Live data from Hacker News

US SEC blames 'SIM swapping' for its X account hack

reuters.com

11–20 of 21 posts

Re: US SEC blames 'SIM swapping' for its X account hack

#11
A lot of this should land on X. This is a high-profile, high-risk account. Allowing a password reset on these accounts without an additional check is sloppy. When people look at how many people you need to actually run X, things like this often get lost, and over time, they degrade trust in the service.

Re: US SEC blames 'SIM swapping' for its X account hack

#12

In my country, carriers are allowed to cancel your SIM card if you don't use it for a couple of months, then give the number to some other, new customer. It's a nightmare since you can lose your accounts and even the debit card is tied to a phone number to make online payments. I wanted to swap providers but I had to keep the old SIM active in a phasing-out stage...

It happens in many (if not all countries) and in some it happens surprisingly fast.

Re: US SEC blames 'SIM swapping' for its X account hack

#14
post #8

Earlier quoted context omitted.

You don't have to give true answers to security questions, FWIW.

Yep. All of my answers are GUIDs that I keep track of in 1Password.

I have read a suggestion that one should pick real (but randomly generated) words because, where it is possible to call the company that maintains your account, an attacker might claim that the recovery answer is a series of random characters, and there is a chance that the employee will accept this and allow the attacker access to the account.

Re: US SEC blames 'SIM swapping' for its X account hack

#15
post #8
post #5

Earlier quoted context omitted.

Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")

You don't have to give true answers to security questions, FWIW.

I thought this was a good strategy too until some one said that a customer service rep once asked him one of the questions over the phone and, lacking his backed up security questions at hand, he just said "it is a bunch of random characters" and was let through...

Probably the best bet is using a passphrase here but it might not be fool proof.

Re: US SEC blames 'SIM swapping' for its X account hack

#16
post #8

Earlier quoted context omitted.

You don't have to give true answers to security questions, FWIW.

I thought this was a good strategy too until some one said that a customer service rep once asked him one of the questions over the phone and, lacking his backed up security questions at hand, he just said "it is a bunch of random characters" and was let through... Probably the best bet is using a passphrase here but it might not be fool proof.

I've started to make up answers that could be accurate, but aren't obvious / the first thing someone would guess. For example, if the question is "where were you born?", I pick a random city.

Re: US SEC blames 'SIM swapping' for its X account hack

#17
post #5
post #4

Earlier quoted context omitted.

This is one of the reasons that I try to avoid giving companies my number. I'm always worry that they will decide that it is a valid recovery mechanism for my account. (Either that it is required locking me out or that it is sufficient allowing takeover)

Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")

How about no alternatives? The password being the only authentication mechanism.

Re: US SEC blames 'SIM swapping' for its X account hack

#19

A lot of this should land on X. This is a high-profile, high-risk account. Allowing a password reset on these accounts without an additional check is sloppy. When people look at how many people you need to actually run X, things like this often get lost, and over time, they degrade trust in the service.

Wouldn't it be more reasonable that government agencies treat their accounts as high risk and implement proper security measures themselves? Why should X use their manpower for special treatment to SOME of their users? If anything they should educate ALL users to use proper security, but the blame is entirely on the SEC. Don't be ridiculous.

The article also mentions that:

> The SEC also said that, six months prior to the attack, staff had removed an added layer of protection, known as multi-factor authentication (MFA), and did not restore it until after the Jan. 9 attack.

So they removed MFA for some reason. How should X handle a situation like that?

Re: US SEC blames 'SIM swapping' for its X account hack

#20

A lot of this should land on X. This is a high-profile, high-risk account. Allowing a password reset on these accounts without an additional check is sloppy. When people look at how many people you need to actually run X, things like this often get lost, and over time, they degrade trust in the service.

Wouldn't it be more reasonable that government agencies treat their accounts as high risk and implement proper security measures themselves? Why should X use their manpower for special treatment to SOME of their users? If anything they should educate ALL users to use proper security, but the blame is entirely on the SEC. Don't be ridiculous. The article also mentions that: > The SEC also said that, six months prior t…

> Why should X use their manpower for special treatment to SOME of their users?

Because X wants to continue to be a trusted platform. The more account takeovers there are, the more people start to doubt what authoritative sources say on X, and the less they use X.

> How should X handle a situation like that?

Flag high-risk accounts to go through extra verification because the cost of not doing it is high.

Post reply on HN