Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
> Number porting should require an SMS to the existing SIM with the ability to respond NO to cancel the process and flag the request as fraud This would work to the thief's advantage in the case of physical device theft. The notification should definitely be a thing, but it should not be possible to cancel the process without talking to the carrier directly and verifying your identity to them.
Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
181–190 of 312 posts
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#182Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#183Does anyone know how common or easy SIM swapping elsewhere in the world? The SIM swapping stories I've seen on HN mostly focus on US users. I remember reading an article years ago, about banks combating SIM swapping in Africa, where a lot of transfers are done by SMS, by forcing a cooldown. But I wonder, besides the US and Africa, where is SIM swapping prevalent? NYT says I'm at risk too. I'm in Europe -- am I?
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#184Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#185Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
hugely important point. helped a less-tech-savvy neighbor 'reset her skype' account that was tied to 'her phone number', only to find that the account bound to that phone number, which she had recently acquired, was publically searchable and connected with some sort of anime sex fetish subculture, presumably from a previous owner of that phone number.. she was using this phone / skype account for a job interview. nee…
I get why businesses want to harvest peoples phone numbers and phone books but you'd hope at least some would think of the implications to users first.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#186I'm still a big fan of passwords. Long, hard to guess passwords. More than one password/phrase as a failsafe, in case I lose it. I got my first iOS device 3 days ago as a gift, an iPad. During the excitement of the setup process, I was told to set up 2FA for my iCloud account, which I've never conscientiously used since I own no iOS devices. Now all my Apple ids, from my 2009 iMac to my macbook are tied to the darn 2…
This sounds strange. I always get the 2FA authorization message and the code through a push notification from Apple that appears as a dialog on the device(s) used to authorize access from another device. SMS or voice call is used for the initial setup though. [1]
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#187Someone was telling me that here in India authorities clone SIM cards to eavesdrop on WhatsApp conversations. I don't know if that's accurate, but it's becoming clear that SIMs in general are a vulnerable form of ID. I've seen US-based IT-security-minded people saying on Twitter for a long time that SMS based 2fa is bad, but the problem with hardware dongles is that they can be too secure. I don't want to lock myself…
All systems/services I have seen that allow 2FA through a hardware device like a Yubikey also provide you a set of several recovery codes that you need to note down somewhere safe so that you can use those if your device fails or is lost. Some systems/services also force you to first setup a TOTP based authentication (with an app like OTP Auth/Authy) and then proceed with setting up additional hardware based 2FA. Unless you lose access to your recovery codes, which is the same as losing your password on a system with no 2FA, you should be fine (though I do get the concern here). People also get two hardware keys and set them up for the same platforms/services, keeping one in a safe place for future use in case the first one that's regularly used gets lost or breaks.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#188(googler, opinions are my own) This is one thing nice about Google Fi, Sim swap attacks aren't possible. Your phone number with Fi what is tied to your Google account, the only way to get a Fi phone number on a new phone is to sign into the Google account. So if you protect your account with good 2FA, your number is safer than any cell phone company (at least in the US).
Why I Can No Longer Recommend Google Fi https://onemileatatime.com/google-fi-review/
> I’ve been fiercely evangelical about Project Fi since Google launched their cell phone service a few years ago. ... I think it’s important to update y’all about some recent experiences and research, along with why I am withdrawing my endorsement.
> ...
> Previously, whenever I had issues with my Pixel 2 or prior Fi-enabled devices, the third-party support center was phenomenal. I’ve had them help me with hardware issues, system issues, a phone that just wouldn’t connect to WiFi, or tethering that didn’t work when it was supposed to — every interaction was great, and resulted in the problem being solved.
> Since November, this has not been the case. My calls and chats to support have gone nowhere, and the once-great support staff have been replaced (or supplemented) by random people using generic scripts. I’m sure the awesome trouble-shooters are still there, but the sampling I’ve seen doesn’t suggest pervasive competency.
EDIT: Actually there is another, possibly more serious issue with Google Fi mentioned in the article:
> If you can’t use Google Payments, you can’t pay for Google Fi
> ...
> Getting this fixed is actually impossible, and I say that as someone who really, truly, loves solving problems and has made a living off getting phone agents to want to help me.
> We have submitted copies of his ID four times, my ID twice, multiple photos of credit cards, and various credit card statements. We’ve talked to agents and supervisors at Google Payments and Google Fi. No one is empowered to do anything, and even a well-intentioned agent doesn’t get the same answer from the "security department" twice.
> I’ve since found hundreds of comments and Reddit threads from people having similar experiences, with almost zero positive conclusions.
> The only suggestion of a solution we’ve been given is that he abandon both his email address and phone number of the past twenty years and start fresh.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#189> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T Those seem like excellent litigation targets, and I’m surprised that that fact alone hasn’t fixed this bug. Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.
> Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves. If you are a captain of a ship that sees an out of control oil tanker heading for it, the solution is not to sue the oil tanker owners, rather it is to get out of its way which in Jack's case should be ordering an immediate implementation of a non-SMS 2FA
Twitter supports U2F. Jack Dorsey just prefers not to use it, according to reports.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#190Earlier quoted context omitted.
Authy / Google Authenticator / 1Password have built-in TOTP generators. They have great UX and are much more secure.
Don't save your TOTP codes in your password manager if you are going for the "best" security. That turns multi-factor auth back into "single factor auth" and leaves you one exploit away from having your password and TOTP code from getting stolen.
It is a security tradeoff that I take for most of my accounts. For a few that a much more sensitive I use a Yubikey.