You know what's funny? LinkedIn is supposed to be a 'professional' social network (Microsoft owned) and a friend of mine was asked to add a phone number 'For security purposes'. I knew this was suspiciously involving 2FA SMS + a bonus of spam callers and I told him to press "Not Now". Whilst the world is moving to U2F and time-sensitive codes, a security system using SMS 2FA is now equivalent to a single PC running W…
Not true. Not true by far. That's an over statement. 2FA is only one of two factors, you need the the password, you need the mobile number and you need to obtain a duplicate or being close to your victim. You should be worried if you are a POI or you are being targeted personally. And if it is so, SIM Swapping it's just one option and if it doesn't work there are other methods (breaking in, stealing yubikeys, mobiles…
SMS is not 2FA-secure
91–100 of 379 posts
Re: SMS is not 2FA-secure
#92I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…
My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.
Re: SMS is not 2FA-secure
#93Earlier quoted context omitted.
That's not a problem if you have to physically show up though, since no one can spoof that.
As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.
Re: SMS is not 2FA-secure
#94Earlier quoted context omitted.
That's not a problem if you have to physically show up though, since no one can spoof that.
As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.
Re: SMS is not 2FA-secure
#95People always focus on SIM swaps and signal security, but neither of those apply to Google voice numbers. So in the context of Google voice, is there still any reason to not use SMS 2FA?
Bank of America doesn’t send SMS to google voice phone numbers.
Re: SMS is not 2FA-secure
#96The amount of knowledge one needs to port a phone number is unbelievably little, and peoples very nature to be helpful works against us. Up until maybe just very recently you needed the account number of the phone number and the last four of a social security number... sometimes, just the account number. Also, the last four of one's social security number is perhaps the shittiest way to authenticate _ANYTHING_. For many years, a lot of sites online would show you the last four of an account holder's SSN (and some places still probably do) if you have an email address, correct name, and phone number or physical address.
Getting the account number would likely be even easier thanks to helpful store reps... Just go in and make up an excuse why you need it or forgot it, it's like "social engineering 101" because it seems so benign to most people. You already know the name, address, and phone number-- you just "forgot" your id at home... Or one could just listen to them call each-other write down their info and then call another store.
With those two things in hand, the phone number is pretty much the attacker's, and getting it back would take more than enough time for extensive amounts of damage... ESPECIALLY if that is the only line on the account (or they took all the lines)... I'd guess a bare minimum with near immediate recognition of the real problem (your number heisted) and police involvement, probably a minimum of ~12 hours.
So, if phone numbers are so bad why are they ever used? IMHO, that's because they aren't to provide security, they're to provide easy tracking between your virtual life and your physical one. You're only securing the businesses data pipeline, not your personal data.
If you want 2FA (and everyone should) use Google Authenticator or a Yubikey... or whatever I'm not trying to shill brands just ideas that work.
Re: SMS is not 2FA-secure
#97The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.
Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…
In all these situations, I've found companies which offer a back up SMS option very valuable since it usually gets delivered.
Re: SMS is not 2FA-secure
#98Just use a token like yubikey. I have a small fleet and am very happy with the decision. The only problem is there are very few services that get it right. Get it right means support multiple tokens and allow to truly disable any other means of logging in or recovering the password. Most services seem bent on allowing many ways of logging in without giving a choice. For example, they will advertise they use 2fa token…
What about Authenticator? Maintaining a small fleet of yubikeys costs as much as a whole phone. https://play.google.com/store/apps/details?id=com.google.and...
Re: SMS is not 2FA-secure
#99This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…
I wish Apple added iMessage as a service to make 2FA more secure.
In fact, Apple should redesign Keychain into a user friendly, 1Password-lite product with 2FA built-in (1Password offers this too) or as a separate app that works with Keychain.
Re: SMS is not 2FA-secure
#100This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…
I wish Apple added iMessage as a service to make 2FA more secure.
Once you have control over a phone number, you can register iMessage as that number on a device you control.