The CEO Got Locked Out of His Own House

The CEO Got Locked Out of His Own House

Tech News security sim-swap twitter two-factor-auth

So yesterday afternoon somebody hijacked Jack Dorsey's Twitter account and started blasting out racial slurs and a fake bomb threat against Twitter's own headquarters, all from the guy's personal, verified, ten-million-follower account. It lasted maybe twenty minutes before Twitter's security team wrestled it back under control, but twenty minutes is a long time when you're the CEO and your own product is being used to embarrass you in front of the entire internet. A group calling itself Chuckling Squad took credit. I don't know if that's the actual group of if it's just some kid who wants a group name to be famous, and honestly it doesn't matter much either way.

Here's the part that I can't stop thinking about, though. This wasn't some sophisticated zero-day exploit or a password leaked in a breach dump. As far as anyone's reported, it came down to Dorsey's phone number. Twitter still has this ancient feature, left over from literally 2006, where you can tweet by texting a short code. It's how the whole product started, back when "what are you doing" was the prompt and nobody had smartphones yet. Almost nobody uses it now. But it's still active, tied to your phone number, and if someone convinces your carrier to move your number onto a SIM card they control, congratulations, they can now tweet as you without touching a password at all.

That's a SIM swap, and it is not a new attack. Security people have been screaming about this for years. I remember writing about it here after the whole wave of crypto-wallet SIM swap thefts back in 2018, where people lost six figures in Bitcoin because some teenager social-engineered a T-Mobile rep into porting their number. The fix carriers keep offering is a PIN on your account, which is fine until the rep at the store just overrides it anyway because a customer is annoyed and it's faster to click yes than argue. I switched my own two-factor setup off SMS for anything that matters years ago, moved everything to an authenticator app, and I still get a little smug about it every time a story like this shows up. Maybe that's not a great look but its true.

What gets me is that this happened to the CEO of the company. Not some rando. The person who, in theory, has the most leverage to say "hey, maybe we should kill the SMS-tweet feature that's been an open door since the Bush administration." And it still bit him. There's something almost funny about it, in a bleak way, like watching a locksmith get locked out of his own house.

Twitter's response was to say they're disabling the ability to tweet via text for accounts in the US, which, fine, sure, but also: why did it take the CEO's account getting hijacked with a bomb threat for that to happen? These reports about the vulnerability of Twitter-via-SMS have been floating around for a while. I get that legacy features are hard to kill because someone, somewhere, in some country with spotty data coverage, actually still uses it. But there's a cost-benefit calculation there and I think they had it backwards for a long time.

I don't have a tidy fix to offer. Carriers keep failing at this because their incentive is speed of service, not security, and that's not going to change until it costs them real money. Turning off SMS-to-tweet for a service basically nobody uses is an easy call in hindsight. The harder problem, the actual number-porting-with-a-fake-ID-at-a-store problem, is still sitting there for the rest of us, unsolved, and it'll happen to somebody else's account by the weekend probably. If you've still got SMS as your two-factor on anything, your bank, your email, whatever, this is as good a nudge as any to go turn on an app-based code instead. It takes maybe ten minutes. I promise it's less annoying than explaining to your followers why you didn't actually mean any of that.

Anyway. Back to actually useful things this week, I've been messing with a Raspberry Pi 4 that finally showed up after being backordered for a month, more on that soon once I stop breaking the SD card image every other night.