Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

61–70 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#62
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

$700k in NFTs I recall. Isn't that more like $70?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#63
post #26

Earlier quoted context omitted.

Every competent TOTP implementation has backup codes. Use one of your backup codes when your phone breaks. You did write them down like the site told you to, right? Even if a site doesn't offer backup codes, you can extract the TOTP secret from the QR code, or most authenticator apps, quite easily, and then write it down. It's more secure to only save the backup codes though since they have a limited number of uses,…

Except Google. Google backup codes are near useless because a Google backup code will let you log in, but won't allow you to disable 2 factor or add a new 2 factor device - meaning if you ever lose a 2 factor device and have to use a backup code, there is no way to recover your account.

Really? I'd imagine you'd need two codes (one for the login, one for access to your 2FA settings), but not being able to recover at all using them seems horrible!

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#64
post #47

Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…

I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#65
post #16

Earlier quoted context omitted.

Just having a phone number added to Twitter means your account is at risk of being taken over with a sim-swap. This was not 2FA related AFAICT. Twitter also requires you to add a phone number, even on old accounts you can get locked out unless you add one.

Doesn't Twitter force you to add a phone number now?

As far as I remember they only use it for spam protection (i.e. the phone number serves as a moderate-level "proof of humanity"), but not for 2FA purposes (unless you pay for their premium service).

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#66
post #46

How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.

𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.

Looking at that tweet, I can't tell if it's a scam or just your regular cryptard NFT pump post.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#67
post #4

Earlier quoted context omitted.

"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever

> "A phone number is sufficient to password reset a Twitter account even if not used as 2FA " In other words, they don't have a 2FA system. They have a 1FA system, and the only factor is your phone number. This is a weird choice, since people are much more likely to know your phone number than they are to know your password.

If you have 2FA enabled, they can deny you access to your account, but they can't actually access it either (unless they also compromise your 2FA of course). That is, they can reset and change your password with only a phone number, but will still require a 2FA token to actually access the account.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#68

This makes me feel really good that the Canada Revenue Agency and most banks in Canada use SMS for second factor auth!

The EBA (the European banking regulator in charge of specifying the technical details of the PSD2 regulation, which covers secure cardholder authentication, among other things) also stated a while ago that only SMS-OTP is a "true" factor; Email-OTP isn't.

Ironically, my email account is so much better protected than my mobile phone number.

I'm trying very hard to believe that the SMS lobby (i.e. mobile phone operators, which earn multiple cents per inbound SMS in Europe, as well as our friendly SMS verification providers adding their markup on that) didn't exert some pressure on the regulators here...

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#69
post #46

How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.

𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.

And the "this is free for 24h" is just a red herring, to make it legitimate for people to speculate?

Still crazy that such a semi-anonymous scam got 700k, sounds like there's still a lot of money in crypto ready to gamble.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#70
post #4

Earlier quoted context omitted.

"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever

I just tried it on my now account. It asks for the account's username, phone number, email and then sends an email to the email address. Perhaps he didn't add an email address to his Twitter account?

I also experimented a bit. I was able to reset my own password only with phone access when 2FA was not enabled: in the reset password flow, I started with my phone number, was then asked for my username and email, and then I was presented with an option to send the reset code either to my email or to my phone number.

But, I then enabled 2FA (with an authentication app), and now when I try the flow again, I get to the screen for sending the reset code and I only have the email option left (but the screen still shows up as an extra step).

So, it's possible that when you have 2FA enabled you can no longer do it. Or, it's possible I've triggered some internal rules by resetting my password twice in a short span of time (and enabling 2FA as well) and they've bumped me to some kind of "extra verification" flow that disabled phone-based password reset.

Post reply on HN