Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

91–100 of 379 posts

Re: SMS is not 2FA-secure

#91
post #53

You know what's funny? LinkedIn is supposed to be a 'professional' social network (Microsoft owned) and a friend of mine was asked to add a phone number 'For security purposes'. I knew this was suspiciously involving 2FA SMS + a bonus of spam callers and I told him to press "Not Now". Whilst the world is moving to U2F and time-sensitive codes, a security system using SMS 2FA is now equivalent to a single PC running W…

Not true. Not true by far. That's an over statement. 2FA is only one of two factors, you need the the password, you need the mobile number and you need to obtain a duplicate or being close to your victim. You should be worried if you are a POI or you are being targeted personally. And if it is so, SIM Swapping it's just one option and if it doesn't work there are other methods (breaking in, stealing yubikeys, mobiles…

You don’t always know if you are a target.

Re: SMS is not 2FA-secure

#92
post #65

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.

This is where countries like India are going with Biometric Auth plus 2FA (though the implementation has issues). The government provides a public API for sending fingerprint or Iris scan data plus SMS 2FA to authenticate identity with a cost.

Re: SMS is not 2FA-secure

#93

Earlier quoted context omitted.

That's not a problem if you have to physically show up though, since no one can spoof that.

As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.

I think requiring you to be physically present and having a human take the sample in a prescribed manner serves as an effective 'password' - unless it's a live sample, the DNA is useless.

Re: SMS is not 2FA-secure

#94

Earlier quoted context omitted.

That's not a problem if you have to physically show up though, since no one can spoof that.

As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.

Consider if you're kidnapped and extracted DNA in unwilling manner

Re: SMS is not 2FA-secure

#95
post #39

People always focus on SIM swaps and signal security, but neither of those apply to Google voice numbers. So in the context of Google voice, is there still any reason to not use SMS 2FA?

Bank of America doesn’t send SMS to google voice phone numbers.

Bank of America won’t send sms to my Canadian carrier either. I have to request a call every time.

Re: SMS is not 2FA-secure

#96
I have been saying this for years.

The amount of knowledge one needs to port a phone number is unbelievably little, and peoples very nature to be helpful works against us. Up until maybe just very recently you needed the account number of the phone number and the last four of a social security number... sometimes, just the account number. Also, the last four of one's social security number is perhaps the shittiest way to authenticate _ANYTHING_. For many years, a lot of sites online would show you the last four of an account holder's SSN (and some places still probably do) if you have an email address, correct name, and phone number or physical address.

Getting the account number would likely be even easier thanks to helpful store reps... Just go in and make up an excuse why you need it or forgot it, it's like "social engineering 101" because it seems so benign to most people. You already know the name, address, and phone number-- you just "forgot" your id at home... Or one could just listen to them call each-other write down their info and then call another store.

With those two things in hand, the phone number is pretty much the attacker's, and getting it back would take more than enough time for extensive amounts of damage... ESPECIALLY if that is the only line on the account (or they took all the lines)... I'd guess a bare minimum with near immediate recognition of the real problem (your number heisted) and police involvement, probably a minimum of ~12 hours.

So, if phone numbers are so bad why are they ever used? IMHO, that's because they aren't to provide security, they're to provide easy tracking between your virtual life and your physical one. You're only securing the businesses data pipeline, not your personal data.

If you want 2FA (and everyone should) use Google Authenticator or a Yubikey... or whatever I'm not trying to shill brands just ideas that work.

Re: SMS is not 2FA-secure

#97
post #37

The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.

Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…

They (and similar corporate 2FA solutions like PingID and similar systems used by banks) basically assume uninterrupted access to the internet which is generally a poor assumption. It often breaks down when you're traveling either due to network or roaming issues just when you desperately need access.

In all these situations, I've found companies which offer a back up SMS option very valuable since it usually gets delivered.

Re: SMS is not 2FA-secure

#98
post #49
post #7

Just use a token like yubikey. I have a small fleet and am very happy with the decision. The only problem is there are very few services that get it right. Get it right means support multiple tokens and allow to truly disable any other means of logging in or recovering the password. Most services seem bent on allowing many ways of logging in without giving a choice. For example, they will advertise they use 2fa token…

What about Authenticator? Maintaining a small fleet of yubikeys costs as much as a whole phone. https://play.google.com/store/apps/details?id=com.google.and...

Know that if your single phone dies with all your totp credentials, you're sunk.

Re: SMS is not 2FA-secure

#99
post #80
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

I wish Apple added iMessage as a service to make 2FA more secure.

I could see Apple offering 2FA as a core feature, at least on iOS.

In fact, Apple should redesign Keychain into a user friendly, 1Password-lite product with 2FA built-in (1Password offers this too) or as a separate app that works with Keychain.

Re: SMS is not 2FA-secure

#100
post #80
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

I wish Apple added iMessage as a service to make 2FA more secure.

Isn't iMessage just as vulnerable to SIM swapping and number portability fraud as SMS?

Once you have control over a phone number, you can register iMessage as that number on a device you control.

Post reply on HN