US SEC blames 'SIM swapping' for its X account hack
11–20 of 21 posts
Re: US SEC blames 'SIM swapping' for its X account hack
#12In my country, carriers are allowed to cancel your SIM card if you don't use it for a couple of months, then give the number to some other, new customer. It's a nightmare since you can lose your accounts and even the debit card is tied to a phone number to make online payments. I wanted to swap providers but I had to keep the old SIM active in a phasing-out stage...
Re: US SEC blames 'SIM swapping' for its X account hack
#13Re: US SEC blames 'SIM swapping' for its X account hack
#14Earlier quoted context omitted.
You don't have to give true answers to security questions, FWIW.
Yep. All of my answers are GUIDs that I keep track of in 1Password.
Re: US SEC blames 'SIM swapping' for its X account hack
#15Earlier quoted context omitted.
Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")
You don't have to give true answers to security questions, FWIW.
Probably the best bet is using a passphrase here but it might not be fool proof.
Re: US SEC blames 'SIM swapping' for its X account hack
#16Earlier quoted context omitted.
You don't have to give true answers to security questions, FWIW.
I thought this was a good strategy too until some one said that a customer service rep once asked him one of the questions over the phone and, lacking his backed up security questions at hand, he just said "it is a bunch of random characters" and was let through... Probably the best bet is using a passphrase here but it might not be fool proof.
Re: US SEC blames 'SIM swapping' for its X account hack
#17Earlier quoted context omitted.
This is one of the reasons that I try to avoid giving companies my number. I'm always worry that they will decide that it is a valid recovery mechanism for my account. (Either that it is required locking me out or that it is sufficient allowing takeover)
Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")
Re: US SEC blames 'SIM swapping' for its X account hack
#18Re: US SEC blames 'SIM swapping' for its X account hack
#19A lot of this should land on X. This is a high-profile, high-risk account. Allowing a password reset on these accounts without an additional check is sloppy. When people look at how many people you need to actually run X, things like this often get lost, and over time, they degrade trust in the service.
The article also mentions that:
> The SEC also said that, six months prior to the attack, staff had removed an added layer of protection, known as multi-factor authentication (MFA), and did not restore it until after the Jan. 9 attack.
So they removed MFA for some reason. How should X handle a situation like that?
Re: US SEC blames 'SIM swapping' for its X account hack
#20A lot of this should land on X. This is a high-profile, high-risk account. Allowing a password reset on these accounts without an additional check is sloppy. When people look at how many people you need to actually run X, things like this often get lost, and over time, they degrade trust in the service.
Wouldn't it be more reasonable that government agencies treat their accounts as high risk and implement proper security measures themselves? Why should X use their manpower for special treatment to SOME of their users? If anything they should educate ALL users to use proper security, but the blame is entirely on the SEC. Don't be ridiculous. The article also mentions that: > The SEC also said that, six months prior t…
Because X wants to continue to be a trusted platform. The more account takeovers there are, the more people start to doubt what authoritative sources say on X, and the less they use X.
> How should X handle a situation like that?
Flag high-risk accounts to go through extra verification because the cost of not doing it is high.