Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

261–270 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#261
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

Indian laws require a police report before telecom operators can transfer a line to a new SIM card. I was always surprised how easy it is in US to transfer in comparison.

I guess that's only for lost SIM cards?

I've got my number transferred to new SIM card, about 30 times over last 10 years, without any police report. Had to produce ID proof which is quite convenient.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#262

Earlier quoted context omitted.

Twitter doesn’t use 2FA over SMS. Dorsey’s hack doesn’t tell us anything about that.

Yes, they do. 2FA is via SMS or TOTP. Frustratingly, you can't enable TOTP without a phone number, and if you remove your phone number, you disable 2FA.

No, they don’t. You can access your account with just SMS. That makes it 1FA.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#263
post #53
post #48

Earlier quoted context omitted.

How does adding a second factor of authentication to an already good password make it less secure?

because they let you use the phone number to reset the password

So you can’t add it as a second factor but not as a recovery mechanism?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#264
post #219

I once walked into a T-mobile store, showed them my phone and claimed that the simcard is stuck and asked them to transfer it to a new simcard I brought with me. They asked for my phone number, scanned the barcode on the new simcard, done. I didn't have to provide any identity. I could have been anybody and the only trace would be the security camera in the store.

Reading stories like these make me feel like it’s only a matter of time before this happens to me. Frustrating.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#265
SIM swapping events are due to phishing attacks which are hard to prevent for multiple reasons so relying on SMS based 2FA for for account security is completely foolish. You're better off disabling SMS 2FA than having it enabled because the attacker can reset your account by having your phone number.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#266

Earlier quoted context omitted.

Indian laws require a police report before telecom operators can transfer a line to a new SIM card. I was always surprised how easy it is in US to transfer in comparison.

I guess that's only for lost SIM cards? I've got my number transferred to new SIM card, about 30 times over last 10 years, without any police report. Had to produce ID proof which is quite convenient.

In those cases you would have the physical possession of the old SIM, so I guess no one can just claim to be you.

Example form for others reading till here - https://discover.vodafone.in/documents/pdfs/simreplacement/s...

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#267
Both mobile number portability and SIM swap are stupidly insecure in the US. In every other country, you need to initiate the port with your current provider - usually by sending a text from your phone. Over here, I can do it from the receiving provider and that makes it really easy to bypass security checks. Similarly for SIM swaps - there's very little security and social engineering will do the job of bypassing it.

I see plenty of people suggesting we don't give phone numbers at all. That's not very convenient for most people. I consider myself savvy and use 2FA and password managers ...etc. But by the time I realized this issue, I had given my phone number to most important services.

This and spam are two very serious issues in the US that's already solved in most countries of the world.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#268
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

It's always kindof annoyed me they don't offer a u2f auth mechanism. Can't be that hard for a company of that size.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#269

Can I put in a note saying that "Don't transfer unless I physically show up with ID in a brick and mortar store?"

Unless you technically enforce the block, there is nothing stopping a bad rep from doing it for a bribe, or being fooled. If you technically enforce the block, you now store more dangerous data with the telco that they shouldn't be holding at all for any reason.

I have a few friends in the esports field that deal with some of these issues - one had someone physically show up to a mobile store with two fakes including most watermarks in the correct name to get a SIM swap attack completed (to only shitpost on Twitter, mind you, not to steal crypto or anything)

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#270
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

It's always kindof annoyed me they don't offer a u2f auth mechanism. Can't be that hard for a company of that size.

they do https://www.yubico.com/works-with-yubikey/catalog/twitter/
Post reply on HN