Vitalik Buterin reveals X account hack was caused by SIM-swap attack
61–70 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#62When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#63Earlier quoted context omitted.
Every competent TOTP implementation has backup codes. Use one of your backup codes when your phone breaks. You did write them down like the site told you to, right? Even if a site doesn't offer backup codes, you can extract the TOTP secret from the QR code, or most authenticator apps, quite easily, and then write it down. It's more secure to only save the backup codes though since they have a limited number of uses,…
Except Google. Google backup codes are near useless because a Google backup code will let you log in, but won't allow you to disable 2 factor or add a new 2 factor device - meaning if you ever lose a 2 factor device and have to use a backup code, there is no way to recover your account.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#64Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#65Earlier quoted context omitted.
Just having a phone number added to Twitter means your account is at risk of being taken over with a sim-swap. This was not 2FA related AFAICT. Twitter also requires you to add a phone number, even on old accounts you can get locked out unless you add one.
Doesn't Twitter force you to add a phone number now?
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#66How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.
𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#67Earlier quoted context omitted.
"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever
> "A phone number is sufficient to password reset a Twitter account even if not used as 2FA " In other words, they don't have a 2FA system. They have a 1FA system, and the only factor is your phone number. This is a weird choice, since people are much more likely to know your phone number than they are to know your password.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#68This makes me feel really good that the Canada Revenue Agency and most banks in Canada use SMS for second factor auth!
Ironically, my email account is so much better protected than my mobile phone number.
I'm trying very hard to believe that the SMS lobby (i.e. mobile phone operators, which earn multiple cents per inbound SMS in Europe, as well as our friendly SMS verification providers adding their markup on that) didn't exert some pressure on the regulators here...
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#69How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.
𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.
Still crazy that such a semi-anonymous scam got 700k, sounds like there's still a lot of money in crypto ready to gamble.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#70Earlier quoted context omitted.
"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever
I just tried it on my now account. It asks for the account's username, phone number, email and then sends an email to the email address. Perhaps he didn't add an email address to his Twitter account?
But, I then enabled 2FA (with an authentication app), and now when I try the flow again, I get to the screen for sending the reset code and I only have the email option left (but the screen still shows up as an extra step).
So, it's possible that when you have 2FA enabled you can no longer do it. Or, it's possible I've triggered some internal rules by resetting my password twice in a short span of time (and enabling 2FA as well) and they've bumped me to some kind of "extra verification" flow that disabled phone-based password reset.