Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
Vitalik Buterin reveals X account hack was caused by SIM-swap attack
101–110 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#102Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks. The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#103Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
[1]: https://support.google.com/fi/answer/9834243?hl=en [2]: https://www.reddit.com/r/cybersecurity/comments/10rqtt2/goog...
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#104This makes me feel really good that the Canada Revenue Agency and most banks in Canada use SMS for second factor auth!
The EBA (the European banking regulator in charge of specifying the technical details of the PSD2 regulation, which covers secure cardholder authentication, among other things) also stated a while ago that only SMS-OTP is a "true" factor; Email-OTP isn't. Ironically, my email account is so much better protected than my mobile phone number. I'm trying very hard to believe that the SMS lobby (i.e. mobile phone operator…
Note that NIST also recommends against email as a factor in 2FA (A-B11 here: https://pages.nist.gov/800-63-FAQ/ ), and says that SMS OTP must be directed to a phone, not an IP address (such as with VoIP, see A-B01 in the same document).
"Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication." (5.1.3.1 of NIST SP 800-63B)
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#105When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…
Nice. A happy user of Reddit, the platform, whose CEO edits messages of his opponents to win an argument, that shadow bans users for mentioning specific words ("Soros" is one, BTW), that automatically sends wrong-think posts to spam... would tell us about the dystopian future Musk is leading us into. What kind of trust do you have in mind, like the one built in soviet times Pravda and Moskovskiy Komsomolets?
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#106Earlier quoted context omitted.
Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…
> in their believe they are smart Nice. A happy user of Reddit, the platform, whose CEO edits messages of his opponents to win an argument, that shadow bans users for mentioning specific words ("Soros" is one, BTW), that automatically sends wrong-think posts to spam... would tell us about the dystopian future Musk is leading us into. What kind of trust do you have in mind, like the one built in soviet times Pravda an…
Speaking of Soviet Russia - the FSB has fascinating manuals on exactly this topic, how to break down people’s ability to trust systematically to make them vulnerable to ideological hijacking via authority figures and contrarian messages. Highly recommended reading.
As we say in German “getroffene Hunde bellen ”.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#107Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
"Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication."
(5.1.3.1 of SP 800-63B https://pages.nist.gov/800-63-3/sp800-63b.html)
"Currently, authenticators leveraging the public switched telephone network, including phone- and Short Message Service (SMS)-based one-time passwords (OTPs) are restricted. Other authenticator types may be added as additional threats emerge. Note that, among other requirements, even when using phone- and SMS-based OTPs, the agency also has to verify that the OTP is being directed to a phone and not an IP address, such as with VoIP, as these accounts are not typically protected with multi-factor authentication."
"NIST SP 800-63B does not allow the use of email as a channel for single or multi-factor authentication processes."
(A-B01 and A-B11 in the FAQ https://pages.nist.gov/800-63-FAQ/)
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#108Earlier quoted context omitted.
Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…
You'd be surprised at the typical profile of a crypto scam victim. I trace cryptocurrency professionally and try to help as many victims as possible. Most that I meet are far from the "crypto bro" archetype. Often they are people who trust others easily, are not very tech-savvy, and believe what a website tells them without second guessing.
Trusting the first website they read is exactly the defining trait of crypto bros. Normal people just use experience to guide their decision, like say, do like their parents and stick to a bank account.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#109When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#110Earlier quoted context omitted.
"SMS 2FA" makes bank account balances strictly less secure. The main thing you need to do to keep your bank balance secure is verify your transactions every statement period. Increasing login friction discourages the checking of transactions.
How does SMS 2FA make bank account balances (what do you even mean by that?) strictly less secure than having password 1FA? In both cases the attacker needs the password (or the client cert, whatever the other factor is), but only in the SMS 2FA case the attacker has to perform SIM swapping.