Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Finally got back my T-mobile account (yes, it was a sim swap, meaning that someone socially-engineered T-mobile itself to take over my phone number).
48 replies
178 recasts
563 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Main learning re twitter was: > A phone number is sufficient to password reset a Twitter account even if not used as 2FA. Can completely remove phone from Twitter. I had seen the "phone numbers are insecure, don't authenticate with them" advice before, but did not realize this
10 replies
17 recasts
87 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
I don't remember when I *added* the number; my guess is that it was required to sign up for twitter blue.
4 replies
2 recasts
50 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Anyway, glad to be on farcaster, where my account recovery can be controlled by a good wholesome ethereum address :)
19 replies
66 recasts
278 reactions

aferg pfp
aferg
@aferg.eth
Glad you’re back. Sorry you got sim swapped :-( Are T-Mobile going to add some extra protection to your mobile to prevent this going forward? I am anxious that mobile companies are woefully unprepared to curtail social engineering…especially if AI can simulate a speaker since many telecoms use voice for auth
1 reply
0 recast
7 reactions

↑ j4ck 🥶 icebreaker.xyz ↑ pfp
↑ j4ck 🥶 icebreaker.xyz ↑
@j4ck.eth
👏👏👏
0 reply
0 recast
3 reactions

antimo pfp
antimo
@antimofm.eth
Welcome back
0 reply
0 recast
1 reaction

Robin A. pfp
Robin A.
@degenroot.eth
Hear hear!
0 reply
0 recast
0 reaction

Dave Pazdan pfp
Dave Pazdan
@paz
prior to this, did you tell tmobile no port, no sim swap under any circumstances on your account?
0 reply
0 recast
0 reaction

‎ pfp
@mpryor.eth
🤧 that was wild
0 reply
0 recast
0 reaction

Jackson 🎩🍖 pfp
Jackson 🎩🍖
@jacks0n
who woulda thought a seed phrase could feel so comfy and safe
0 reply
1 recast
6 reactions

frdysk pfp
frdysk
@fcpro.eth
+1 for ethereum and farcaster 🍸
0 reply
0 recast
1 reaction

Tempe Techie pfp
Tempe Techie
@tempetechie.eth
Yet another reason to ditch web2 social 🤘
0 reply
1 recast
0 reaction

Project7 pfp
Project7
@project7
Yay! That's so true :D
0 reply
0 recast
0 reaction

okokk.base.eth pfp
okokk.base.eth
@abcd
品味不错
0 reply
0 recast
0 reaction

WholesomeCrypto pfp
WholesomeCrypto
@rudy
It's all about being wholesome in crypto. Glad you recovered your number and account.
0 reply
0 recast
0 reaction

Lee pfp
Lee
@0xcyclone
Good to have you on here, Welcome
0 reply
0 recast
0 reaction

Mohamad pfp
Mohamad
@mohamad
That’s so cool
0 reply
0 recast
0 reaction

Jeeg 👾 pfp
Jeeg 👾
@jeeg
yes
0 reply
0 recast
0 reaction

Lukas pfp
Lukas
@lukaslevert.eth
X sucks. Long live farcaster. Also for web2 stuff in the interim, reminder for everyone else here to get some hardware security keys (Yubico). Phone 2FA is clearly too vulnerable.
0 reply
0 recast
0 reaction

dev pfp
dev
@photoshop.eth
Scary stuff 😮‍💨 maybe elon should integrate ENS too
0 reply
0 recast
0 reaction

0xCuttlefish pfp
0xCuttlefish
@0xcuttlefish
So if I'm understanding correctly, your account had a mobile number associated, but it was not enabled for 2FA, and even though you weren't using SMS 2FA the hackers were still able to take over via the mobile number? Is that correct? If so I really dislike that Twitter Blue requires a mobile number to sign up.
0 reply
0 recast
0 reaction

Po pfp
Po
@thepanda
Welcome to the World of Decentralised! 🤟
0 reply
0 recast
0 reaction