https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo... NIST has said that 2FA via SMS is bad and awful for at least 3 years now. Can we knock it off, already? This won’t stop SIM swaps, but it will blunt their impact by rather a lot.
Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
171–180 of 312 posts
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#172https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo... NIST has said that 2FA via SMS is bad and awful for at least 3 years now. Can we knock it off, already? This won’t stop SIM swaps, but it will blunt their impact by rather a lot.
The problem is when companies implement 1FA over SMS and call it “2FA.” That is a catastrophically had idea, and unfortunately it confuses people into thinking that 2FA over SMS is somehow dangerous.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#173Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#174> Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T Those seem like excellent litigation targets, and I’m surprised that that fact alone hasn’t fixed this bug. Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves.
> Dorsey should sue and sue and sue and not settle and get these companies to unfuck themselves. If you are a captain of a ship that sees an out of control oil tanker heading for it, the solution is not to sue the oil tanker owners, rather it is to get out of its way which in Jack's case should be ordering an immediate implementation of a non-SMS 2FA
A.2b. "In construing and complying with these rules due regard shall be had to all dangers of navigation and collision and to any special circumstances, including the limitations of the vessels involved, which may make a departure from these rules necessary to avoid immediate danger"
Basically, if obeying the other rules mean you'll get hit by an oil tanker, Rule 2b says ignore those other rules so that you don't get hit by an oil tanker. So yeah, Jack ought to order his engineers to go fix this.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#175While companies definitely need to move away from SMS two factor it’s so entrenched (and simple) that more is needed. The government agencies that setup the mobile number portability system need to realise the seriousness of this flaw and allow a “Never transfer my Number” flag to be set in their databases. Until then even the lowest rung service desk agent at any telco has the ability to transfer numbers. A system l…
> “Never transfer my Number” flag what if you actually want to transfer your number?
This is common for many telcos, banks, etc.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#176Earlier quoted context omitted.
There is no universally accepted second factor. * SMS (and automated voice call) are bad for people who live in areas with poor phone coverage, people with international phone numbers, and people who want good security. * TOTP is bad for people who don't have smartphones. * FIDO U2F is bad for people who don't have $20, safari/iOS users, and people whose devices don't have USB. * Vendor-specific apps are bad for peop…
> * SMS (and automated voice call) are bad for [...] people with international phone numbers Why is that? I'm maybe spoiled by my surroundings (Poland and Europe in general), but receiveing SMS text is free abroad. While using dataplan generally is not, so SMS is cheaper (free) as a second factor if you travel a lot.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#177https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo... NIST has said that 2FA via SMS is bad and awful for at least 3 years now. Can we knock it off, already? This won’t stop SIM swaps, but it will blunt their impact by rather a lot.
2FA over SMS is fine. It’s not a terribly strong second factor, but it’s decent, and far better than nothing. The problem is when companies implement 1FA over SMS and call it “2FA.” That is a catastrophically had idea, and unfortunately it confuses people into thinking that 2FA over SMS is somehow dangerous.
The only reason I can see for why companies don't give the option for TOTP is to force people to hand over phone numbers so they can be tracked, and in the process make the system less secure.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#178Please do not allow people to call SMS 2FA. For it to be 2FA, it must be: something I know alone, something I possess alone, something I am alone. Otherwise, it's just another account identifier (and likely spoof-able). SMS and phone numbers are none of these. In same vein, I wish security questions would die in a fire. Always treat them like additional passwords: use nonsensical words and store them in your password…
Don't forget to change your birthday, mother's maiden name, fingerprint, and face regularly.
i make up random answers and write them down in the notes of my password manager. i always try and recommend others do the same.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#179Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
This would work to the thief's advantage in the case of physical device theft. The notification should definitely be a thing, but it should not be possible to cancel the process without talking to the carrier directly and verifying your identity to them.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#180Earlier quoted context omitted.
2FA over SMS is fine. It’s not a terribly strong second factor, but it’s decent, and far better than nothing. The problem is when companies implement 1FA over SMS and call it “2FA.” That is a catastrophically had idea, and unfortunately it confuses people into thinking that 2FA over SMS is somehow dangerous.
It's not fine, considering the zero cost of enabling TOTP 2 factor authentication. The only reason I can see for why companies don't give the option for TOTP is to force people to hand over phone numbers so they can be tracked, and in the process make the system less secure.