SMS is not 2FA-secure
41–50 of 379 posts
Re: SMS is not 2FA-secure
#42HN seems to be getting a lot of these submissions lately where the question asked in the title is the same as the domain name. Sometimes the content of the page doesn't even answer the question. Feels like some kind of spammy PageRank manipulation going on. I'm happy to be wrong about this, but I wanted to see if anyone else has noticed. Maybe I'm just smoking crack waffles again.
It's a single-purpose domain name, so the Name of the domain is the same as the Name of the content on the domain.
Re: SMS is not 2FA-secure
#43The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.
Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…
Re: SMS is not 2FA-secure
#44Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no". https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...
Re: SMS is not 2FA-secure
#45Earlier quoted context omitted.
Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…
The problem there is that it's not very clear that you didn't trigger the login yourself.
Your experience and standards of clarity may be different from mine, obviously.
Re: SMS is not 2FA-secure
#46It's a complete shitshow. Occasionally syndicates manage to get both sides of 2FA lined up (insiders) and clean out someone's account.
Then the bank says not my problem - you didn't keep your password safe. And the cell provider says not my problem - not intended as security mechanism. Leaving the customer poor and sht out of luck.
Re: SMS is not 2FA-secure
#47Not in Russia. Numerous examples exist when victim's number was linked to attacker's sim card to obtain 2FA code, then linked back to victim's sim so he does not notice anything. This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with su…
Just google for "форум пробив" and you will find black market for accessing any kind of information, including SMS, phone location, etc and associated services for hacking accounts (VK, Gmail, etc). You don't need to be a government, it is open for everyone.
Re: SMS is not 2FA-secure
#48Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker.
Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked.
If it’s one thing I have learned the hard way it’s that the most dangerous person in the equation is myself. I won’t trust myself with any kind of security.
Re: SMS is not 2FA-secure
#49Just use a token like yubikey. I have a small fleet and am very happy with the decision. The only problem is there are very few services that get it right. Get it right means support multiple tokens and allow to truly disable any other means of logging in or recovering the password. Most services seem bent on allowing many ways of logging in without giving a choice. For example, they will advertise they use 2fa token…
https://play.google.com/store/apps/details?id=com.google.and...
Re: SMS is not 2FA-secure
#50Compared to what? Better than not having it? Yes. Better than committing a 4,096Kb PK to memory and confirming all interactions with mental arithmetic? No.
I happen to think the benefits of SMS 2FA, even when working as intended, are negligible. It seems like a bad idea to waste the finite amount of developer good will we have asking services to implement it.
Literally the only attack that SMS 2FA has any impact on is credential stuffing, and even then it's debatable. Credential stuffing is using the credentials stolen from one service to compromise another. If you don't reuse passwords, then you don't need SMS 2FA.
If you do reuse passwords - then it seems impossible you're not also vulnerable to phishing. After all, you're already willing to hand over your credentials to anyone who asks. SMS 2FA is not a solution to phishing, as the tokens themselves can be phished.