When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Vitalik Buterin reveals X account hack was caused by SIM-swap attack
11–20 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#12Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#13Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#14When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#15Doesn't Xitter require you to have a paid account to use SMS authentication? So one way to secure your account is to refuse to pay for Blue.
This is now what they call themselves?
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#16Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#17Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#18Doesn't Xitter require you to have a paid account to use SMS authentication? So one way to secure your account is to refuse to pay for Blue.
"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever
In other words, they don't have a 2FA system. They have a 1FA system, and the only factor is your phone number.
This is a weird choice, since people are much more likely to know your phone number than they are to know your password.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#19Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#20Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
Scary stuff, had to give sooo much personal information over the course of months to recover a single account.
Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?