Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

101–110 of 379 posts

Re: SMS is not 2FA-secure

#102
post #27

And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?

at least one of my banks cannot SMS me codes, I can't remmeber which, so I always forget, try it, and have to select another method. I THINK it's chase, but I'm not sure. They have my correct phone number, but for years now, the code just... never shows up.

Are you using Google Voice? I have the same problem with Chase on my GV number. Calling works fine, and so does email, but no SMS.

Re: SMS is not 2FA-secure

#103

Is SMS 2FA Secure? No, I agree. Is SMS 2FA enough for most of the people today? Yes Is SMS a cost-benefit solution for most uses? Yes

Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes. It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.

In a previous company, one of the employees enabled 2FA for their staff account (it was mandatory), stored the backup codes on his phone (presumably as a photo) and it fall in the ocean the next day.

With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.

Re: SMS is not 2FA-secure

#104
post #65

Earlier quoted context omitted.

My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.

>with appropriate DNA extraction procedures Carriers have already demonstrated their complete across the board failure to have appropriate security procedures. Your DNA isn't hard to find, you leave it literally everywhere you go. And do you really want mobile carriers creating a DNA database of their every customer? The same companies that already sell your location data to bounty hunters? That's going to be a big n…

While I basically agree, why do you think they'd need your actual DNA? Wouldn't it be hashed?

Re: SMS is not 2FA-secure

#105
DontPort.Com - I built this to fix this. I've been a victim of this 4 times and was too much frustrated. Unfortunately Sim swap is only one way to get your 2FA but the risks are much higher which I am working to solve one by one

Re: SMS is not 2FA-secure

#106
post #83

Earlier quoted context omitted.

Awareness may make providers more willing to switch to a better 2FA, such as TOTP.

Sadly, providers seem to be going the other way. I had a service try to bully me into disabling TOTP in favor of SMS 2FA this week.

Because they want your phone number. They are more and more used to link to identities, as people tend to keep (and port) their phone number

Hint: if a store ask for a phone number to get a discount, try the local areacode then 634 5789. This is from an old song, and many people seem to have created "anonymous" account with it!

https://en.wikipedia.org/wiki/634-5789_(Soulsville,_U.S.A.)

Re: SMS is not 2FA-secure

#107

Earlier quoted context omitted.

As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.

Consider if you're kidnapped and extracted DNA in unwilling manner

I've built something around it. It's not 100% but gets you to 99%. Dontport.com

Re: SMS is not 2FA-secure

#108

The big benefit of SMS for the website is that it outsources the problem of lost 2FA tokens. What happens if the user loses a yubikey. Or changes phones and did not back up their TOTP. With SMS authentication, even if the user loses a phone, they can go down to the local cell phone store and get a new phone on their number and be back in business without the website having to get involved.

> What happens if the user loses a yubikey. Always buy two. ;-) Joking aside, I've moved almost every 2FA to hard token, soft-token, or google voice. But the root of trust is still LastPass & Google. I don't see an easy way out of dependency other than power of attorney. Even worse: I worry what happens to my protected assets as I age and possibly face memory loss.

Bad idea: google will disable your google voice after some time of not logging in.

I got bitten in a bad way!

Hopefully twilio will start creating "recognized" numbers someday, as my twilio number is unusable for TOTP. There seems to be a blacklist of all twilio voip numbers.

Re: SMS is not 2FA-secure

#109

And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?

There is even a "Use Token" button on the Chase login page, but apparently only business accounts can use it.

Re: SMS is not 2FA-secure

#110

My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…

The SIM Swap would seem to be a bit more accessible to the average fraudster. Hacking SS7 apparently requires setting up a "hub" and obtaining a carrier license from a lax country. That is, until we get to the bit about "illicit merchants offering ‘Connection-as-a-Service’ to such hubs."

https://www.kaspersky.com/blog/hacking-cellular-networks/106...

Post reply on HN