◇ 0xNull

← Search the archive · Browse this month

John McAfee · archived post

@bsgreenb @jack SIM swap is the simplest of all social engineering hacks. Take over your phone number, change your password ... they are in. Never submit your phone number for 2FA. period.

74 likes · 20 reposts at capture Original source ↗

Other archived McAfee posts in this conversation

Up to 100 posts; this is not necessarily the complete thread or the other participants’ replies.

THE TWITTER HACK I may be crazy, but I'm still the founder of the World's largest computer security firm, and I'm telling you: 2 factor authentication is Twitter's worst security threat. It exposes users to the trivial SIM Swap hack, which @Jack was a victim of. Wake up Jack! https://t.co/c16RWi52ku

Media was attached; images and videos are not mirrored in this edition.

2,158 likes · 481 reposts at capture Original source ↗
Reply to @finch_rfoll

@finch_rfoll @jack Peaple actually BELIEVE 2 factor authentication is more secure. What the https://t.co/SpijABdNuw wrong with this world?

57 likes · 8 reposts at capture Original source ↗
Reply to @su_xcode

@su_xcode @jack Use Google.

1 likes · 0 reposts at capture Original source ↗
Reply to @AlexKosa1

@AlexKosa1 @jack Just us a password. A hundred times more secure than using two factor authentication.

54 likes · 11 reposts at capture Original source ↗
Reply to @fullfrankchan

@full8chan @jack Two factor authentication is the worst security solution ever suggested.

92 likes · 20 reposts at capture Original source ↗
Reply to @matthewbabula

@matthewbabula @jack Refuse to give your phone number. Period.

25 likes · 6 reposts at capture Original source ↗
Reply to @idiot_salad

@idiot_salad @jack It's the most stupid idea ever conceived.

18 likes · 1 reposts at capture Original source ↗
Reply to @imnotshreyas

@imnotshreyas @jack Just a simple password.

0 likes · 0 reposts at capture Original source ↗
Reply to @LongBeachOGKush

@LongBeachOGKush @jack Din't guve your phone number to Twitter.

9 likes · 1 reposts at capture Original source ↗
Reply to @DarkNodeGuru

@DarkNodeGuru @jack Just a password . 2 factor is no security at all.

12 likes · 1 reposts at capture Original source ↗
Reply to @shawn_elbaz

@shawn_elbaz @jack Yes, but Twitter still supports 2 factir authentication. It is a huge security hole.

3 likes · 1 reposts at capture Original source ↗
Reply to @TreyWozzz

@TreyWozzz @jack Two factor is truvial to hack. Just a well thought out password is a million times safer.

32 likes · 3 reposts at capture Original source ↗
Reply to @IzzyGayeDrag

@IzzyGayeDrag @jack Yes!!!!

3 likes · 0 reposts at capture Original source ↗
Reply to @vivekdevops

@214vivek @jack Just never, ever give a company your phone number if it can be used to authenticate you. Any idiot can socially engineer your phone company and take your number.

12 likes · 1 reposts at capture Original source ↗
Reply to @erock23175

@erock23175 @jack Companies like Twitter have little understanding of the nuances of security. They listen to marketers and the media; they copy other companies who know no more than themselves, and they hire their security experts, not from the ranks of those on the front lines, but from academia

83 likes · 16 reposts at capture Original source ↗
Reply to @officialmcafee

Just never give any company your phone number if that number is going to be used to authenticate you. A 12 year old could socially engineer your phone company and take your number from you. It is the simplest of all social engineering hacks. Are you listening @Jack?

1,014 likes · 168 reposts at capture Original source ↗
Reply to @ConcreteJungel

@ConcreteJungel @jack Because he used his phone number in Twitter's 2FA. Only someone who does not understand computer security would do simething so naive.

9 likes · 1 reposts at capture Original source ↗
Reply to @WGTM19

@WGTM19 @jack Yes

7 likes · 0 reposts at capture Original source ↗
Reply to @xstvstr

@xstvstr @jack Just a goid password. Nothing is safer

5 likes · 0 reposts at capture Original source ↗
Reply to @AnthonyBxxx

@AnthonyBena @jack I somehow doubt it.

2 likes · 0 reposts at capture Original source ↗
Reply to @mac_nest

@mac_nest @jack Just use a good password and keep it private.

19 likes · 2 reposts at capture Original source ↗
Reply to @BuIIish

@BTC_Bullish @jack J6st a goid password is a million times better.

2 likes · 1 reposts at capture Original source ↗
Reply to @Joemanog

@JoelNog49985732 @jack No!!! It's the same!!!!!!!

3 likes · 1 reposts at capture Original source ↗
Reply to @GamingTooLong

@GamingTooLong @jack I know I am

3 likes · 0 reposts at capture Original source ↗
Reply to @FFairing

@FFairing @jack Just a good password. Nothing is more secure.

10 likes · 0 reposts at capture Original source ↗
Reply to @carliche1on1

@carliche1on1 @jack Anything other than your phone number. A goid passeord and nothing else is excellent security.

7 likes · 2 reposts at capture Original source ↗
Reply to @jajajavi75

@jajajavi75 @jack N8. J6st choise a good password and kerp it private.

0 likes · 0 reposts at capture Original source ↗