Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
NIST recommends against email or VoIP "phones" for the second factor, because then it's not what you know and what you have , but just two things you know , so no 2FA. As far as I understand, it does not recommend against SIM-based 2FA anymore, though considers it RESTRICTED. "Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentica…
Vitalik Buterin reveals X account hack was caused by SIM-swap attack
151–160 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#152Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#153When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#154Earlier quoted context omitted.
I've got an account from 2009 and have never had to enter my phone number (if I ever get asked, that'll be the time when I stop using it).
Nowadays if you create a new account it’ll get briefly banned while they do additional checks to ensure you’re human, which is fixed by giving a phone number. Id almost appreciate just asking for one on signup then the charade
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#155I don't understand this sim-swapping concept. Where I am from (EU country), if you need to get a new sim for your number, you have to physically go to your service provider's stores with an official proof of identity (passport or identity card) and do the change. Upon changing, your previous sim immediately loses service
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#156Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
On their tech support page [1], Google Fi is said to be resistant/immune to SIM swap attacks because the attacker needs physical access to your device and Google account. Yet earlier this year [2], the Google Fi hack said to have exposed Fi users to SIM swapping. Can anyone shed light on how this can happen without someone having your phone? [1]: https://support.google.com/fi/answer/9834243?hl=en [2]: https://www.red…
I do not know specific details of this particular incident but I would like to emphasize the fact that Google Fi, at least in the US, is a virtual network on top of the T-mobile's physical one. There is some extra level of security via obscurity that makes simple social engineering attacks harder but fundamentally it is still T-mobile underneath.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#157Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point. You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them. Private key auth systems have security challenges of their own (losing access forever when you lose your…
And a solution to this is very simple. Make telcos legally liable for losses due to SIM-swap attacks and before the ink is dry on such a law, Telcos will ban using phone numbers for authentication in their TOS. The banks and alike will be forced to come up with another, hopefully, better auth system.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#158When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Crypto bros are self selecting for scams. If your world view has been degraded to see zero trust as a solution rather than a dystopian end state, meaning you’ve lost all trust in society, you’re highly vulnerable to be conned by the authority figures you secretly crave to trust. It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and u…
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#159I don't understand this sim-swapping concept. Where I am from (EU country), if you need to get a new sim for your number, you have to physically go to your service provider's stores with an official proof of identity (passport or identity card) and do the change. Upon changing, your previous sim immediately loses service
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#160When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
$700k in NFTs I recall. Isn't that more like $70?