Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
Indian laws require a police report before telecom operators can transfer a line to a new SIM card. I was always surprised how easy it is in US to transfer in comparison.
Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
271–280 of 312 posts
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#272Earlier quoted context omitted.
My experience is that after you give your phone number to most companies it effectively becomes a single factor: it's trivial to get them to change passwords with that alone. AFAICT, the only protection is to not give them your phone number in the first place.
Maybe it's time to reconsider phone numbers. Think about it. There's already a divide between phones on one side, and tablets/laptops/pcs etc on the other. You can only use whatsapp on a phone (or a laptop connected to a phone). You need a special phone contract to make phone calls. You can make voice calls via voip/whatsapp/whatever but you have to understand what network the person is on. Then there's this security…
That "just" is doing a lot of legwork, though. How do you identify and find that someone else, so you can call them? Generally, you need some sort of unique identity. And how do you make sure that unique virtual identity connects to the correct physical person? Once you solve that, you can probably apply the solution to phone numbers.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#273Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#274Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
Better yet, a YES text should be required with a port
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#275Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
> Number porting should require an SMS to the existing SIM with the ability to respond NO to cancel the process and flag the request as fraud (e.g. whoever made the request on the carrier side should be flagged, to fish out compromised support reps). Better yet, a YES text should be required with a port
I believe t-mobile has a nice requirement of being able to mark you number as "show up in the store and show your ID"
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#276This is why I use Google Voice with 2 factor authentication for my SMS. Google has no customer service to socially engineer.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#277Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#278Earlier quoted context omitted.
But phone numbers are not unique. They are regularly re-assigned to new customers.
It’s a good enough solution. Especially for those with disposable income, they’re not changing numbers often, if ever.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#279Earlier quoted context omitted.
SMS is only as good as the cell providers security, which has been shown over and over again to be terrible. It should never be used in any ongoing authentication.
It may very well be bad in absolute terms but compared to a single weak password it’s a huge improvement. I would bet on “log in with phone number” being better than “log in with password” across a population any day.
Beyond SIM card cloning, I could sit behind a target, initiate a SMS auth, and simply wait for the guy to look at his phone. Most of the time it will pop up right on the front screen even if locked. If he misses it, I just wait for him to unlock the phone and look at his SMS. How would you like it if passwords just popped up visible to all on your phone?
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#280Both mobile number portability and SIM swap are stupidly insecure in the US. In every other country, you need to initiate the port with your current provider - usually by sending a text from your phone. Over here, I can do it from the receiving provider and that makes it really easy to bypass security checks. Similarly for SIM swaps - there's very little security and social engineering will do the job of bypassing it…
How does this work if your phone is lost/stolen?