Hacker News new | past | comments | ask | show | jobs | submit login
Last night I was the victim of a SIM swap (reddit.com)
11 points by b0ner_t0ner on May 27, 2021 | hide | past | favorite | 6 comments



My point still stands. [0] [1]

Never ever use SMS verification. If you linked any account with your phone number, they can do a SIM swap attack and password reset your account, which is game over.

[0] https://news.ycombinator.com/item?id=26145985

[1] https://news.ycombinator.com/item?id=25762179


It's so shocking to me that this person is breathing a metaphorical sigh of relief already. If someone got into my E-mail, it would pretty much be game over. I would have to spend weeks (if not months or years) dealing with the potential fallout.

Also, aside from the regular problems that come from such a compromise, attackers can also begin sending E-mails from your address - in perpetuity - if they set up a Gmail alias.


How exactly did they get this person's email password, though? The SIM swap shouldn't be useful unless your first factor is compromised.


They probably didn’t; they probably just reset the password by authenticating using the phone. Using SMS as a second form of authentication is a really bad idea, and password resets of all kinds are usually the weakest point in your account security.


See, that's the real problem though. If you can reset your password via SMS, then SMS isn't a second factor, it's a single factor. And it's a far less secure single factor than a strong and unique password!


Absolutely! You should definitely check how your email provider handles password resets before you make your decision about what email provider to use.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: