Earlier quoted context omitted.
Using the account of probably one of the few trustworthy people in crypto probably helps.
Ironically, every SIM card is a cryptographic secure element, and it would've been ideal to do public key login. If you plug SIM card into desktop, you can actually do signing with it, and TLS authentication. I recall, only Nokia S60 series, and A200 had a SIM card API exposed to apps. Ios does not give you access to SIM, Android does only for system apps.
Vitalik Buterin reveals X account hack was caused by SIM-swap attack
41–50 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#42Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication. Scary stuff, had to give sooo much personal information over the course of months to recover a single account. Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?
You can even save the QR code and enroll a new device later if you want.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#43Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#44When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#45Earlier quoted context omitted.
I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication. Scary stuff, had to give sooo much personal information over the course of months to recover a single account. Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?
Every competent TOTP implementation has backup codes. Use one of your backup codes when your phone breaks. You did write them down like the site told you to, right? Even if a site doesn't offer backup codes, you can extract the TOTP secret from the QR code, or most authenticator apps, quite easily, and then write it down. It's more secure to only save the backup codes though since they have a limited number of uses,…
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#46Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#47Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell providers).
The state of "two-factor authentication" (a.k.a. something you're phished for and something you're social-engineered out of) and "identity verification" (a.k.a. "have a $80/month phone plan with these three companies or get lost”) in this country makes me really sad.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#48Ironically SMS 2fa is less safer than just using a password
As someone else pointed out, SMS based account recovery is the culprit.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#49Ironically SMS 2fa is less safer than just using a password
That's not true. SMS 2FA may be the weakest form of 2FA, but it cannot be weaker than just using a password, because you always also need the password. As someone else pointed out, SMS based account recovery is the culprit.
I mean, at least SMS-OTPs are one-time use, i.e. they don't facilitate a compromise if done correctly, but the "done correctly" part here is once again very load-bearing.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#50How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.
You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.