Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

111–120 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#111

Earlier quoted context omitted.

Have a paper backup of the codes?

And carry it with you at all times, of course.

All those proponents of a 'proper security with a strict 2FA' never been out of country, mugged, in an accident or in any combination of these.

Hell, if I just lose my wallet and would be forced to reissue the IDs and SIM (retaining the number!) it would take weeks to be back 'online'.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#113
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

Which bank?

Wells Fargo is one. You cannot unlock a card suspended for suspicious activity with the app. You must call the automated line and listen to the 5 most recent transactions. You can confirm you made them or deny you made them. If you deny, the card is immediately revoked, and a new card is issued. If you confirm, the suspension on your card is immediately removed.

Maybe the don't let you unlock on the app in case someone is in possession of your device? Via the automated line, you have to provide ID'ing information that someone with the device might not no still. Just trying to find some logic

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#114
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Using the account of probably one of the few trustworthy people in crypto probably helps.

[flagged]

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#115
post #36
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Back in 2020, some teenage kid got access to "God mode" on Twitter and burned it on a crypto scam too. Easy money seems to be a pretty common goal. https://fortune.com/2020/07/16/hackers-blew-twitter-god-mode...

[deleted]

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#116
post #98

Earlier quoted context omitted.

How does SMS 2FA make bank account balances (what do you even mean by that?) strictly less secure than having password 1FA? In both cases the attacker needs the password (or the client cert, whatever the other factor is), but only in the SMS 2FA case the attacker has to perform SIM swapping.

After the first sentence, there were two more sentences explaining that. "Bank balance" meaning the money in your bank account, as opposed to information about your transactions. I did forget to include that my comment was US-centric.

Sorry, I still don't follow. With SMS 2FA the attacker needs strictly more information as compared to just a password. It doesn't matter if you log into your bank account or twitter.

Did you mean a TAN for protecting individual transactions? I file this under authorization instead of authentication. But even then a SMS TAN is better than no TAN. I cannot see a scenario where adding SMS authentication makes things less secure.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#118
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

Pretty sure 95%+ of crypto “investors” are in it for get-rich-quick, rather than some sort of “zero trust” ideology.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#119
I’m curious about the conversation that happened between the attackers/scammers and T-Mobile.

Was it just a single call to social engineer support? Or did they call multiple times until they found an agent susceptible to their deception?

Personally, have gotten rid of using SMS as a 2FA method for most services. However my most critical services (banking) still use SMS as the only option.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#120
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

> Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell providers).

It’s common for organisations to blacklist VOIP-based numbers for 2FA. There’s more discussion about this, including some solutions, here:

https://news.ycombinator.com/item?id=36909505

Post reply on HN