Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Finally got back my T-mobile account (yes, it was a sim swap, meaning that someone socially-engineered T-mobile itself to take over my phone number).
50 replies
74 recasts
384 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Main learning re twitter was: > A phone number is sufficient to password reset a Twitter account even if not used as 2FA. Can completely remove phone from Twitter. I had seen the "phone numbers are insecure, don't authenticate with them" advice before, but did not realize this
11 replies
11 recasts
67 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
I don't remember when I *added* the number; my guess is that it was required to sign up for twitter blue.
3 replies
3 recasts
37 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Anyway, glad to be on farcaster, where my account recovery can be controlled by a good wholesome ethereum address :)
20 replies
54 recasts
246 reactions

Aaron Ferguson ๐ŸŽฉ pfp
Aaron Ferguson ๐ŸŽฉ
@aaronrferguson.eth
Glad youโ€™re back. Sorry you got sim swapped :-( Are T-Mobile going to add some extra protection to your mobile to prevent this going forward? I am anxious that mobile companies are woefully unprepared to curtail social engineeringโ€ฆespecially if AI can simulate a speaker since many telecoms use voice for auth
1 reply
0 recast
4 reactions

โ†‘ j4ck ๐Ÿฅถ icebreaker โ†‘ pfp
โ†‘ j4ck ๐Ÿฅถ icebreaker โ†‘
@j4ck.eth
๐Ÿ‘๐Ÿ‘๐Ÿ‘
0 reply
0 recast
4 reactions

accountless pfp
accountless
@accountless.eth
thank you for sharing. that dank sharping post was pretty good. i clicked the link.
0 reply
0 recast
3 reactions

Jackson ๐ŸŽฉ๐Ÿ– pfp
Jackson ๐ŸŽฉ๐Ÿ–
@jacks0n
who woulda thought a seed phrase could feel so comfy and safe
0 reply
1 recast
5 reactions

frdysk ๐Ÿฆ  pfp
frdysk ๐Ÿฆ 
@fufuprophet.eth
+1 for ethereum and farcaster ๐Ÿธ
0 reply
0 recast
1 reaction

Tempe.degen ๐ŸŽฉ pfp
Tempe.degen ๐ŸŽฉ
@tempetechie.eth
Yet another reason to ditch web2 social ๐Ÿค˜
0 reply
1 recast
0 reaction

antimo ๐ŸŽฉ pfp
antimo ๐ŸŽฉ
@antimofm.eth
Welcome back
0 reply
0 recast
1 reaction

Project7 โค๏ธ $chicken pfp
Project7 โค๏ธ $chicken
@project7
Yay! That's so true :D
0 reply
0 recast
0 reaction

Lukas pfp
Lukas
@lukaslevert.eth
X sucks. Long live farcaster. Also for web2 stuff in the interim, reminder for everyone else here to get some hardware security keys (Yubico). Phone 2FA is clearly too vulnerable.
0 reply
0 recast
0 reaction

@developer pfp
@developer
@dos.eth
Scary stuff ๐Ÿ˜ฎโ€๐Ÿ’จ maybe elon should integrate ENS too
0 reply
0 recast
0 reaction

Dave Pazdan pfp
Dave Pazdan
@paz
prior to this, did you tell tmobile no port, no sim swap under any circumstances on your account?
0 reply
0 recast
0 reaction

Matthew pfp
Matthew
@mpryor.eth
๐Ÿคง that was wild
0 reply
0 recast
0 reaction

0xCuttlefish pfp
0xCuttlefish
@0xcuttlefish
So if I'm understanding correctly, your account had a mobile number associated, but it was not enabled for 2FA, and even though you weren't using SMS 2FA the hackers were still able to take over via the mobile number? Is that correct? If so I really dislike that Twitter Blue requires a mobile number to sign up.
0 reply
0 recast
1 reaction

WholesomeCrypto pfp
WholesomeCrypto
@rudy
It's all about being wholesome in crypto. Glad you recovered your number and account.
0 reply
0 recast
0 reaction

Lee pfp
Lee
@0xcyclone
Good to have you on here, Welcome
0 reply
0 recast
0 reaction

Robin A. pfp
Robin A.
@degenroot.eth
Hear hear!
0 reply
0 recast
0 reaction

Mohamad pfp
Mohamad
@mohamad
Thatโ€™s so cool
0 reply
0 recast
0 reaction

Jeeg ๐Ÿ‘พ pfp
Jeeg ๐Ÿ‘พ
@jeeg
yes
0 reply
0 recast
0 reaction

Po pfp
Po
@thepanda
Welcome to the World of Decentralised! ๐ŸคŸ
0 reply
0 recast
0 reaction