Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

61–70 of 379 posts

Re: SMS is not 2FA-secure

#61
post #53

You know what's funny? LinkedIn is supposed to be a 'professional' social network (Microsoft owned) and a friend of mine was asked to add a phone number 'For security purposes'. I knew this was suspiciously involving 2FA SMS + a bonus of spam callers and I told him to press "Not Now". Whilst the world is moving to U2F and time-sensitive codes, a security system using SMS 2FA is now equivalent to a single PC running W…

Not true. Not true by far. That's an over statement. 2FA is only one of two factors, you need the the password, you need the mobile number and you need to obtain a duplicate or being close to your victim.

You should be worried if you are a POI or you are being targeted personally. And if it is so, SIM Swapping it's just one option and if it doesn't work there are other methods (breaking in, stealing yubikeys, mobiles...)

Re: SMS is not 2FA-secure

#62
post #39

People always focus on SIM swaps and signal security, but neither of those apply to Google voice numbers. So in the context of Google voice, is there still any reason to not use SMS 2FA?

Bank of America doesn’t send SMS to google voice phone numbers.

Re: SMS is not 2FA-secure

#63

Is SMS 2FA Secure? No, I agree. Is SMS 2FA enough for most of the people today? Yes Is SMS a cost-benefit solution for most uses? Yes

Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes. It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.

There is a reason for that, most average Joes just can't handle the technology. You can change OTP-SMS in Banks for TOTP, but it involves more complexity and probably it will be more prone to user errors.

Configuring the seed, remembering an extra password to use the OTP... For me it's not that hard, but probably my mom will need some help in order to remember all the steps...

Re: SMS is not 2FA-secure

#64
I know a few people who have been hacked with this method via t-mobile in order to control chat rooms on telegram and steal crypto.

According to this paper, t-mobile has the smallest surface area, which is sad.

Re: SMS is not 2FA-secure

#65

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.

Re: SMS is not 2FA-secure

#66

And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?

At least they offer codes via email. I can (and do) secure access to my email account and domain registration with a very long password and a Yubikey. That’s “good enough” for my purposes.

"secure" and "email" really do not belong in the same sentence.

Re: SMS is not 2FA-secure

#67

Earlier quoted context omitted.

Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes. It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.

There is a reason for that, most average Joes just can't handle the technology. You can change OTP-SMS in Banks for TOTP, but it involves more complexity and probably it will be more prone to user errors. Configuring the seed, remembering an extra password to use the OTP... For me it's not that hard, but probably my mom will need some help in order to remember all the steps...

So make it a non default option? No one who doesn’t want to use TOTP would even have to know about it.

I know some services require SMS in order to force collection of user’s phone number, for data selling purposes and to prevent bots.

Re: SMS is not 2FA-secure

#68

And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?

At least they offer codes via email. I can (and do) secure access to my email account and domain registration with a very long password and a Yubikey. That’s “good enough” for my purposes.

Most email is unencrypted during transit, so a state level adversary can still easily intercept it. For most people this is however sufficient.

Re: SMS is not 2FA-secure

#70
post #65

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.

The issue with using permanent characteristics for auth is that you lose the ability to revoke one credential in favor of another.
Post reply on HN