Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

81–90 of 379 posts

Re: SMS is not 2FA-secure

#81

Earlier quoted context omitted.

At least they offer codes via email. I can (and do) secure access to my email account and domain registration with a very long password and a Yubikey. That’s “good enough” for my purposes.

Most email is unencrypted during transit, so a state level adversary can still easily intercept it. For most people this is however sufficient.

Absolutely, a state-level opponent could get up to some shenanigans though I would argue that a state has much easier methods to go cracking into my Visa card. My threat model doesn’t include nation states targeting me specifically because, simply, if one comes after me I am screwed anyway.

As for email being unencrypted, I think most of it now is encrypted during transit (thanks to the Big Two providers knocking points off a spam score if a message does come via TLS) and even if it weren’t the password is also not known so the second factor is not useful. For example, I just tried to log in to chase.com and the code they emailed me at 1752 MST is 067315.

If I’ve been phished so hard that posting this is useful, again I’m screwed.

Re: SMS is not 2FA-secure

#82
post #39

People always focus on SIM swaps and signal security, but neither of those apply to Google voice numbers. So in the context of Google voice, is there still any reason to not use SMS 2FA?

Bank of America doesn’t send SMS to google voice phone numbers.

What happens if you port to Google voice, can you no longer access your account?

Re: SMS is not 2FA-secure

#83

The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.

Awareness may make providers more willing to switch to a better 2FA, such as TOTP.

Sadly, providers seem to be going the other way. I had a service try to bully me into disabling TOTP in favor of SMS 2FA this week.

Re: SMS is not 2FA-secure

#84

Earlier quoted context omitted.

The issue with using permanent characteristics for auth is that you lose the ability to revoke one credential in favor of another.

That's not a problem if you have to physically show up though, since no one can spoof that.

As another person said, you're literally leaving it everywhere you go.

If you need a blood sample, then would donating blood be considered compromising security?

Identity is what your DNA is. Password is a secret. Your DNA is not a secret.

Re: SMS is not 2FA-secure

#85
post #65

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.

Consider identical twins, mothers, and organ donation or blood transfusion recipients.

Re: SMS is not 2FA-secure

#86

My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…

I am pretty sure this is how they got Bezos' texts. All you need to do is register a CLEC and then you can get your official hookup to SS7. My experience isn't with messaging but I'd imagine if you bid* to deliver messages to a certain area much lower than other carriers, you can target people.

* Bidding doesn't happen in real time, but you can tell carriers your "rates" so to speak.

Re: SMS is not 2FA-secure

#87

Earlier quoted context omitted.

The issue with using permanent characteristics for auth is that you lose the ability to revoke one credential in favor of another.

That's not a problem if you have to physically show up though, since no one can spoof that.

That's exactly what they did in the movie Gattica- it's hard but seems totally possible. I'd rather have multiple revokable keys.

Re: SMS is not 2FA-secure

#88
post #64

I know a few people who have been hacked with this method via t-mobile in order to control chat rooms on telegram and steal crypto. According to this paper, t-mobile has the smallest surface area, which is sad.

Why sad? someone has to have the smallest

Would it be less sad if it was Verizon?

Re: SMS is not 2FA-secure

#89
post #82

Earlier quoted context omitted.

Bank of America doesn’t send SMS to google voice phone numbers.

What happens if you port to Google voice, can you no longer access your account?

I don't know, all I know is I can't receive BoA 2FA SMS on my Google Voice number. This is what BoA says:

>You are consenting to be contacted at the phone number selected for the purpose of receiving an authorization code. If you selected text message, Wireless and text message fees may apply from your carrier. Supported carriers include: Alltel, AT&T, Cellular One, T-Mobile, Virgin Mobile, U.S Cellular and Verizon Wireless.

Although I just remembered this person on Hacker News replied to me 1+ year ago that their Google Voice number does work with BoA 2FA SMS, so maybe it's just my specific GV phone number?

https://news.ycombinator.com/item?id=18196014

Post reply on HN