Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

91–100 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#91
post #9

I thought T-Mobile significantly cracked down on SIM-swapping internally so this couldn't happen again? I know there's still no patch for human stupidity, but I really am concerned that T-Mobile still apparently seems to be the carrier of choice for easy SIM-swap attacks.

A few years ago, my phone completely died. I walked into a store with it and my new phone, and got them to port the number to a new SIM without providing any information like the account PIN which I had set but didn't remember. It's good customer service, and even if they're supposed to check a bunch of info, that's still just a bit of social engineering to get around. The only solution is to not allow those lower level employees to do anything, which will cause complaints.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#92

Earlier quoted context omitted.

That’s meaningless if you can also use it to compute a signature. Just use the signature of a constant string as the id.

Android could append the unique app identifier (ie. "com.myapp") to the end of any data to be signed. Then the user can't be tracked between apps. But it also prevents you using 'sim sign in' to sign in to the same service from a web browser and app for example.

> Android could append the unique app identifier (ie. "com.myapp") to the end of any data to be signed. Then the user can't be tracked between apps. But it also prevents you using 'sim sign in' to sign in to the same service from a web browser and app for example.

I doubt that: simply add two "SIM identities" (which on the mobile phone map to the same SIM card) to the account of the respective service.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#93
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks.

The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#94
post #16

Earlier quoted context omitted.

Just having a phone number added to Twitter means your account is at risk of being taken over with a sim-swap. This was not 2FA related AFAICT. Twitter also requires you to add a phone number, even on old accounts you can get locked out unless you add one.

Doesn't Twitter force you to add a phone number now?

Yes and they plan to require ID verification next, losing privacy-conscious users is clearly not a big issue for Musk.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#95
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

You'd be surprised at the typical profile of a crypto scam victim. I trace cryptocurrency professionally and try to help as many victims as possible. Most that I meet are far from the "crypto bro" archetype. Often they are people who trust others easily, are not very tech-savvy, and believe what a website tells them without second guessing.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#96
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks. The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.

I’d call that a number porting attack. A SIM swap to me is convincing the current provider to provision a new SIM for an existing line, which the attacker can then use to receive texts addressed to the victim.

Porting attacks are definitely possible against Google Voice, but these require confirming the port in the target account first, no?

And the Google Voice equivalent to a SIM swap would just be a compromise of the Google account itself. Definitely not impossible, and I know I’m tying my availability to a company not exactly known for being the best custodian for that – but I’ll take my chances with them over any phone provider.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#97
post #48

Earlier quoted context omitted.

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.

He did not use phone/SMS as his 2FA it seems, because he knew it's insecure, per his tweet. But nevertheless Twitter requires a phone number for verified accounts and that phone number can be used to reset the Twitter account password. There is nothing the user can do. Since these incompetent telecom employees get social engineered again and again, it's simply bad practice to have anything phone number related for se…

> But nevertheless Twitter requires a phone number for verified accounts and that phone number can be used to reset the Twitter account password.

Sure, but that is not 2FA. It's 1FA. They could have used e-mail as the recovery mechanism to send a password reset link, then it still would have been SMS 2FA if they then required the SMS factor upon authentication and it would have been secure. This wasn't a problem of SMS 2FA, it was a problem of SMS based account recovery.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#98
post #48

Earlier quoted context omitted.

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.

"SMS 2FA" makes bank account balances strictly less secure. The main thing you need to do to keep your bank balance secure is verify your transactions every statement period. Increasing login friction discourages the checking of transactions.

How does SMS 2FA make bank account balances (what do you even mean by that?) strictly less secure than having password 1FA? In both cases the attacker needs the password (or the client cert, whatever the other factor is), but only in the SMS 2FA case the attacker has to perform SIM swapping.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#99
post #96

Earlier quoted context omitted.

Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks. The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.

I’d call that a number porting attack. A SIM swap to me is convincing the current provider to provision a new SIM for an existing line, which the attacker can then use to receive texts addressed to the victim. Porting attacks are definitely possible against Google Voice, but these require confirming the port in the target account first, no? And the Google Voice equivalent to a SIM swap would just be a compromise of t…

Google will not share how threat actors are pulling it off but it definitely is happening. (see the Terpin v. AT&T lawsuit for why they might not be disclosing the vector)

There are "fingerprint" cookie marketplaces that sell tokens from malware-compromised computers and allow you to make HTTP requests from a victim's connection, this could be one approach. There are also scammer call centers that will call unsuspecting people pretending to be Google, Coinbase, AT&T, or whomever, and have them click buttons in user interfaces.

I've seen entire Google accounts deleted with no recourse due to this "suspicious activity" that victims had no control over. Computer says no, and it's near-impossible to get in touch with a human at Google.

(I agree with you on terminology but media reports tend to group number porting attacks in with "SIM swaps")

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#100
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

Quote of the day - If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust.

Very well said.

Post reply on HN