my 90-year-old neighbour who only has a landline phone.

I've helped maybe 50 employees set up VPN access at my workplace, and at least 2 of them said they didn't have any way to TOTP independently of the laptop we were issuing them with.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#155
post #99

Earlier quoted context omitted.

What's the universally accepted alternative?

There is no universally accepted second factor. * SMS (and automated voice call) are bad for people who live in areas with poor phone coverage, people with international phone numbers, and people who want good security. * TOTP is bad for people who don't have smartphones. * FIDO U2F is bad for people who don't have $20, safari/iOS users, and people whose devices don't have USB. * Vendor-specific apps are bad for peop…

> * SMS (and automated voice call) are bad for [...] people with international phone numbers

Why is that? I'm maybe spoiled by my surroundings (Poland and Europe in general), but receiveing SMS text is free abroad. While using dataplan generally is not, so SMS is cheaper (free) as a second factor if you travel a lot.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#156
I think it's pretty bad that the phone companies facilitate this attack. I wonder if they have any kind of legal liability for their negligence? Maybe all that's needed to stop these attacks is for people to start suing them for the damages incurred upon being SIM-swapped? It should not be easy to steal someone's phone number.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#157
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

hugely important point.

helped a less-tech-savvy neighbor 'reset her skype' account that was tied to 'her phone number', only to find that the account bound to that phone number, which she had recently acquired, was publically searchable and connected with some sort of anime sex fetish subculture, presumably from a previous owner of that phone number..

she was using this phone / skype account for a job interview.

needless to say, a searchable skype account connected to her phone number with such a public profile could have had a hugely negative impact on her job search, and she wasn't even aware of it's existence until she happened to stumble upon it..

not good.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#158
I’m hope Google Voice on a dedicated Google Account makes this relatively harder for crooks to pull-off. In theory it should require a porting attack and in theory since you can lock your number on the Google side you should at least get notified by Google first about any porting attempt.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#159
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

It's really ½FA, worse than 1FA authentication because it's sufficient to clear any 1 of the 2 factors.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#160
Not a security expert by any means and it'd actually be nice to get some feedback on this. I have a Gmail account protected with a hardware token and no additional 2FA mechanisms. I created a google voice # that forwards any text or voice messages to this email. The number is locked and cannot be transferred without having physical access to the google account. If I need to setup 2FA, I use the google voice #. The 2FA token is received via my secured Gmail. Any kind of social engineering attempts would have to go through Google support instead of telco. Is something like this worth pursuing?
Post reply on HN