Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

171–180 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#171
post #71

Earlier quoted context omitted.

I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.

It's not a real vacation if you don't get locked out of at least one bank account or credit card for the crime of accessing your balance from a foreign IP, with no way to recover :)

> It's not a real vacation if you don't get locked out of at least one bank account or credit card for the crime of accessing your balance from a foreign IP, with no way to recover :)

Laughs in Bitcoin

Also, Charles Schwab Investment checking account for the uninitiated saves me from this issue; NFC enabled now ensures my card will never get eaten in a random ATM now.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#172
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point. You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them. Private key auth systems have security challenges of their own (losing access forever when you lose your…

His..twitter account.

Not his private wallet.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#174
post #121
post #104

Earlier quoted context omitted.

Insofar as one of the factors should be something the user knows , and one factor something the user has , that makes perfect sense. You know your password (or the master password to your password manager), and you have your phone with the SIM card. With email (or Authy), the second factor is also something you know , thus it's not 2F anymore. Note that NIST also recommends against email as a factor in 2FA (A-B11 her…

What do you mean? I "have" access to my SMSes via my phone, and I "have" access to my email or my Authy also via my phone. If you get my phone, you can: 1. start password reset via email 2. confirm via SMS 2FA So that makes this into 1FA not 2FA. At least for TOTP secrets, I can store them securely, and attackers cannot convince a human support agent somewhere to hand them over. If you want true 2FA, you need somethi…

You need the SIM to receive SMS ("possession"), not just a password ("knowledge"). For email, you just need knowledge.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#175
post #157

Earlier quoted context omitted.

> It's pretty wild how baked into modern life insecure 2fa is. And a solution to this is very simple. Make telcos legally liable for losses due to SIM-swap attacks and before the ink is dry on such a law, Telcos will ban using phone numbers for authentication in their TOS. The banks and alike will be forced to come up with another, hopefully, better auth system.

Not sure why you're being downvoted; I think this is pretty reasonable idea. Of course, there's zero chance of this happening in the US, given telcos would lobby heavily against it. But as a thought experiment, I think that's exactly what should happen: telcos should be held liable for their piss-poor security practices against SIM swapping. And you never know what's going to come up from EU from a regulatory perspec…

I didn't down vote GP and I agree with both of you, but I think a reason for down votes could be because it's quite authoritarian.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#176
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

On their tech support page [1], Google Fi is said to be resistant/immune to SIM swap attacks because the attacker needs physical access to your device and Google account. Yet earlier this year [2], the Google Fi hack said to have exposed Fi users to SIM swapping. Can anyone shed light on how this can happen without someone having your phone? [1]: https://support.google.com/fi/answer/9834243?hl=en [2]: https://www.red…

Think of it. You lost your phone and went to store and store employee or CS over the phone is able to issue you a SIM. Now the same employee takes bribe and give it to the hackers who use it to steal your fund

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#177
post #123

Earlier quoted context omitted.

On their tech support page [1], Google Fi is said to be resistant/immune to SIM swap attacks because the attacker needs physical access to your device and Google account. Yet earlier this year [2], the Google Fi hack said to have exposed Fi users to SIM swapping. Can anyone shed light on how this can happen without someone having your phone? [1]: https://support.google.com/fi/answer/9834243?hl=en [2]: https://www.red…

Implementation flaws like that are always possible, but my concern is that in so many cases, SIM swaps are ridiculously easy by design (or more accurately, by absence) of the phone provider's security procedures.

Issue is that FCC mandates a port out within 4 hours and stores don't make $$ while doing these so their goal is to get you out of the door ASAP so they can focus on the revenue. So that's why + bribe factor

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#178
post #157

Earlier quoted context omitted.

It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point. You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them. Private key auth systems have security challenges of their own (losing access forever when you lose your…

> It's pretty wild how baked into modern life insecure 2fa is. And a solution to this is very simple. Make telcos legally liable for losses due to SIM-swap attacks and before the ink is dry on such a law, Telcos will ban using phone numbers for authentication in their TOS. The banks and alike will be forced to come up with another, hopefully, better auth system.

Security comes with cost and inconvenience. Like would you pay $50 everytime you've to swap a SIM ?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#179
post #127

Earlier quoted context omitted.

The only time where Google's absolute lack of customer service for end users might pay off

True – can't social-engineer a person if there's no person!

https://www.bleepingcomputer.com/news/security/google-fi-dat...

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#180
post #157

Earlier quoted context omitted.

> It's pretty wild how baked into modern life insecure 2fa is. And a solution to this is very simple. Make telcos legally liable for losses due to SIM-swap attacks and before the ink is dry on such a law, Telcos will ban using phone numbers for authentication in their TOS. The banks and alike will be forced to come up with another, hopefully, better auth system.

Security comes with cost and inconvenience. Like would you pay $50 everytime you've to swap a SIM ?

If it was used as prepayment for services, this is not half bad idea. But for targeted attacks to people like Vitalik that's well within budget.
Post reply on HN