Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

101–110 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#101
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

Which bank?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#102
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks. The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.

The only time where Google's absolute lack of customer service for end users might pay off

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#103
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

On their tech support page [1], Google Fi is said to be resistant/immune to SIM swap attacks because the attacker needs physical access to your device and Google account. Yet earlier this year [2], the Google Fi hack said to have exposed Fi users to SIM swapping. Can anyone shed light on how this can happen without someone having your phone?

[1]: https://support.google.com/fi/answer/9834243?hl=en [2]: https://www.reddit.com/r/cybersecurity/comments/10rqtt2/goog...

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#104
post #68

This makes me feel really good that the Canada Revenue Agency and most banks in Canada use SMS for second factor auth!

The EBA (the European banking regulator in charge of specifying the technical details of the PSD2 regulation, which covers secure cardholder authentication, among other things) also stated a while ago that only SMS-OTP is a "true" factor; Email-OTP isn't. Ironically, my email account is so much better protected than my mobile phone number. I'm trying very hard to believe that the SMS lobby (i.e. mobile phone operator…

Insofar as one of the factors should be something the user knows, and one factor something the user has, that makes perfect sense. You know your password (or the master password to your password manager), and you have your phone with the SIM card. With email (or Authy), the second factor is also something you know, thus it's not 2F anymore.

Note that NIST also recommends against email as a factor in 2FA (A-B11 here: https://pages.nist.gov/800-63-FAQ/ ), and says that SMS OTP must be directed to a phone, not an IP address (such as with VoIP, see A-B01 in the same document).

"Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication." (5.1.3.1 of NIST SP 800-63B)

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#105
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

> in their believe they are smart

Nice. A happy user of Reddit, the platform, whose CEO edits messages of his opponents to win an argument, that shadow bans users for mentioning specific words ("Soros" is one, BTW), that automatically sends wrong-think posts to spam... would tell us about the dystopian future Musk is leading us into. What kind of trust do you have in mind, like the one built in soviet times Pravda and Moskovskiy Komsomolets?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#106
post #82

Earlier quoted context omitted.

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

> in their believe they are smart Nice. A happy user of Reddit, the platform, whose CEO edits messages of his opponents to win an argument, that shadow bans users for mentioning specific words ("Soros" is one, BTW), that automatically sends wrong-think posts to spam... would tell us about the dystopian future Musk is leading us into. What kind of trust do you have in mind, like the one built in soviet times Pravda an…

If you believe there is signal value in having consumed reddit content - or see a Soros conspiracy behind every criticism of certain idols, I have some crypto coins to sell you too.

Speaking of Soviet Russia - the FSB has fascinating manuals on exactly this topic, how to break down people’s ability to trust systematically to make them vulnerable to ideological hijacking via authority figures and contrarian messages. Highly recommended reading.

As we say in German “getroffene Hunde bellen ”.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#107
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

NIST recommends against email or VoIP "phones" for the second factor, because then it's not what you know and what you have, but just two things you know, so no 2FA. As far as I understand, it does not recommend against SIM-based 2FA anymore, though considers it RESTRICTED.

"Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication."

(5.1.3.1 of SP 800-63B https://pages.nist.gov/800-63-3/sp800-63b.html)

"Currently, authenticators leveraging the public switched telephone network, including phone- and Short Message Service (SMS)-based one-time passwords (OTPs) are restricted. Other authenticator types may be added as additional threats emerge. Note that, among other requirements, even when using phone- and SMS-based OTPs, the agency also has to verify that the OTP is being directed to a phone and not an IP address, such as with VoIP, as these accounts are not typically protected with multi-factor authentication."

"NIST SP 800-63B does not allow the use of email as a channel for single or multi-factor authentication processes."

(A-B01 and A-B11 in the FAQ https://pages.nist.gov/800-63-FAQ/)

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#108
post #82

Earlier quoted context omitted.

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

You'd be surprised at the typical profile of a crypto scam victim. I trace cryptocurrency professionally and try to help as many victims as possible. Most that I meet are far from the "crypto bro" archetype. Often they are people who trust others easily, are not very tech-savvy, and believe what a website tells them without second guessing.

Yup I think your definition of crypto bro is wrong: that's exactly who they are in their vast majority, people who read once the opinion that the "federal reserve is never federal nor a reserve" and believe it and start clicking on bullshit links. It's in the very name of it and they can still believe the first guy telling them, with no proof nor demonstration, that it's not.

Trusting the first website they read is exactly the defining trait of crypto bros. Normal people just use experience to guide their decision, like say, do like their parents and stick to a bank account.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#109
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

[dead]

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#110
post #98

Earlier quoted context omitted.

"SMS 2FA" makes bank account balances strictly less secure. The main thing you need to do to keep your bank balance secure is verify your transactions every statement period. Increasing login friction discourages the checking of transactions.

How does SMS 2FA make bank account balances (what do you even mean by that?) strictly less secure than having password 1FA? In both cases the attacker needs the password (or the client cert, whatever the other factor is), but only in the SMS 2FA case the attacker has to perform SIM swapping.

After the first sentence, there were two more sentences explaining that. "Bank balance" meaning the money in your bank account, as opposed to information about your transactions. I did forget to include that my comment was US-centric.
Post reply on HN