Solar Energy News  
INTERNET SPACE
Twitter CEO hack highlights dangers of 'SIM swap' fraud
By Rob Lever
Washington (AFP) Sept 4, 2019

Even with considerable security precautions in place, Twitter chief executive Jack Dorsey became the victim of an embarrassing compromise when attackers took control of his account on the platform by hijacking his phone number.

Dorsey became the latest target of so-called "SIM swap" fraud which enables a fraudster to trick a mobile carrier into transferring a number -- potentially causing people to lose control not only of social media, but bank accounts and other sensitive information.

This type of attack targets a weakness in "two factor authentication" via text message to validate access to an account, which has become a popular break-in method in recent years.

Twitter said Friday the account was restored after a brief time in which the attackers posted a series of offensive tweets.

But Ori Eisen, founder of Arizona-based security firm Trusona, which specializes in authentication without passwords, said the rapid fix should not be seen as an answer to the broad problem of SIM swap fraud.

"The problem is not over," Eisen said, noting that these kinds of attacks have been used to take over other high-profile social media accounts and for various kinds of fraud schemes.

Eisen said it's not clear how many people are attacked in this manner but that automated technology can create billions of calls that lure people into giving up information or passwords.

- Switching phones, or fraud? -

Some analysts say hackers have found ways to easily get enough information to get a telecom carrier to transfer a number to a fraudster's account, especially after hacks of large databases which result in personal data sold on the so-called "dark web."

"Mobile accounts' text messages can be hijacked by sophisticated hardware techniques, but also by so-called 'social engineering' -- convincing a mobile provider to migrate your account to another, unauthorized phone," said R. David Edelman, a former White House adviser who heads a cybersecurity research center at the Massachusetts Institute of Technology.

"It only takes a few minutes of confusion to make mischief like Dorsey experienced."

Thousands of these attacks have been reported in countries where mobile payments are common, including in Brazil, Mozambique, India and Spain.

Researchers at the security firm Kaspersky say security systems by many mobile operators "are weak and leave customers open to SIM swap attacks" especially if the attackers are able to gather information such as birth dates and other data.

In a recent blog post, Kaspersky researchers Fabio Assolini and Andre Tenreiro said some cases come from cybercriminals paying off corrupt employees of mobile carriers -- for as little as $10 to $15 per victim.

"The interest in such attacks is so great among cybercriminals that some of them decided to sell it as a service to others," the researchers wrote.

In Brazil, some criminals have taken over victims' WhatsApp accounts, using it to ask the person's friends for "urgent payment," Assolini and Tenreiro wrote.

- 'Ripe' for fraud -

"This is a pretty ripe avenue for fraud," said Joseph Hall, technologist at the Center for Democracy & Technology in Washington.

Hall said some carriers are using artificial intelligence to separate the legitimate SIM card replacements from fraud, but that this has not been universally deployed.

"I would blame the carriers for not having more robust ways to authenticate users," he added, while also calling on Twitter to offer better safeguards.

A faked tweet from the president or other prominent person could lead to "devastating consequences," such as a plunge in financial markets, Hall said.

"This kind of thing becomes hard to counteract, because even after the information comes out that it's a hoax, people may not believe it," he said.

The Dorsey case, Hall said, highlights the need for better forms of authentication, especially for large online platforms like Facebook and Twitter where messages can have an impact.

This could involve a physical key that plugs into a device or a software-based system such as Google Authenticator, Hall noted.

Eisen said that paradoxically, the push for longer and more complex passwords has led to greater use of insecure text messages for authentication.

"The security practitioners must come to terms with the fact that what used to work doesn't work now," he said.

"We need to look for solutions that are not so easily exploited by bad guys and are easy for people to adopt."


Related Links
Satellite-based Internet technologies


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


INTERNET SPACE
Apple loosens grip on iPhone repair work
San Francisco (AFP) Aug 29, 2019
Apple on Thursday said it will begin supplying parts and training to independent repair shops, offering more options to service for devices made by the California tech giant. The change of course came in the face of criticism that the iPhone maker's tight grip on where repair work could be done was unfair. The new repair program for out-of-warranty iPhone fixes is starting in the US and will eventually be expanded internationally, according to the California-based company. "We're making it e ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

INTERNET SPACE
Researchers use AI to plot green route to nylon

Dangerous wild grass will be used in batteries

Biomaterials smarten up with CRISPR

Protein factors increasing yield of a biofuel precursor in microscopic algae

INTERNET SPACE
NASA wants your help developing autonomous rovers

Psychosensory electronic skin technology for future AI and humanoid development

Russian humanoid robot boards space station after delay

Russia sends 'Fedor' its first humanoid robot into space

INTERNET SPACE
Colombia's biggest wind power portfolio purchased by AES Colombia

Growth of wind energy points to future challenges, promise

Scout obtains construction permit for 200MW Sweetland Wind Farm

E.ON announces 440 MW southern Texas windfarm

INTERNET SPACE
DLR at IAA New Mobility World 2019

Brussels mulls car use tax to cut traffic jams

Singapore to trial driverless buses booked with an app

Seoul to fine Volkswagen over 'illicit' emissions devices

INTERNET SPACE
Ammonia for fuel cells

First report of superconductivity in a nickel oxide material

Breakthrough enables storage and release of mechanical waves without energy loss

Physicists' study demonstrates silicon's energy-harvesting power

INTERNET SPACE
Slovenia PM backs building second nuclear reactor

Russia launches floating nuclear reactor in Arctic despite warnings

Seven bidders compete to fund Bulgaria nuclear project

US Govt issues new safety rules for launching nuclear systems into space

INTERNET SPACE
Macro-energy systems and the science of the energy transition

Oslo wants to reduce its emissions by 95 percent by 2030

Northern Irish pensioner thrives in off grid cottage

Global warming = more energy use = more warming

INTERNET SPACE
G7 pledges millions to fight Amazon fires

Heat, wildfires could alter Alaska's forest composition

DR Congo president warns over risk to forest reserves

Amazon rainforest absorbing less carbon than expected









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.