US SEC blames 'SIM swapping' for its X account hack
reuters.com
reuters.com
I wonder if MFA even was at play here. If you can reset the password with nothing but a SIM-swapped phone number then the password was basically vestigial. And if you were using text for 2FA then really it was single factor the whole time even though you might not realize it.
Probably the best bet is using a passphrase here but it might not be fool proof.
I suppose life is about to get way more difficult for those who found accessing X with MFA too difficult ...
The article also mentions that:
> The SEC also said that, six months prior to the attack, staff had removed an added layer of protection, known as multi-factor authentication (MFA), and did not restore it until after the Jan. 9 attack.
So they removed MFA for some reason. How should X handle a situation like that?
Because X wants to continue to be a trusted platform. The more account takeovers there are, the more people start to doubt what authoritative sources say on X, and the less they use X.
> How should X handle a situation like that?
Flag high-risk accounts to go through extra verification because the cost of not doing it is high.
You trust the source behind the account, and that varies based on who the account belongs to, not how many computer illiterate users got hacked. Any journalist worth their name will contact the source through official channels to confirm statements made on X.
It's a nightmare since you can lose your accounts and even the debit card is tied to a phone number to make online payments.
I wanted to swap providers but I had to keep the old SIM active in a phasing-out stage...
i also hate how social media companies use your number to build a social graph and show you other people who have your number. huge privacy risk