Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

71–80 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#71
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.

It's not a real vacation if you don't get locked out of at least one bank account or credit card for the crime of accessing your balance from a foreign IP, with no way to recover :)

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#72

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

The big problem is that apparently if you have a phone number linked to your account, it can be used to reset your password even with TOTP 2FA enabled which to me, is bonkers: https://twitter.com/TimBeiko/status/1700659107764785336

Twitter was requiring phone numbers for a while for account verification and I had mine attached from pre-history, but have obviously removed it after people have been pointing this out as an attack vector.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#73
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point.

You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them.

Private key auth systems have security challenges of their own (losing access forever when you lose your key) but I wish they were an option in place of the current regime.

In the 90s you could bypass security locally on a machine by clicking cancel and it would just log you in. Feels like today it's only slightly more complicated and costs a bit of money to access twitter, email, bank accounts etc.

Seemingly little to no interest in resolving this state of affairs beyond obscure and increasingly less legal crypto based systems.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#74
post #9

I thought T-Mobile significantly cracked down on SIM-swapping internally so this couldn't happen again? I know there's still no patch for human stupidity, but I really am concerned that T-Mobile still apparently seems to be the carrier of choice for easy SIM-swap attacks.

Tinfoil hat in me says that T-Mobile has a real bad problem with their internal tooling allowing low level employees access that facilitates these sort of attacks. They claim social engineering because that allows them to blame a specific employee being "tricked" rather than a more widespread issue.

This type of stuff is why I canceled my account with them. It just keeps happening.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#75
post #63

Earlier quoted context omitted.

Except Google. Google backup codes are near useless because a Google backup code will let you log in, but won't allow you to disable 2 factor or add a new 2 factor device - meaning if you ever lose a 2 factor device and have to use a backup code, there is no way to recover your account.

Really? I'd imagine you'd need two codes (one for the login, one for access to your 2FA settings), but not being able to recover at all using them seems horrible!

It just gives some error like "this login method is not allowed for this action" or similar.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#76
post #48

Ironically SMS 2fa is less safer than just using a password

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.

He did not use phone/SMS as his 2FA it seems, because he knew it's insecure, per his tweet. But nevertheless Twitter requires a phone number for verified accounts and that phone number can be used to reset the Twitter account password. There is nothing the user can do. Since these incompetent telecom employees get social engineered again and again, it's simply bad practice to have anything phone number related for security. Twitter and other companies need to change this, it's not safe.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#77
post #52

Earlier quoted context omitted.

The API could return different identifiers per app

That’s meaningless if you can also use it to compute a signature. Just use the signature of a constant string as the id.

Android could append the unique app identifier (ie. "com.myapp") to the end of any data to be signed. Then the user can't be tracked between apps. But it also prevents you using 'sim sign in' to sign in to the same service from a web browser and app for example.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#78
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.

As someone who has been moving countries and subsequently changing phone numbers, every couple of years, SMS 2FA is such a pain.

It's hard to recall all services that have your phone number for migrating them, and even if you do, many won't accept a foreign number.

I've resorted to holding on to my old phone numbers by transferring them to prepaid SIMs.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#79
post #48

Ironically SMS 2fa is less safer than just using a password

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.

"SMS 2FA" makes bank account balances strictly less secure. The main thing you need to do to keep your bank balance secure is verify your transactions every statement period. Increasing login friction discourages the checking of transactions.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#80

Earlier quoted context omitted.

𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.

Looking at that tweet, I can't tell if it's a scam or just your regular cryptard NFT pump post.

I think that's why it's such an effective scam, these types of posts are everywhere around cryptocurrency fanbases, but this time it came from a reputable person within the community.
Post reply on HN