Live data from Hacker News

Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

nytimes.com

291–300 of 312 posts

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#291
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

I don't like being limited to 2FA using SMS. As soon as your phone isn't available, you're out of luck :P

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#292
post #286

Earlier quoted context omitted.

There's an MVNO owned by the Canadian ISP tucows called Ting, I used them for my primary mobile service for some time (I would still but I wanted access to Verizon's 700 and 800 Mhz bands for better coverage at my residence so I switched). Anyhow last time I checked they've since added several awesome (and self configurable via their account dashboard) features like multi factor auth settings for # porting, comprehen…

> There's an MVNO owned by the Canadian ISP tucows called Ting, I used them for my primary mobile service for some time (I would still but I wanted access to Verizon's 700 and 800 Mhz bands for better coverage at my residence so I switched). Anyhow last time I checked they've since added several awesome (and self configurable via their account dashboard) features like multi factor auth settings for # porting, compreh…

Tucows has been terrible in handling a client of mine's issues, their domain has no SPF or DKIM, and thus their email is unreliably making it to customer's inboxes.

If anyone has pointers on how to get a domain & email address that are both bought & hosted with Tucows up to snuff with the email security standards of yesteryear (SPF & DKIM), I would really appreciate it!

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#293

Please do not allow people to call SMS 2FA. For it to be 2FA, it must be: something I know alone, something I possess alone, something I am alone. Otherwise, it's just another account identifier (and likely spoof-able). SMS and phone numbers are none of these. In same vein, I wish security questions would die in a fire. Always treat them like additional passwords: use nonsensical words and store them in your password…

Be careful with nonsense in those security question answers. I've hear many are plain text and if you tell the rep, "it is just nonsense," they can say "yup, sounds good."

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#294
post #146

Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…

I don't like being limited to 2FA using SMS. As soon as your phone isn't available, you're out of luck :P

Just get a Google phone number. My Google phone number is secret and non-port-able.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#295

This could be stopped easily by making cell phone companies liable > Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T to switch a phone number to a new device that is under their control. > Hackers can get the codes by bribing phone company employees. How hard is it to insist on someone coming down to a store and submit several forms of identification to get a new SIM? And make mul…

But cell phone companies never opted into being used as security authenticators for other parties.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#296
post #227

Earlier quoted context omitted.

My experience is that after you give your phone number to most companies it effectively becomes a single factor: it's trivial to get them to change passwords with that alone. AFAICT, the only protection is to not give them your phone number in the first place.

> "the only protection is to not give them your phone number in the first place." That has its own risks. If you don't provide it to google and your account gets hacked, it's extremely hard to get it back. (My wife lost her original gmail account that way about 2 years ago. And of course there was no way to get any live support to try & fix it) Basically if you don't provide your number, you're more open to the more…

I've read of many cases of folks losing access to their personal Google account through no fault of their own, and winding up helpless to get it back. Almost happened to me after I was victim of a SIM Swap.

From the article, even the Twitter CEO has this problem:

While he has managed to get back his social media accounts, he has not regained access to two Google email accounts that held years of communications.

If anyone with directional authority at Google is out there: It would be really decent of you to provide some means of customer service for consumers stuck in this catch-22.

I can't accept there's no reasonable way to perform an identity confirmation beyond the laughably limited self-help measures currently in place. If it's a matter of economics, make it pay-per-use.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#298
post #270

Earlier quoted context omitted.

It's always kindof annoyed me they don't offer a u2f auth mechanism. Can't be that hard for a company of that size.

they do https://www.yubico.com/works-with-yubikey/catalog/twitter/

Hey, nice. Setting this up now. They didn't have it last time I checked.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#299

Earlier quoted context omitted.

It's 1 FA authentication because all you need is the phone to access the account. The password is irrelevant since all you need is access to the reset code that is sent via SMS. However, since you don't really even need access to the phone and can easily social engineer access to messages sent to the phone, it's not really a full one factor.

Using your logic, doesn't the ability to social engineer access to a password make passwords less than 1 FA as well?

Suppose you mistype your password and get a page saying "wrong password, log in anyway?" You click yes and are logged in to your account. Would you consider that account to be password-protected?

To me, a second factor that can bypass the first factor is exactly the same as this situation. Being able to hack your way into an account is a different issue.

Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’

#300
post #258

Earlier quoted context omitted.

It may very well be bad in absolute terms but compared to a single weak password it’s a huge improvement. I would bet on “log in with phone number” being better than “log in with password” across a population any day.

It's less secure than even passwords. Beyond SIM card cloning, I could sit behind a target, initiate a SMS auth, and simply wait for the guy to look at his phone. Most of the time it will pop up right on the front screen even if locked. If he misses it, I just wait for him to unlock the phone and look at his SMS. How would you like it if passwords just popped up visible to all on your phone?

I'm usually the one on my phone, and when I'm not the user I'm almost always aware of who the user is and I've granted them permission to access the device. The level of security cannot be not objectivly measured across all threat surfaces or catagories of potential bad actors.

The parent poster said "login with phone number" but that should be understood as login with a one time password by demonstating access to the receiving end of a fairly private and relatively difficult to intercept communication channel (physically controlling the client registered to receive messages destined for your phone number on the SS7 network). The authentication factor effectively becomes something have (your phone) whereas a password is something you know which allows for a much larger pool of potential bad actors (with a realistic means of gainig access).

SMS factor works more like a physical key your in possesion of that can be used to set a new combination (secret/password) for future access. In practice, combinations (passwords) are forgotten much more often than keys (phones) are lost or compromised.

Post reply on HN