Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

41–50 of 379 posts

Re: SMS is not 2FA-secure

#41
Ran Bar-Zik, from Israel, created a technique to hack most voice 2FA by using a weak voicemail password. It was largely used in 2019 to hack Brazilian politicians, including state ministers. The hacked telegram messages were passed to Glenn Greenwald, linked to Assange.

Re: SMS is not 2FA-secure

#42

HN seems to be getting a lot of these submissions lately where the question asked in the title is the same as the domain name. Sometimes the content of the page doesn't even answer the question. Feels like some kind of spammy PageRank manipulation going on. I'm happy to be wrong about this, but I wanted to see if anyone else has noticed. Maybe I'm just smoking crack waffles again.

This is clearly a PR effort associated with the research paper hosted on the site.

It's a single-purpose domain name, so the Name of the domain is the same as the Name of the content on the domain.

Re: SMS is not 2FA-secure

#43
post #37

The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.

Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…

The problem there is that it's not very clear that you didn't trigger the login yourself.

Re: SMS is not 2FA-secure

#44

Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no". https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...

The key part here is to only post this comment under headlines for which the answer in "no".

Re: SMS is not 2FA-secure

#45
post #43
post #37

Earlier quoted context omitted.

Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…

The problem there is that it's not very clear that you didn't trigger the login yourself.

It's been my experience that it's often reasonably clear to users that they did perform a login themselves in the past few seconds. Adding an approximate location and a short verification token to the prompt generally helps.

Your experience and standards of clarity may be different from mine, obviously.

Re: SMS is not 2FA-secure

#46
Definitely not. In my home country the banks use SMS 2FA.

It's a complete shitshow. Occasionally syndicates manage to get both sides of 2FA lined up (insiders) and clean out someone's account.

Then the bank says not my problem - you didn't keep your password safe. And the cell provider says not my problem - not intended as security mechanism. Leaving the customer poor and sht out of luck.

Re: SMS is not 2FA-secure

#47
post #36

Not in Russia. Numerous examples exist when victim's number was linked to attacker's sim card to obtain 2FA code, then linked back to victim's sim so he does not notice anything. This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with su…

Just google for "форум пробив" and you will find black market for accessing any kind of information, including SMS, phone location, etc and associated services for hacking accounts (VK, Gmail, etc). You don't need to be a government, it is open for everyone.

That type of service can allow the attackers to access SMS contents, but not from swapping numbers back and forth between SIM cards. And without it, the victim will know he is being attacked.

Re: SMS is not 2FA-secure

#48
I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity.

Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker.

Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked.

If it’s one thing I have learned the hard way it’s that the most dangerous person in the equation is myself. I won’t trust myself with any kind of security.

Re: SMS is not 2FA-secure

#49
post #7

Just use a token like yubikey. I have a small fleet and am very happy with the decision. The only problem is there are very few services that get it right. Get it right means support multiple tokens and allow to truly disable any other means of logging in or recovering the password. Most services seem bent on allowing many ways of logging in without giving a choice. For example, they will advertise they use 2fa token…

What about Authenticator? Maintaining a small fleet of yubikeys costs as much as a whole phone.

https://play.google.com/store/apps/details?id=com.google.and...

Re: SMS is not 2FA-secure

#50
post #9

Compared to what? Better than not having it? Yes. Better than committing a 4,096Kb PK to memory and confirming all interactions with mental arithmetic? No.

The article says "We found 17 websites on which user accounts can be compromised based on a SIM swap alone", that seems like a pretty clear indication that it can be worse than nothing.

I happen to think the benefits of SMS 2FA, even when working as intended, are negligible. It seems like a bad idea to waste the finite amount of developer good will we have asking services to implement it.

Literally the only attack that SMS 2FA has any impact on is credential stuffing, and even then it's debatable. Credential stuffing is using the credentials stolen from one service to compromise another. If you don't reuse passwords, then you don't need SMS 2FA.

If you do reuse passwords - then it seems impossible you're not also vulnerable to phishing. After all, you're already willing to hand over your credentials to anyone who asks. SMS 2FA is not a solution to phishing, as the tokens themselves can be phished.

Post reply on HN