Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

231–240 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#231
This could be stopped easily by making cell phone companies liable

> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T to switch a phone number to a new device that is under their control.

> Hackers can get the codes by bribing phone company employees.

How hard is it to insist on someone coming down to a store and submit several forms of identification to get a new SIM? And make multiple people in the store sign off on it. Has anyone ever gone to jail for taking a bribe to swap a SIM?

The other issue is to stop using SMS for a 1-factor recovery. There still needs to be a second factor, like knowing a password or a pin.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#232

https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo... NIST has said that 2FA via SMS is bad and awful for at least 3 years now. Can we knock it off, already? This won’t stop SIM swaps, but it will blunt their impact by rather a lot.

That’s the problem. Twitter requires you to add a phone number (even if you sign up without one, eventually you’ll be locked out and requires to add one). Then, once you add a number to unlock your account you’re left exposed.

Can't you add a number, verify the account, then delete the number?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#233
post #103
post #86

Earlier quoted context omitted.

eavesdrop ? the WhatsApp I use agrees to work only on one phone, if yo move it it stops working on the original.

Is that not per-phone number? The cloned SIM would have the same one

WhatsApp accounts can only be used from one device simultaneously.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#234

Please do not allow people to call SMS 2FA. For it to be 2FA, it must be: something I know alone, something I possess alone, something I am alone. Otherwise, it's just another account identifier (and likely spoof-able). SMS and phone numbers are none of these. In same vein, I wish security questions would die in a fire. Always treat them like additional passwords: use nonsensical words and store them in your password…

> Always treat them like additional passwords: use nonsensical words and store them in your password manager.

I wish password managers would make this easier.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#235

> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T Those seem like excellent litigation targets, and I’m surprised that that fact alone hasn’t fixed this bug. Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.

> Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves. If you are a captain of a ship that sees an out of control oil tanker heading for it, the solution is not to sue the oil tanker owners, rather it is to get out of its way which in Jack's case should be ordering an immediate implementation of a non-SMS 2FA

Why not both? Steer the ship aside (give directive to product/engineering teams to implement proper 2FA) while calling your lawyer.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#236
post #41

Earlier quoted context omitted.

How does this work? You have to send in your old sim before you can receive a new one? What if you lose your old sim?

> What if you lose your old sim? I'd say it's pretty simple then: you can't transfer your number and just need to get a new one. I mean at some point you have to draw a line; losing your password and resetting it via email is already a pretty gracious thing, and most support desks will help you beyond the default password reset as well if necessary. But at some point you have to draw a line - key's lost? Access is lo…

I would so much rather lose my twitter account where:

a) I don't use twitter, so it's a loss of minimal proportions

b) It's twitter's fault and easily prevented by them

Sure, a) won't be applicable to all services because there are services I actually use that my life revolves around. However, the only service I can think of that would disrupt more of my life than losing my phone number is verified 2FA secured and does not have this vulnerability.

I would actively avoid a carrier that promotes this policy and think it's naive to assert that it's even remotely viable.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#237

Earlier quoted context omitted.

In Turkey if you change your SIM card you cannot login to your bank account (web site, app). Yeah, even if you are in same mobile operator with your same phone number. How does my bank know that I have changed my SIM card? I think that they have API between mobile operator, government, and bank. For example I can see my mobile and land line numbers from my e-government account.

App is able to access the sim unique identifier. - https://en.wikipedia.org/wiki/SIM_card#ICCID - https://stackoverflow.com/a/38032034/1329429 But I am not sure about website, maybe they have integration with the operators to check last sim change date and compare it to their last know trusted sim or check the last time your phone was audited? You need to generate one time codes in TR banks afaik.

https://m.garantibbva.com.tr/mobile-tr/bireysel/subesiz/inte...

>Numara taşıma, 4.5G veya başka nedenlerle yapılan SIM kart değişikliklerinden sonra, Garanti BBVA İnternet Bankacılığı ve Garanti BBVA Mobil’e girişte kullanılan tek kullanımlık şifreler güvenliğiniz için bloke edilmektedir.

"Due to switching to another provider, 4G, or for whatever reason if you change your SIM card your password is blocked for both the app and internet banking."

>Blokenizi kaldırmak için Garanti BBVA Şubelerine uğrayabilir ya da 444 0 333 no’lu Garanti BBVA Müşteri İletişim Merkezi’ni arayabilirsiniz.

"In order to remove the password block you will need either to visit the one of our banks or call us."

Logging to Garanti requires 2FA. You can either use your password + SMS, or your password + one time code generator, in the past there was also password + mobile sign.

In Turkey 2FA is required by law in banking. This law is in action since for, I think 5-6 years.

Also, it is easy to implement this "notify the bank if SIM has changed" because all the banks (except few state banks which are in Ankara) and mobile operators (3) are all located in Istanbul.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#238
Vaguely related...SIM Swap crime is rampant in South Africa - in the Bank acc 2FA context.

Interestingly enough (academically) neither party is accepting blame, resulting in consumer taking the hit given organised syndicates.

Bank - not my problem if password and 2FA gets compromised

Cell provider - I never promised you bank grade security or safety of funds

...consumer...FML

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#239

Earlier quoted context omitted.

It's not fine, considering the zero cost of enabling TOTP 2 factor authentication. The only reason I can see for why companies don't give the option for TOTP is to force people to hand over phone numbers so they can be tracked, and in the process make the system less secure.

While you're correct it's not fine, not everyone has a smart phone or a TOTP device. There are some cases where SMS makes sense as 2FA since it's a reasonable compromise between having no 2FA or a TOTP device.

Most feature phones can also easily run a TOTP application (and have/do). There are J2ME TOTP applications that will run on hardware far back into the ancient past. There are all sorts of fun TOTP apps in the AdaFruit, Arduino, RPi hacking worlds.

The algorithm is rather straightforward. The "hardest" part is the SHA1 hashing algorithm and people have written versions of that for just about every hardware under the sun, including 6502 assembly. (Hmm, an old Game Boy would make an amusing TOTP device. I should add that to my list of possible future hack project ideas.)

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#240

Earlier quoted context omitted.

So whats the procedure for someone to recover an account if the 2fa is busted/lost ?

When you setup TOTP 2FA, the application should offer a few one time use codes (google offers 10, for example). These can be copied and stored safely somewhere. If you lose the one time use codes, then you're screwed. But that's the risk you face if you want the most simple and most secure method.

Also, most providers allow you to setup multiple simultaneous TOTP devices (and those that don't, should). On my personal TODO list is setting up a "safe deposit box" TOTP device sometime.
Post reply on HN