Earlier quoted context omitted.
U2F is great but everything is better than SMS.
Except SMS is better than nothing, right? Yes it's flawed. But it's a harder attack than simple password auth. An attacker has to to target an individual and know their phone number, and be able to spoof their phone.
Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
121–130 of 225 posts
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#122Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#123Earlier quoted context omitted.
Note that one time codes do not protect against phishing the same way U2F does (U2F is always bound to secure origin).
U2F is a kind of OTP, no?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#124Here's a guide for how to set up SMS-free two-factor authentication on your Gmail account. It will cost you $18; if that's a hardship, contact me. https://techsolidarity.org/resources/security_key_gmail.htm
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#125Earlier quoted context omitted.
SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…
You can get a pre printed card for cheap for 2fa. No need for RSA token
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#126Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…
Chip Authentication Programme (CAP) vulnerabilities https://www.cl.cam.ac.uk/research/security/banking/emvcap/ http://sec.cs.ucl.ac.uk/users/smurdoch/papers/fc09optimised....
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#127Earlier quoted context omitted.
SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…
Hopefully we'll get to a world where people keep a U2F key on their keychain, and use it for all their important logins.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#128My bank's 2FA literally comes on a piece of paper. A set of numbered codes, and the banking app/site tells me which code to use for any given transfer.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#129Earlier quoted context omitted.
Except it's not because they are very small, cheap devices that everyone has, generally a couple of. I have one at home, one at work, one in my bag, and everyone I know has one I could borrow if I needed one. Essentially all security is a trade off against convinience, this is, in my eyes, a no-brainer. It's barely any more effort and much, much more secure.
What? I can't think of a single person who uses this and I have lived here ten years. I once got one for a corporate account and it was atrocious with required plug-ins for ie
Picking two at random:
http://www.nationwide.co.uk/support/security-centre/internet...
http://personal.natwest.com/personal/ways-to-bank/online-ban...
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#130Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…