• Question for Woody on the Twitter hack.

    Home » Forums » AskWoody support » Windows » Windows 10 » Questions: Win10 » Question for Woody on the Twitter hack.

    Author
    Topic
    #2281399

    Hey Woody, in your article on the Twitter hack you said “In short, if you use mobile phone SMS to verify a log on to an account, you could get slammed.” Are you saying that if we have 2-factor auth going to our text on our phone that it is a bad thing? I read yesterday that turning on 2-factor was a good idea for Twitter accounts. Should I now turn it back off again? Thanks.

    PS. Any idea if and when the RSS feed will be working on ighome?

    Viewing 1 reply thread
    Author
    Replies
    • #2281468

      Your phone SIM can be hijacked, therefore your SMS will also be hijacked.
      This is not a trivial task so only high profile / value people are worth hijacking. Those people need to be careful, ordinary users can be more relaxed about this.

      cheers, Paul

      • #2281575

        I may not have fully understood the Twitter account spoofing/hijacking. But I do not believe that each of these high profile targets had their individual SIMs compromised. Rather a very large hole in the way Twitter handles account permissions allowed the interception of two-factor messaging without the account holder’s authorisation.

        Please help me understand better, if this impersonation required compromising each cellphone’s SIM.

        • #2281650

          Correct. It didn’t involve SMS at all.

    • #2281653

      The attack was internal to twitter and 2FA was turned off for accounts they wanted to hack.

      You should use 2FA for important accounts, like banking. Whether twitter counts as important…

      cheers, Paul

    Viewing 1 reply thread
    Reply To: Question for Woody on the Twitter hack.

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: