Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

161–170 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#162

https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo... NIST has said that 2FA via SMS is bad and awful for at least 3 years now. Can we knock it off, already? This won’t stop SIM swaps, but it will blunt their impact by rather a lot.

That’s the problem. Twitter requires you to add a phone number (even if you sign up without one, eventually you’ll be locked out and requires to add one). Then, once you add a number to unlock your account you’re left exposed.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#163
post #8

How does this work? The sim-card is sent to your own address, in a plain white envelope.They have to steal that envelope to gain physical access to the sim. Why is it so hard to stop sending sim-cards to different addresses than the main address where it was registered?

It's much simpler. The attackers simply go to the service provider, claim they lost the sim card/phone and provide your details. If they're convincing enough the provider will deactivate your SIM and activate theirs within 10 minutes or so and by the time you notice your mobile connection doesn't work anymore they're already busy entering TANs sent to your number. Now I don't know how easy that is to pull off in the…

It seems to me like there needs to be far more security in place before a SIM card can be swapped out over the phone. You should need to state your SSN, answer a few security questions and maybe let them know how much you paid on your last three bills or something like that.

That doesn't mitigate the risk of bribery but if you have the right software in place for the person on the line at T-Mobile or AT&T then they wouldn't be able to proceed without the proper verification.

Seems like a pretty big but easy to solve problem to me.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#164
post #155

Earlier quoted context omitted.

There is no universally accepted second factor. * SMS (and automated voice call) are bad for people who live in areas with poor phone coverage, people with international phone numbers, and people who want good security. * TOTP is bad for people who don't have smartphones. * FIDO U2F is bad for people who don't have $20, safari/iOS users, and people whose devices don't have USB. * Vendor-specific apps are bad for peop…

> * SMS (and automated voice call) are bad for [...] people with international phone numbers Why is that? I'm maybe spoiled by my surroundings (Poland and Europe in general), but receiveing SMS text is free abroad. While using dataplan generally is not, so SMS is cheaper (free) as a second factor if you travel a lot.

Depending on where the customer is roaming from and to, they might risk a per-SMS charge, suffer unreliability, get no signal, or even turn off their phone to avoid accidentally running up a big roaming bill.

When I went from the UK to Montreal, I tried to use local Uber competitor "Teo Taxi" but was unable to as their number-confirmation SMS didn't arrive.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#165

> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T Those seem like excellent litigation targets, and I’m surprised that that fact alone hasn’t fixed this bug. Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.

> Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.

If you are a captain of a ship that sees an out of control oil tanker heading for it, the solution is not to sue the oil tanker owners, rather it is to get out of its way which in Jack's case should be ordering an immediate implementation of a non-SMS 2FA

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#166

Earlier quoted context omitted.

The written list of one-time passwords (not a "pad" the One Time Pad is a specific crypto design that largely exists to compare things to rather than as a practical gizmo) fails the requirement in 2018/389 because it doesn't end up verifying the specific transaction. Suppose you have password '47BF-38AP-3M99' on the list. You get a plausible email from your friend Barry saying he needs €40 urgently. You send €40 usin…

Any idea what the keypad device is called? Are you expected to carry it with you at all times? Is that feasible? Is there some sort of threshold for its use? For example, transactions under $X, even if fraudulent, might not be worth the inconvenience to the customer of having to go through the extra steps. If you don’t mind my asking, is your banking institution geared towards HNW clients? The amount verification sou…

The device claims to be a "Vasco DigiPass". It has lots of other identifying marks but those might be secret (even if they weren't supposed to be, disclosing them might inadvertently reveal a secret)

I am not required to carry it, but my understanding is that most features of my online banking don't work if I tell the system I don't have it with me. I store it with other valuable identity items like my birth certificate in my home, I do not take it with me when I travel.

This bank offers excellent 24/7 phone service, if I was away from home I would call them if I needed anything. All conceivable transactions can be concluded by phone, indeed I've mentioned to HN before that it turns out very high value financial transactions (literally buying a home in my case) can't be done online at all. The web site just tells me to call them instead to complete the transaction.

The institution is not especially geared to High Net Worth individuals, but it doesn't offer any products geared to people focused on being thrifty/ economical. It doesn't offer zero fee current account banking, it doesn't pay great interest on savings, it doesn't have "cash back" features on credit cards, it's just a very well run bank. If I needed £10 more than I need a bank I can rely on, I would leave.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#167
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

Thanks for clarifying this. This article completely missed this point and hand-waved over this, although this should have been the most important message: Twitter should not allow SMS as a single factor.

Lots of account take-overs could have been prevented if they had added this obvious security measure.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#168
post #47

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

Passwords don't work these days for sophisticated attacks. Phishing is too easy. I repeat, they don't work. No 2FA means you'll experience many successful account takeover attacks on your customers. 2FA does not mean you won't, though. Coinbase had a great talk about account takeover attacks on the recent DefCon. They receive some of the most sophisticated attacks, sometimes when attackers already have control of eve…

Link to talk?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#170
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

> Number porting should require an SMS to the existing SIM

This is done by some carriers in Russia as far as I remember.

> with the ability to respond NO to cancel the proces

There is no such possibility, but you can visit carrier's representative.

> A mandatory time delay (12 or 24 hours) could be imposed.

Some carriers do this for SMS. Here is a quote from one of the carrier's website:

> To protect you from scammers, after replacing a SIM card SMS messages from banks and commercial online services will be blocked for 24 hours. You will be able to send and receive SMS from other users and popular messengers and applications instantly.

> SMS is an extremely powerful authentication factor

But it discloses person's identity and location.

Post reply on HN