Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

41–50 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#41
post #31

Earlier quoted context omitted.

Using the account of probably one of the few trustworthy people in crypto probably helps.

Ironically, every SIM card is a cryptographic secure element, and it would've been ideal to do public key login. If you plug SIM card into desktop, you can actually do signing with it, and TLS authentication. I recall, only Nokia S60 series, and A200 had a SIM card API exposed to apps. Ios does not give you access to SIM, Android does only for system apps.

Giving apps access to the sim is a privacy leak. Every app would use it to get a unique user identifier and track you between apps.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#42

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication. Scary stuff, had to give sooo much personal information over the course of months to recover a single account. Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?

You can enroll multiple devices using the same TOTP QR code, just scan it more than once. They will generate the same code sequence and the site won’t know the difference.

You can even save the QR code and enroll a new device later if you want.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#44
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

$700k? I see that human idiocy is a large untapped source of wealth...

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#45
post #26

Earlier quoted context omitted.

I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication. Scary stuff, had to give sooo much personal information over the course of months to recover a single account. Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?

Every competent TOTP implementation has backup codes. Use one of your backup codes when your phone breaks. You did write them down like the site told you to, right? Even if a site doesn't offer backup codes, you can extract the TOTP secret from the QR code, or most authenticator apps, quite easily, and then write it down. It's more secure to only save the backup codes though since they have a limited number of uses,…

Except Google. Google backup codes are near useless because a Google backup code will let you log in, but won't allow you to disable 2 factor or add a new 2 factor device - meaning if you ever lose a 2 factor device and have to use a backup code, there is no way to recover your account.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#46
How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes?

Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#47
Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course).

Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell providers).

The state of "two-factor authentication" (a.k.a. something you're phished for and something you're social-engineered out of) and "identity verification" (a.k.a. "have a $80/month phone plan with these three companies or get lost”) in this country makes me really sad.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#48

Ironically SMS 2fa is less safer than just using a password

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password.

As someone else pointed out, SMS based account recovery is the culprit.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#49
post #48

Ironically SMS 2fa is less safer than just using a password

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.

Going strictly by the definition that's correct, but if you take a look at the number of services that allow you to reset your password using only an SMS-OTP you'll quickly realize that reality doesn't live up to that ideal.

I mean, at least SMS-OTPs are one-time use, i.e. they don't facilitate a compromise if done correctly, but the "done correctly" part here is once again very load-bearing.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#50
post #46

How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.

𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v...

You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.

Post reply on HN