Live data from Hacker News

US SEC blames 'SIM swapping' for its X account hack

reuters.com

1–10 of 21 posts

Re: US SEC blames 'SIM swapping' for its X account hack

#2
"Monday's statement also said that due to difficulties accessing the account, SEC staff had asked X Support in June of 2023 to disable MFA, which can offer added protection against unauthorized access."

I suppose life is about to get way more difficult for those who found accessing X with MFA too difficult ...

Re: US SEC blames 'SIM swapping' for its X account hack

#3
From the sounds of it they had disabled MFA since it was to annoying, but the phone number was still setup to be able to do a password recovery (probably by default I'm guessing) so really the phone number was the only thing required to get in.

I wonder if MFA even was at play here. If you can reset the password with nothing but a SIM-swapped phone number then the password was basically vestigial. And if you were using text for 2FA then really it was single factor the whole time even though you might not realize it.

Re: US SEC blames 'SIM swapping' for its X account hack

#4
post #3

From the sounds of it they had disabled MFA since it was to annoying, but the phone number was still setup to be able to do a password recovery (probably by default I'm guessing) so really the phone number was the only thing required to get in. I wonder if MFA even was at play here. If you can reset the password with nothing but a SIM-swapped phone number then the password was basically vestigial. And if you were usi…

This is one of the reasons that I try to avoid giving companies my number. I'm always worry that they will decide that it is a valid recovery mechanism for my account. (Either that it is required locking me out or that it is sufficient allowing takeover)

Re: US SEC blames 'SIM swapping' for its X account hack

#5
post #4
post #3

From the sounds of it they had disabled MFA since it was to annoying, but the phone number was still setup to be able to do a password recovery (probably by default I'm guessing) so really the phone number was the only thing required to get in. I wonder if MFA even was at play here. If you can reset the password with nothing but a SIM-swapped phone number then the password was basically vestigial. And if you were usi…

This is one of the reasons that I try to avoid giving companies my number. I'm always worry that they will decide that it is a valid recovery mechanism for my account. (Either that it is required locking me out or that it is sufficient allowing takeover)

Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")

Re: US SEC blames 'SIM swapping' for its X account hack

#6
In my country, carriers are allowed to cancel your SIM card if you don't use it for a couple of months, then give the number to some other, new customer.

It's a nightmare since you can lose your accounts and even the debit card is tied to a phone number to make online payments.

I wanted to swap providers but I had to keep the old SIM active in a phasing-out stage...

Re: US SEC blames 'SIM swapping' for its X account hack

#7

"Monday's statement also said that due to difficulties accessing the account, SEC staff had asked X Support in June of 2023 to disable MFA, which can offer added protection against unauthorized access." I suppose life is about to get way more difficult for those who found accessing X with MFA too difficult ...

What's somewhat comical is that the federal government has a PKI system (common access cards [1]) that Login.gov supports, but SEC folks couldn't manage a Yubikey or similar secure hardware authenticator for their Twitter/X account.

[1] https://www.cac.mil/common-access-card/

Re: US SEC blames 'SIM swapping' for its X account hack

#8
post #5
post #4

Earlier quoted context omitted.

This is one of the reasons that I try to avoid giving companies my number. I'm always worry that they will decide that it is a valid recovery mechanism for my account. (Either that it is required locking me out or that it is sufficient allowing takeover)

Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")

You don't have to give true answers to security questions, FWIW.

Re: US SEC blames 'SIM swapping' for its X account hack

#10
post #8
post #5

Earlier quoted context omitted.

Which worse? Your SIM as an alternate password, or public information about you being your alternate password? ("Security" questions and "identity verification")

You don't have to give true answers to security questions, FWIW.

Yep. All of my answers are GUIDs that I keep track of in 1Password.
Post reply on HN