Earlier quoted context omitted.
hugely important point. helped a less-tech-savvy neighbor 'reset her skype' account that was tied to 'her phone number', only to find that the account bound to that phone number, which she had recently acquired, was publically searchable and connected with some sort of anime sex fetish subculture, presumably from a previous owner of that phone number.. she was using this phone / skype account for a job interview. nee…
Never really made any sense to me whatsoever why we all switched over from having to use phone numbers instead of email addresses as sign in over the past few years. I get why businesses want to harvest peoples phone numbers and phone books but you'd hope at least some would think of the implications to users first.
Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
251–260 of 312 posts
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#252Earlier quoted context omitted.
Never really made any sense to me whatsoever why we all switched over from having to use phone numbers instead of email addresses as sign in over the past few years. I get why businesses want to harvest peoples phone numbers and phone books but you'd hope at least some would think of the implications to users first.
Using phone numbers as authentication is a cheap and effective way to prevent spam, as well as track users with a unique ID.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#253Earlier quoted context omitted.
Using phone numbers as authentication is a cheap and effective way to prevent spam, as well as track users with a unique ID.
But phone numbers are not unique. They are regularly re-assigned to new customers.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#254Earlier quoted context omitted.
I'm not sure I would go that far - 1FA means you require either one or the other or both. But if you have neither you're out of luck. If you had parts of either, or a hint, maybe a previously used password works for "verifying your ID" then I'd call that 1/2FA
It's 1 FA authentication because all you need is the phone to access the account. The password is irrelevant since all you need is access to the reset code that is sent via SMS. However, since you don't really even need access to the phone and can easily social engineer access to messages sent to the phone, it's not really a full one factor.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#255Earlier quoted context omitted.
Most feature phones can also easily run a TOTP application (and have/do). There are J2ME TOTP applications that will run on hardware far back into the ancient past. There are all sorts of fun TOTP apps in the AdaFruit, Arduino, RPi hacking worlds. The algorithm is rather straightforward. The "hardest" part is the SHA1 hashing algorithm and people have written versions of that for just about every hardware under the s…
Just noticed the tab I had opened mentioning 6502 SHA1 hashing was to do it on old Tamagotchi hardware. Forgot that was also a 6502. Wonder if that person ever finished a TOTP Tamagotchi.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#256Earlier quoted context omitted.
You don't need a smartphone or 2FA device to generate TOTP codes, and in fact, can use applications like Bitwarden. SMS is obviously not adequate, or the Jack Dorsey wouldn't have been hacked.
Twitter doesn’t use 2FA over SMS. Dorsey’s hack doesn’t tell us anything about that.
Frustratingly, you can't enable TOTP without a phone number, and if you remove your phone number, you disable 2FA.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#257Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#258Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
SMS is only as good as the cell providers security, which has been shown over and over again to be terrible. It should never be used in any ongoing authentication.
I would bet on “log in with phone number” being better than “log in with password” across a population any day.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#259Earlier quoted context omitted.
That’s the problem. Twitter requires you to add a phone number (even if you sign up without one, eventually you’ll be locked out and requires to add one). Then, once you add a number to unlock your account you’re left exposed.
Can't you add a number, verify the account, then delete the number?
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#260Earlier quoted context omitted.
The problem is, I think a lot of these hacks have an internal connection. How much access do these 3rd party carrier stores have to transfer numbers?
It could be done remotely but only if the store had signed off that ID had been viewed and the port confirmed in person. Of course this could be gamed but an employee would need to put their name on the line to say they had met the person and viewed the ID
I can imagine however that an admin at a reasonably large business would receive several of these emails per day and may just reflexively click on them all. Note these emails are sent to the business account admin, not the end-user. I happen to be both so can see both sides of the process.
Edit: I should also add that I have never met this rep and so he has definitely not looked at my government ID. The process is secured only by receipt of email.