Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

141–150 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#141
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

> probably because it's not with the big three cell providers

More likely because it's a VOIP number, which is easy to verify (Twilio's Lookup API will expose this info, and I'm sure there's other lower-level techniques)

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#143
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

my bank disallowed me from using my google voice. they said to reduce impersonation. but i said this now makes me vulnerable to sim swapping attacks and they had no response

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#144
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks. The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.

> A GV number is just as easy to transfer as any other phone number.

There is nobody to social engineer (it's Google, they hate customer service) and the system rejects all port-out requests until you unlock the number by paying a few dollars which requires breaking into the Google Account to begin with. It is absolutely not the same as compromising an employee of a carrier.

To be clear I'm describing Google Voice which is purely a VOIP service, not Google Fi which is a MVNO.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#145
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

The healthier attitude to trust issues in crypto (and society at large too), is to find mechanisms (cryptographic, game theory, economic, legal) to manage and constrain the trust assumptions that are made. You can't eliminate trust, and you probably shouldn't try. But you should figure out ways to put good seatbelts and airbags on that trust so that when you do use trust as a social lubricant (it is very good at that), the damage from when it goes wrong is constrained.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#146
post #106

Earlier quoted context omitted.

> in their believe they are smart Nice. A happy user of Reddit, the platform, whose CEO edits messages of his opponents to win an argument, that shadow bans users for mentioning specific words ("Soros" is one, BTW), that automatically sends wrong-think posts to spam... would tell us about the dystopian future Musk is leading us into. What kind of trust do you have in mind, like the one built in soviet times Pravda an…

If you believe there is signal value in having consumed reddit content - or see a Soros conspiracy behind every criticism of certain idols, I have some crypto coins to sell you too. Speaking of Soviet Russia - the FSB has fascinating manuals on exactly this topic, how to break down people’s ability to trust systematically to make them vulnerable to ideological hijacking via authority figures and contrarian messages.…

> Highly recommended reading.

If one were interested in finding these to read where or how might they be found?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#147
post #106

Earlier quoted context omitted.

> in their believe they are smart Nice. A happy user of Reddit, the platform, whose CEO edits messages of his opponents to win an argument, that shadow bans users for mentioning specific words ("Soros" is one, BTW), that automatically sends wrong-think posts to spam... would tell us about the dystopian future Musk is leading us into. What kind of trust do you have in mind, like the one built in soviet times Pravda an…

If you believe there is signal value in having consumed reddit content - or see a Soros conspiracy behind every criticism of certain idols, I have some crypto coins to sell you too. Speaking of Soviet Russia - the FSB has fascinating manuals on exactly this topic, how to break down people’s ability to trust systematically to make them vulnerable to ideological hijacking via authority figures and contrarian messages.…

> or see a Soros conspiracy behind every criticism of certain idols

Idols, Soros conspiracy... And you accuse others of being stupid. A simple idea, shady practices on the part of a platform are not OK if what you want, as you say, is trust.

> I have some crypto coins to sell you too.

I'm sure you have. You were left holding the bag in the subreddit you've mentioned.

> the FSB has fascinating manuals on exactly this topic. Highly recommended reading.

Right, they've sent you a copy. You and your government, the idiots who can be seen laughing [1][2] when told they should not depend on Russian energy. "I don't really understand what he means by that ha-ha-ha", tells your genius defense minister.

[1]: https://www.youtube.com/watch?v=FfJv9QYrlwg

[2]: https://www.youtube.com/watch?v=0CvQmWoog18

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#148

Earlier quoted context omitted.

Nowadays if you create a new account it’ll get briefly banned while they do additional checks to ensure you’re human, which is fixed by giving a phone number. Id almost appreciate just asking for one on signup then the charade

That's not always the case. Sometimes it asked me for a phone number, but most of the time not when not using a VPN or something similar. But last year I managed to create two Twitter accounts with the Tor browser and some sketchy email address and never got asked for a number, just had to do some captcha after a few minutes.

I created a few twitter accounts this year for various reasons and all of them had the same number requirement after around 24 hours!

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#149
I probably said it 100 of times, any thing relies on GSM protocol for authentication is not secure, the protocol is fundamentally broken from security perspective, but it’s still there because someone wants to keep these phone numbers as the weakest possible way to link your real identity with the digital ones.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#150
post #96

Earlier quoted context omitted.

I’d call that a number porting attack. A SIM swap to me is convincing the current provider to provision a new SIM for an existing line, which the attacker can then use to receive texts addressed to the victim. Porting attacks are definitely possible against Google Voice, but these require confirming the port in the target account first, no? And the Google Voice equivalent to a SIM swap would just be a compromise of t…

Google will not share how threat actors are pulling it off but it definitely is happening. (see the Terpin v. AT&T lawsuit for why they might not be disclosing the vector) There are "fingerprint" cookie marketplaces that sell tokens from malware-compromised computers and allow you to make HTTP requests from a victim's connection, this could be one approach. There are also scammer call centers that will call unsuspect…

Is there a reason that would-be hackers are not preempted by requiring a specific device, pins, etc with no kill-switch or social engineering available (like, you lose your credentials, there's nothing we can do, its gone)? It sometimes feels like the system is deliberately designed so certain "legitimate" actors have a backdoor into any given system...
Post reply on HN