Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

1–10 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#4
post #3

Doesn't Xitter require you to have a paid account to use SMS authentication? So one way to secure your account is to refuse to pay for Blue.

"A phone number is sufficient to password reset a Twitter account even if not used as 2FA"

This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#5
When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam!

I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still so effective. No need for an attacker to risk making $0 on a more involved attack when they can get easy cash like that, I guess.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#6
post #4
post #3

Doesn't Xitter require you to have a paid account to use SMS authentication? So one way to secure your account is to refuse to pay for Blue.

"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever

Cool, a wild vector appeared.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#7
Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it.

[1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#8
post #4
post #3

Doesn't Xitter require you to have a paid account to use SMS authentication? So one way to secure your account is to refuse to pay for Blue.

"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever

I just tried it on my now account. It asks for the account's username, phone number, email and then sends an email to the email address. Perhaps he didn't add an email address to his Twitter account?

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#9
I thought T-Mobile significantly cracked down on SIM-swapping internally so this couldn't happen again?

I know there's still no patch for human stupidity, but I really am concerned that T-Mobile still apparently seems to be the carrier of choice for easy SIM-swap attacks.

Post reply on HN