4 ms·
From 'minimaxir: https://news.ycombinator.com/item?id=20842045 https://news.ycombinator.com/item?id=20842045 > It's worth noting the client is Cloudhopper: tha
by CiPHPerCoder 7y ago
From 'minimaxir: https://news.ycombinator.com/item?id=20842045 https://news.ycombinator.com/item?id=20842045
> It's worth noting the client is Cloudhopper: that has been compromised before.
> https://twitter.com/gruber/status/859857475146854402 https://twitter.com/gruber/status/859857475146854402
Looking up the hashtag the attackers used, I came across this blog post alleging the problem being AT&T's: https://www.treyexgaming.com/index.php/2019/08/26/how-the-same-hacker-has-hacked-over-10-content-creators/ https://www.treyexgaming.com/index.php/2019/08/26/how-the-sa...
Food for thought.
Regardless of whether the alleged source of insecurity is what happened here, SMS-based authentication was a mistake.
- minimaxir 7y agoAnother thread about Cloudhopper: https://twitter.com/psythor/status/1167528597671878657?s=21 https://twitter.com/psythor/status/1167528597671878657?s=21