Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

31–40 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#31
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Using the account of probably one of the few trustworthy people in crypto probably helps.

Ironically, every SIM card is a cryptographic secure element, and it would've been ideal to do public key login.

If you plug SIM card into desktop, you can actually do signing with it, and TLS authentication.

I recall, only Nokia S60 series, and A200 had a SIM card API exposed to apps. Ios does not give you access to SIM, Android does only for system apps.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#32
post #24
post #16

Earlier quoted context omitted.

Just having a phone number added to Twitter means your account is at risk of being taken over with a sim-swap. This was not 2FA related AFAICT. Twitter also requires you to add a phone number, even on old accounts you can get locked out unless you add one.

I've got an account from 2009 and have never had to enter my phone number (if I ever get asked, that'll be the time when I stop using it).

I've used Twitter from 2013 to 2021, and have eventually been locked-out by Twitter requesting a phone number with no way to work around.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#34
post #24

Earlier quoted context omitted.

I've got an account from 2009 and have never had to enter my phone number (if I ever get asked, that'll be the time when I stop using it).

I've used Twitter from 2013 to 2021, and have eventually been locked-out by Twitter requesting a phone number with no way to work around.

It'll be a shame if that happens to my account, as I lurk on Twitter every day (but never tweet or like), but I value privacy of my phone number more than I value the enjoyment I get from it.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#35
post #19

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

It is good to know that hardware wallets such as Trezor and Ledger supports 2FA protocols so if you have one there is no need to use another device.

If you're actually using them for their intended use (storing your crypto), the less you connect them to your computer, the better. Check them 2-4x a year to make sure they're updated, but I wouldn't want to carry my cold storage device on my keychain like I do my YubiKey.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#36
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Back in 2020, some teenage kid got access to "God mode" on Twitter and burned it on a crypto scam too.

Easy money seems to be a pretty common goal.

https://fortune.com/2020/07/16/hackers-blew-twitter-god-mode...

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#38

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication. Scary stuff, had to give sooo much personal information over the course of months to recover a single account. Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?

Authy solves this by putting all the TOTP keys behind a master password and then backing it up online, so you can get up and running on a different device quickly. It's the same trade-off as a password manager, where your eggs are all in one basket but hopefully it's a secure basket.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#39
I've been using Google Voice free phone number if I need to give out phone number for verification, and I hope it mitigates the possibility of SIM-swapping. Also I have another burner phone number using Hushed on my phone. Does anyone know if there's vulnerability using these burner numbers?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#40
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

I could easily imagine the scam had 30 victims, with 29 of them losing $10 and the remaining one losing $700k.
Post reply on HN