Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

141–150 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#141
post #100
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

The problem is when a phone number is the only factor that is used. That is what Twitter allows. If you truly use an SMS only as a second factor - and don't provide recovery options only by phone, like Twitter - then you have much less of a problem. In that case, a compromised phone number does not give the attacker the password or other factor. SMS is still extremely imperfect for 2FA, but it's still a lot better th…

> The problem is when a phone number is the only factor that is used. That is what Twitter allows.

that's not true. i have twitter 2FA inside authy[0] AND inside twitter's own app (it's hidden -- at least on android -- under setting and privacy -> account -> security -> login verification -> Login Code Generator)

[0] https://authy.com/guides/twitter/

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#142
post #3

If we want to authenticate a user, what is the best way to do it? best: a great balance between convenience, security and cost. Lately, it bothers that we cannot be sure that we are interacting with real people or the people that we are interacting with are not the same people with different accounts.

In some cases the account officially belongs to a company so the real person is only an agent in any case.

Also there are attorneys: a real person acting on behalf of a different real person. Currently many financial institutions seem to be unable to cope with this situation. When talking to a call centre, in practice it's much easier, and probably not illegal, for you to impersonate the person you're representing rather than attempt to explain the actual legal situation to the confused employee in Bangalore.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#143
post #103
post #86

Earlier quoted context omitted.

eavesdrop ? the WhatsApp I use agrees to work only on one phone, if yo move it it stops working on the original.

Is that not per-phone number? The cloned SIM would have the same one

but then the original owner will be notified about that while eavesdropping is "secretly listen to a conversation"

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#144
post #103
post #86

Earlier quoted context omitted.

eavesdrop ? the WhatsApp I use agrees to work only on one phone, if yo move it it stops working on the original.

Is that not per-phone number? The cloned SIM would have the same one

Is that allowed by the network? Can 2 devices share one number?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#146
Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process.

Number porting should require an SMS to the existing SIM with the ability to respond NO to cancel the process and flag the request as fraud (e.g. whoever made the request on the carrier side should be flagged, to fish out compromised support reps).

A mandatory time delay (12 or 24 hours) could be imposed. This would slightly inconvenience people who lost their SIM and need to setup a new one. This seems like a reasonable cost/security trade-off for losing a SIM card. Mission critical numbers should be implemented as forwarding services that separately route to the cell phone anyway, so “this number must be live right now” is not a reasonable excuse to compromise everyone’s security.

You could also mandate a short delay (4 business hours) and high value targets that sometimes take international flights could opt-in to longer (24/48 hour) waiting periods. The expectation should be that 99% of users keep the default.

Using SMS as a second factor has trade-offs. This isn’t news because every single authentication mechanism presents a unique set of trade-offs in terms of cost of provisioning, ease of use, possibility of loss, possibility of spoofing, replay, etc.

SMS is an extremely powerful authentication factor due to its availability, cost, and accessibility. It’s worth it to shore up protection against SIM swaps not in the least because it would improve the security posture of SMS as an authentication factor. It would still not make SMS perfect. Nothing is.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#147
post #7

While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…

I thought number portability was only a between carriers thing. SIM swapping doesn't cross the carrier border usually so would setting that flag actually fix anything?

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#148
post #99

Earlier quoted context omitted.

What's the universally accepted alternative?

There is no universally accepted second factor. * SMS (and automated voice call) are bad for people who live in areas with poor phone coverage, people with international phone numbers, and people who want good security. * TOTP is bad for people who don't have smartphones. * FIDO U2F is bad for people who don't have $20, safari/iOS users, and people whose devices don't have USB. * Vendor-specific apps are bad for peop…

> TOTP is bad for people who don't have smartphones.

This only true if you're willing to define everything beyond the most mundane "dumb phone" as a "smartphone". One of my friends has a long list of exciting problems which ends up meaning he doesn't own what anyone these days would consider a smartphone.

But it's not like he uses carrier pigeons. His phone does have a (monochrome) screen and is quite capable of running software, it's just the software has to be crappy mobile Java from last century. However TOTP is trivial, you probably can't do it in your head but you definitely can do it in a Java 1.0 implementation and so sure enough it can be run on those phones.

On a brand new Pixel of course you vaguely wave your phone near the screen, it reads a QR code and sets everything up, he has to instead laboriously transcribe a secret value using T9 input, but the same effect is achieved - a changing code that he can input to prove he knows the shared secret.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#149
(googler, opinions are my own)

This is one thing nice about Google Fi, Sim swap attacks aren't possible. Your phone number with Fi what is tied to your Google account, the only way to get a Fi phone number on a new phone is to sign into the Google account. So if you protect your account with good 2FA, your number is safer than any cell phone company (at least in the US).

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#150

Disappointed they didn’t do something like use it to manipulate the stock market. Then it would have got much more coverage and something might actually get fixed as a result.

It likely would have made tracking the perpetrators easier if there was a paper trail in the markets.
Post reply on HN