Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

131–140 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#131
post #107
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

NIST recommends against email or VoIP "phones" for the second factor, because then it's not what you know and what you have , but just two things you know , so no 2FA. As far as I understand, it does not recommend against SIM-based 2FA anymore, though considers it RESTRICTED. "Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentica…

> Note that, among other requirements, even when using phone- and SMS-based OTPs, the agency also has to verify that the OTP is being directed to a phone and not an IP address, such as with VoIP, as these accounts are not typically protected with multi-factor authentication."

Unbelievable. My email address is protected with multi-factor authentication (and given the popularity of Gmail, I'd wager that this isn't all that uncommon!); my main phone line isn't.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#132
post #71

Earlier quoted context omitted.

It's not a real vacation if you don't get locked out of at least one bank account or credit card for the crime of accessing your balance from a foreign IP, with no way to recover :)

Works great for my buy-and-hold portfolio.

Same, but it works decidedly less than great for buying train or flight tickets while already abroad and on a travel SIM.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#133
post #107
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

NIST recommends against email or VoIP "phones" for the second factor, because then it's not what you know and what you have , but just two things you know , so no 2FA. As far as I understand, it does not recommend against SIM-based 2FA anymore, though considers it RESTRICTED. "Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentica…

Interesting... I primarily use a virtual phone number because I don't want to give out my real phone number though; it's easier to cancel and replace a virtual one. (Although maybe not - at this point it's tied to so many services I would probably lose access to something permanently if I canceled it...)

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#134

Does anyone here use Efani? They are a security-focused provider, and the only one that claims to have had zero SIM-swap attacks successfully executed against them. They are an MVNO.

Efani CEO here. There are 100s of reviews online. Yes we've been able to defend against 100% of the SIM Swap attacks so far

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#135

Earlier quoted context omitted.

Doesn't Twitter force you to add a phone number now?

Yes and they plan to require ID verification next, losing privacy-conscious users is clearly not a big issue for Musk.

[dead]

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#136

Earlier quoted context omitted.

Sorry, I still don't follow. With SMS 2FA the attacker needs strictly more information as compared to just a password. It doesn't matter if you log into your bank account or twitter. Did you mean a TAN for protecting individual transactions? I file this under authorization instead of authentication. But even then a SMS TAN is better than no TAN. I cannot see a scenario where adding SMS authentication makes things les…

You're focusing on an imagined attacker performing a single type of attack, and losing sight of more significant avenues for damage. When talking about the possibility of losing money, the main thing you need to do is check your account transactions within 30 days of being issued a statement. This is required so that you can report unauthorized transactions in a timely manner, so that they can be reversed. Transactio…

Ah, now I get it, thanks for clarifying.

Well, this could be solved by sending a notification on all transactions. I already get these for my credit card account (I wish they did this on my checking account, too). When paying with Google Pay, I even get three notifications. This was very useful once, when I woke up to a $50 transaction to the XBox store that I supposedly did while sleeping without even owning an XBox.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#137

Earlier quoted context omitted.

You're focusing on an imagined attacker performing a single type of attack, and losing sight of more significant avenues for damage. When talking about the possibility of losing money, the main thing you need to do is check your account transactions within 30 days of being issued a statement. This is required so that you can report unauthorized transactions in a timely manner, so that they can be reversed. Transactio…

Ah, now I get it, thanks for clarifying. Well, this could be solved by sending a notification on all transactions. I already get these for my credit card account (I wish they did this on my checking account, too). When paying with Google Pay, I even get three notifications. This was very useful once, when I woke up to a $50 transaction to the XBox store that I supposedly did while sleeping without even owning an XBox…

Pragmatically you might be able to find a setting for your bank that lets you notify you of transactions over $X, and then set X to $0.01 or $1.00.

Abstractly my larger point is that security isn't a monolithic scalar but rather depends on the threat model and what is being secured. Far too often large entities push out features in the name of "security", but what they really mean is their own security at the expense of yours (eg the TSA). A lot of these pushes (eg SMS 2FA) are like that, especially when made mandatory rather than consensual.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#138
post #48

Earlier quoted context omitted.

That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.

Not to worry, great companies like Google harass you to set a recovery phone number /s No seriously, it is aggravating how much SMS account recovery is a thing. Google even displays banners of "You are missing recovery information" because you set a recovery email but not a recovery phone.

Recovery phone numbers are much more useful for user tracking than emails though.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#139
post #74
post #9

I thought T-Mobile significantly cracked down on SIM-swapping internally so this couldn't happen again? I know there's still no patch for human stupidity, but I really am concerned that T-Mobile still apparently seems to be the carrier of choice for easy SIM-swap attacks.

Tinfoil hat in me says that T-Mobile has a real bad problem with their internal tooling allowing low level employees access that facilitates these sort of attacks. They claim social engineering because that allows them to blame a specific employee being "tricked" rather than a more widespread issue. This type of stuff is why I canceled my account with them. It just keeps happening.

> T-Mobile has a real bad problem with their internal tooling

Oh, yes. 100%. I remember about 10 or so years ago about people selling guides on how to get access to WATSON (one of the dealer systems that let you provision accounts etc) by basically abusing a common username/password convention and making guesses based on the Store Lookup tool. IIRC it only let you set up new accounts (eg, take a stack of blank SIMs and just make infinite lines) but was still just an absolute WTF that it was... somehow a thing.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#140
post #9

I thought T-Mobile significantly cracked down on SIM-swapping internally so this couldn't happen again? I know there's still no patch for human stupidity, but I really am concerned that T-Mobile still apparently seems to be the carrier of choice for easy SIM-swap attacks.

> I thought T-Mobile significantly cracked down on SIM-swapping internally

They've cracked down so hard that the only way to do SIM swaps is to talk to a human who can be (and still routinely is) socially engineered. Self-service changes have been blocked for over a year "to enhance security".

Post reply on HN