Live data from Hacker News

Two-factor authentication is a mess

theverge.com

101–110 of 112 posts

Re: Two-factor authentication is a mess

#101
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

Why do you need a 2nd password when using TOTP? and if you don't then TOTP-1FA should be good enough...

Re: Two-factor authentication is a mess

#102

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

Good! That actually makes me feel really good about their policies. Weaker ID requirements result in people social-engineering their way into other people's accounts.

Your particular situation might be a bit more annoying since all you want to do is close the account, but how does AWS know that? For all they know, you could be a malicious person trying to delete someone else's data.

Re: Two-factor authentication is a mess

#103

Earlier quoted context omitted.

>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…

> It seems like every time I read about how SMS2FA was hacked it was done by some state level power... It seems to be a lot more vulnerable than that. Perhaps the biggest problem is that the phone companies do not treat your phone number as being a component of a 2FA system (and, to be fair, that was never the intent). This is from the linked article by Cody Brown, "How to lose $8k worth of bitcoin in 15 minutes with…

> It seems like every time I read about how SMS2FA was hacked it was done by some state level power... It seems to be a lot more vulnerable than that. Perhaps the biggest problem is that the phone companies do not treat your phone number as being a component of a 2FA system (and, to be fair, that was never the intent).

I think this sums up the problem.

BUT

SMS is likely the most convenient way for non geeks to use. And, as far as I am concern it seems only ( or especially ) Telecoms in US are vulnerable. In places like China / Hong Kong / Japan / Korea, you cant change your recovery code or what ever without your personal ID.

Re: Two-factor authentication is a mess

#104
post #55

Earlier quoted context omitted.

As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned." More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care? [1] https://blog.namecheap.com/account-security/

It's not that they don't care. It's that $CARE_AMOUNT That formula would immediately shift if a high profile website registered on Namecheap encounters an SMS hijacking.

So what's the meaning of caring then? If they aren't implementing the feature, it means that they don't care. It doesn't make a difference to me that they care a bit, just not enough to actually implement it.

Re: Two-factor authentication is a mess

#105
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

We should be just satisfied with TOTP, to be honest. It's just 6 digits by default, and unless you've got good anti-bruteforce protection, it can be broken in a matter of hours to days by just trying enough combinations. I'm sure Google and other big players do a good job of blocking these attacks, but would you trust every TOTP implementation of the web to get that right?

Re: Two-factor authentication is a mess

#106

Earlier quoted context omitted.

I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.

I'll take poor SMS based over none at all. https://lolware.net/assets/images/netregistry.png

I won't, SMS is worse than nothing.

Re: Two-factor authentication is a mess

#107
post #38

Earlier quoted context omitted.

Namecheap does have 2fa... https://www.namecheap.com/support/knowledgebase/article.aspx... Do you mean because they only support SMS based 2fa? Considering they have a drop down menu it's possible they just have not had time to develop the other options?

As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned." More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care? [1] https://blog.namecheap.com/account-security/

[deleted]

Re: Two-factor authentication is a mess

#108
post #42
post #36

Earlier quoted context omitted.

What annoys me most about using SMS for 2FA is that it's useless if you ever travel to another country and don't have global roaming enabled.

SMS receiving is free everywhere, it has nothing to do with data roaming and generic roaming - available on the network - has been free since I had a mobile phone (~17 years). Doesn't make it a the best option though.

You may be surprised to learn that in some countries (particularly the Land of the Free) the standard, for some weird reason, is for sending SMS to be free and receiving them to be paid.

Re: Two-factor authentication is a mess

#109
post #91

Earlier quoted context omitted.

I thought Authy was TOTP?

it's TOTP, but it backs up your TOTP codes in the cloud and will happily restore them to any device that can receive SMSes to your phone number.

a feature, that saved my ass after i forgot my phone in the rain (yeah, not smart).

I'm torn between the insecurity of the cloud and being thankful that all accounts could be restored with ease.

Re: Two-factor authentication is a mess

#110
post #76

Earlier quoted context omitted.

I've just moved my domains to porkbun.com instead, since they support TOTP and have equivalent or better prices.

I just buy my domain from AWS since I'm already using them for hosting. One less account to deal with and one less attack surface.

>one less attack surface

Yes, but your Amazon attack surface just got bigger.

Post reply on HN