Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

131–140 of 379 posts

Re: SMS is not 2FA-secure

#131
post #80

Earlier quoted context omitted.

I wish Apple added iMessage as a service to make 2FA more secure.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that.

Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome.

I wish everyone would start using Yubikeys. WebAuthn is now widely supported by browsers.

Re: SMS is not 2FA-secure

#132
The odd thing about SMS 2FA is the amount of critical services that rely on it as the only method of extra protection.

You want your: bank, utility provider, entity-that-has-lots-of-personal-data-on-you to offer other secure options.

This might be a costing issue though. When your customers number in the millions, your call center is probably handling thousands of "im locked out" issues per day and these need to be handled in x-minutes. Other security options might cause the time meant to handle these scenarios to increase and SMS is generally 'simple' compared to them.

Re: SMS is not 2FA-secure

#133
post #111

Earlier quoted context omitted.

>SS7 signaling system is insecure If people knew how telcom (and the internet) was held together with bubblegun and duct tape... Multiple proposed fixes and replacements to SS7, to the best of my knowledge none of them are going anywhere. And even if it was pushed hard, it has to be a global thing.

Governments and the security industrial complex do not want it fixed. Vulnerabilities in SS7 are features to exploit, not bugs.

More than that it's the amount of work and cost. Average consumer doesn't care about it so why fix something that's not broken. People won't pay more for it

Re: SMS is not 2FA-secure

#134
post #49

Earlier quoted context omitted.

What about Authenticator? Maintaining a small fleet of yubikeys costs as much as a whole phone. https://play.google.com/store/apps/details?id=com.google.and...

Know that if your single phone dies with all your totp credentials, you're sunk.

Only if they neglected to offer backup codes (which anyone who does TOTP should).

Otherwise, you can just grab a few backup codes out of your fireproof safe and register your new totp code, or go to the bank and get them out of your bank vault.

Sure, the fireproof safe costs as much as a few yubikeys, but if you go the yubikey route you both need the yubikeys and a fireproof safe and bank vault for your spare yubikeys too.

Re: SMS is not 2FA-secure

#135

And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?

I asked them over twitter back in may.

https://twitter.com/skunkworker/status/1131297869703438337

Re: SMS is not 2FA-secure

#136

Earlier quoted context omitted.

As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.

I think requiring you to be physically present and having a human take the sample in a prescribed manner serves as an effective 'password' - unless it's a live sample, the DNA is useless.

The movie Gattaca showed in detail how routine spoofing of a variety of IRL DNA samples could work.

Re: SMS is not 2FA-secure

#137
The only good solution at this point is to legislate cell carriers to make SMS more secure. Everyone perceives it as secure, everything uses it for auth, and it aught to be secure for its own sake.

Re: SMS is not 2FA-secure

#139

In Switzerland, we have Mobile ID: https://www.mobileid.ch/en It uses the SIM to implement a challenge-response mechanism where a PIN is prompted by your phone. While not perfect, it's vastly better than using SMS, without being less convenient. I don't know if other places leverage the fact that SIMs are smart cards which are perfectly able to perform this kind of stuff given the proper infrastructure.

In India, if you get a SIM replaced after providing proofs of identity, residence and biometrics, it would get activated after few hours. The kicker is that it wont get SMSes for 24 hours after the SIM is activated. In the US, won't it be cheaper as well as secure to get a virtual phone number from Twilio for purposes of two factor authentication? (In India, there is no service at the rate what Twilio offers, but the…

Airtel also makes you to accept that SIM Swap request on old sim if you are not coming in person to a store with ID documents; most of which is Adhaar number verification.

Re: SMS is not 2FA-secure

#140
post #112

Earlier quoted context omitted.

Are you using Google Voice? I have the same problem with Chase on my GV number. Calling works fine, and so does email, but no SMS.

Port a number to GV, it will work, but you are at risk of losing it if you don't log in often enough. I lost an important number that way (along with my grand fathered free google apps account for my domain)

I have few personal google apps grandfathered account, & I think it sends an email to all admins if you do not log into it for about 10 months.
Post reply on HN