Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

151–160 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#151
post #107
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

NIST recommends against email or VoIP "phones" for the second factor, because then it's not what you know and what you have , but just two things you know , so no 2FA. As far as I understand, it does not recommend against SIM-based 2FA anymore, though considers it RESTRICTED. "Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentica…

NIST has been wrong previously.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#152
I don't understand this sim-swapping concept. Where I am from (EU country), if you need to get a new sim for your number, you have to physically go to your service provider's stores with an official proof of identity (passport or identity card) and do the change. Upon changing, your previous sim immediately loses service

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#153
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

We’re talking about people who still willingly use Twitter and pay for blue check marks here…

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#154
post #24

Earlier quoted context omitted.

I've got an account from 2009 and have never had to enter my phone number (if I ever get asked, that'll be the time when I stop using it).

Nowadays if you create a new account it’ll get briefly banned while they do additional checks to ensure you’re human, which is fixed by giving a phone number. Id almost appreciate just asking for one on signup then the charade

The various Meta properties do this too, except instead of phone numbers they require government ID and headshots. It’s all a scummy dark pattern relying on the sunk cost fallacy.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#155

I don't understand this sim-swapping concept. Where I am from (EU country), if you need to get a new sim for your number, you have to physically go to your service provider's stores with an official proof of identity (passport or identity card) and do the change. Upon changing, your previous sim immediately loses service

United States services are fundamentally broken in this way because there is literally no unified identification system for the United States. There are identity systems for most US states, but there are 50 of those and the requirements and features vary widely which makes it a nightmare to build on top of them.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#156
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

On their tech support page [1], Google Fi is said to be resistant/immune to SIM swap attacks because the attacker needs physical access to your device and Google account. Yet earlier this year [2], the Google Fi hack said to have exposed Fi users to SIM swapping. Can anyone shed light on how this can happen without someone having your phone? [1]: https://support.google.com/fi/answer/9834243?hl=en [2]: https://www.red…

> Can anyone shed light on how this can happen without someone having your phone?

I do not know specific details of this particular incident but I would like to emphasize the fact that Google Fi, at least in the US, is a virtual network on top of the T-mobile's physical one. There is some extra level of security via obscurity that makes simple social engineering attacks harder but fundamentally it is still T-mobile underneath.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#157
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point. You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them. Private key auth systems have security challenges of their own (losing access forever when you lose your…

> It's pretty wild how baked into modern life insecure 2fa is.

And a solution to this is very simple. Make telcos legally liable for losses due to SIM-swap attacks and before the ink is dry on such a law, Telcos will ban using phone numbers for authentication in their TOS. The banks and alike will be forced to come up with another, hopefully, better auth system.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#158
post #82
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…

Please don't take HN threads on generic flamewar tangents. It makes discussion more predictable and eventually more nasty.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

https://news.ycombinator.com/newsguidelines.html

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#159

I don't understand this sim-swapping concept. Where I am from (EU country), if you need to get a new sim for your number, you have to physically go to your service provider's stores with an official proof of identity (passport or identity card) and do the change. Upon changing, your previous sim immediately loses service

In some more corrupt countries in EU, clerks can be bribed, unfortunately

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#160
post #62
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

$700k in NFTs I recall. Isn't that more like $70?

Downvote all you like. NFTs have no real liquidity (or usecase), the 'price' is just wash trading.
Post reply on HN