Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

181–190 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#181
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

> Number porting should require an SMS to the existing SIM with the ability to respond NO to cancel the process and flag the request as fraud This would work to the thief's advantage in the case of physical device theft. The notification should definitely be a thing, but it should not be possible to cancel the process without talking to the carrier directly and verifying your identity to them.

Fun fact, the person who stole the sim probably worked for the carrier, or used someone who worked at the carrier that they either knew or had leverage over. You already have to verify your identity to the carrier if you want to make changes to your account, and while you might be able social-engineer your way past it, but I would be shocked if someone like Jack Dorsey didn't have a password associated with his account that is required to make changes. Saying the carrier needs to be sure before making changes is useless if the person at the carrier is circumventing it. Plus they already do it.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#182
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

In Turkey if you change your SIM card you cannot login to your bank account (web site, app). Yeah, even if you are in same mobile operator with your same phone number. How does my bank know that I have changed my SIM card? I think that they have API between mobile operator, government, and bank. For example I can see my mobile and land line numbers from my e-government account.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#183
post #9

Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?

In Germany, you have an extra PIN (called PUK) that is required for these things (alternatively show up with your ID at a store). So unless someone has that, it’s not as much of a problem.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#185
post #157
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

hugely important point. helped a less-tech-savvy neighbor 'reset her skype' account that was tied to 'her phone number', only to find that the account bound to that phone number, which she had recently acquired, was publically searchable and connected with some sort of anime sex fetish subculture, presumably from a previous owner of that phone number.. she was using this phone / skype account for a job interview. nee…

Never really made any sense to me whatsoever why we all switched over from having to use phone numbers instead of email addresses as sign in over the past few years.

I get why businesses want to harvest peoples phone numbers and phone books but you'd hope at least some would think of the implications to users first.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#186

I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…

> Now everytime I want to upgrade something in my Macbook I have to get an SMS code on my (vulnerable) phone to access my Apple account. This is a very unfortunate decision by Apple.

This sounds strange. I always get the 2FA authorization message and the code through a push notification from Apple that appears as a dialog on the device(s) used to authorize access from another device. SMS or voice call is used for the initial setup though. [1]

[1]: https://support.apple.com/en-us/HT204915

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#187
post #30

Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID. I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself…

> I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself out of my own Gmail account. I guess apps like Authy as mentioned in the other comments are an alternative. In any case I guess there are (or should be) some special codes you can write down in case you lose access to your second-factor info.

All systems/services I have seen that allow 2FA through a hardware device like a Yubikey also provide you a set of several recovery codes that you need to note down somewhere safe so that you can use those if your device fails or is lost. Some systems/services also force you to first setup a TOTP based authentication (with an app like OTP Auth/Authy) and then proceed with setting up additional hardware based 2FA. Unless you lose access to your recovery codes, which is the same as losing your password on a system with no 2FA, you should be fine (though I do get the concern here). People also get two hardware keys and set them up for the same platforms/services, keeping one in a safe place for future use in case the first one that's regularly used gets lost or breaks.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#188
post #149

(googler, opinions are my own) This is one thing nice about Google Fi, Sim swap attacks aren't possible. Your phone number with Fi what is tied to your Google account, the only way to get a Fi phone number on a new phone is to sign into the Google account. So if you protect your account with good 2FA, your number is safer than any cell phone company (at least in the US).

While Google Fi appears to offer better security than other US-based carriers, the support team needs work:

Why I Can No Longer Recommend Google Fi https://onemileatatime.com/google-fi-review/

> I’ve been fiercely evangelical about Project Fi since Google launched their cell phone service a few years ago. ... I think it’s important to update y’all about some recent experiences and research, along with why I am withdrawing my endorsement.

> ...

> Previously, whenever I had issues with my Pixel 2 or prior Fi-enabled devices, the third-party support center was phenomenal. I’ve had them help me with hardware issues, system issues, a phone that just wouldn’t connect to WiFi, or tethering that didn’t work when it was supposed to — every interaction was great, and resulted in the problem being solved.

> Since November, this has not been the case. My calls and chats to support have gone nowhere, and the once-great support staff have been replaced (or supplemented) by random people using generic scripts. I’m sure the awesome trouble-shooters are still there, but the sampling I’ve seen doesn’t suggest pervasive competency.

EDIT: Actually there is another, possibly more serious issue with Google Fi mentioned in the article:

> If you can’t use Google Payments, you can’t pay for Google Fi

> ...

> Getting this fixed is actually impossible, and I say that as someone who really, truly, loves solving problems and has made a living off getting phone agents to want to help me.

> We have submitted copies of his ID four times, my ID twice, multiple photos of credit cards, and various credit card statements. We’ve talked to agents and supervisors at Google Payments and Google Fi. No one is empowered to do anything, and even a well-intentioned agent doesn’t get the same answer from the "security department" twice.

> I’ve since found hundreds of comments and Reddit threads from people having similar experiences, with almost zero positive conclusions.

> The only suggestion of a solution we’ve been given is that he abandon both his email address and phone number of the past twenty years and start fresh.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#189

> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T Those seem like excellent litigation targets, and I’m surprised that that fact alone hasn’t fixed this bug. Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.

> Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves. If you are a captain of a ship that sees an out of control oil tanker heading for it, the solution is not to sue the oil tanker owners, rather it is to get out of its way which in Jack's case should be ordering an immediate implementation of a non-SMS 2FA

> which in Jack's case should be ordering an immediate implementation of a non-SMS 2FA

Twitter supports U2F. Jack Dorsey just prefers not to use it, according to reports.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#190
post #6

Earlier quoted context omitted.

Authy / Google Authenticator / 1Password have built-in TOTP generators. They have great UX and are much more secure.

Don't save your TOTP codes in your password manager if you are going for the "best" security. That turns multi-factor auth back into "single factor auth" and leaves you one exploit away from having your password and TOTP code from getting stolen.

I store my TOTP in 1Password... I think it's still more secure than SMS (because to restore 1Password vault you also need a Secret, not only your password) and so much more convenient than a separate app, because 1Password auto-copies the TOTP code to your clipboard after filling form fields, making signing in a very smooth experience.

It is a security tradeoff that I take for most of my accounts. For a few that a much more sensitive I use a Yubikey.

Post reply on HN