Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
Listen to a SIM-Jacking, Account-Stealing Ransom
11–20 of 95 posts
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#12I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?
I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#13Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
Most of these attacks are social engineering.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#14Earlier quoted context omitted.
I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.
did you try to port it without marking it as portable in Google Voice? I would be interested to see if that flag actually matters.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#15Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done.
The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just happen to call “2FA.”
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#16Earlier quoted context omitted.
Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.
There's many 2FA apps compatible with the TOTP and HOTP standards and they rarely, if ever require an update. Absolutely minimal 3rd party involvement, I'd say less than most web browsers these days as there really isn't a significant attack surface for the apps.
https://en.wikipedia.org/wiki/HMAC-based_One-time_Password_a...
https://en.wikipedia.org/wiki/Time-based_One-time_Password_a...
https://github.com/google/google-authenticator/wiki/Key-Uri-...
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#17Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#18Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#19Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
For paypal, texting is even the only 2FA option for non-US citizens. Baffling.
Paypal’s ceo is head of symantec’s board. Paypal must use symantec software wherever it is available, and their mfa is no exception.
This is still baffling as you say though, because symantecs mfa system does allow for other mechanisms.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#20Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as much 3rd party stuff, but I only keep my Google account (right now) for my old email address that's already forwarded to my new email address, Google Music, and Google Pay, so that doesn't affect me much. If you use a lot of 3rd party apps or get your mail via IMAP and the like, it's going to be more difficult.
A weird thing is that Google doesn't seem to allow for U2F key use without Advanced Protection turned on, which is puzzling to me.