Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.
Vitalik Buterin reveals X account hack was caused by SIM-swap attack
71–80 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#72Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
Twitter was requiring phone numbers for a while for account verification and I had mine attached from pre-history, but have obviously removed it after people have been pointing this out as an attack vector.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#73Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them.
Private key auth systems have security challenges of their own (losing access forever when you lose your key) but I wish they were an option in place of the current regime.
In the 90s you could bypass security locally on a machine by clicking cancel and it would just log you in. Feels like today it's only slightly more complicated and costs a bit of money to access twitter, email, bank accounts etc.
Seemingly little to no interest in resolving this state of affairs beyond obscure and increasingly less legal crypto based systems.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#74I thought T-Mobile significantly cracked down on SIM-swapping internally so this couldn't happen again? I know there's still no patch for human stupidity, but I really am concerned that T-Mobile still apparently seems to be the carrier of choice for easy SIM-swap attacks.
This type of stuff is why I canceled my account with them. It just keeps happening.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#75Earlier quoted context omitted.
Except Google. Google backup codes are near useless because a Google backup code will let you log in, but won't allow you to disable 2 factor or add a new 2 factor device - meaning if you ever lose a 2 factor device and have to use a backup code, there is no way to recover your account.
Really? I'd imagine you'd need two codes (one for the login, one for access to your 2FA settings), but not being able to recover at all using them seems horrible!
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#76Ironically SMS 2fa is less safer than just using a password
That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#77Earlier quoted context omitted.
The API could return different identifiers per app
That’s meaningless if you can also use it to compute a signature. Just use the signature of a constant string as the id.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#78Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.
It's hard to recall all services that have your phone number for migrating them, and even if you do, many won't accept a foreign number.
I've resorted to holding on to my old phone numbers by transferring them to prepaid SIMs.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#79Ironically SMS 2fa is less safer than just using a password
That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#80Earlier quoted context omitted.
𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.
Looking at that tweet, I can't tell if it's a scam or just your regular cryptard NFT pump post.