Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

151–160 of 379 posts

Re: SMS is not 2FA-secure

#151
post #79

Worth noting that this is just for US and for prepaid SIMs, from their paper “We examined the types of authentication mechanisms in place for such requests at 5 U.S. prepaid carriers—–AT&T, T-Mobile, Tracfone, US Mobile, and Verizon Wireless”. It doesn’t mean that for the rest of the world SMS 2FA is completely secure, it’s just a lot more difficult (or impractical/impossible) to do a SIM swap so easily. As mentioned…

These 5 carriers were studied, but where's the evidence that any other carrier is any better (or that you're any better off as a post paid customer of AT&T, T-Mobile or Verizon)?

MetroPCS (prepaid MVNO now something like a subsidiary of TMo) required the 8-digit PIN on the account in order to change IMEIs. A bot would take down all the info, then if/when it was to a phone you'd never used on their network before, you got put on hold to wait to talk to a human and provide your PIN and new IMEI all over again. Then you'd hang up, power off, and move your SIM. But that was ~18 months ago, before it became "Metro by T-Mobile", so I don't know.

Re: SMS is not 2FA-secure

#152

What's with all the redacted entries? Without some context, I assume that these are companies that threatened some sort of legal action if their name was published?

Later in the paper they mention that they're temporarily redacted due to responsible disclosure rules.

Re: SMS is not 2FA-secure

#153
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

> account recovery, as a sole factor, meaning you're substantially worse off with SMS authentication than you are without it at those services But if in those cases you disable SMS auth, then you can't recover your account right? That might be considered worse off in some cases.

What worries me isn’t that I might not be able to recover my account if it uses some other form of authentication, it’s that I might not be able to recover my account because it requires authentication from a phone number I lose access to.

Re: SMS is not 2FA-secure

#154

Earlier quoted context omitted.

Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes. It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.

In a previous company, one of the employees enabled 2FA for their staff account (it was mandatory), stored the backup codes on his phone (presumably as a photo) and it fall in the ocean the next day. With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.

Yes, that is exactly what I want. Life should be much more difficult without the TOTP and backup codes, so much that it takes a great deal of resources to get around it, if at all possible. Maybe even providing heavy documentation such as a Facetime call with various proof so that fraudulent actors are sufficiently deterred.

Re: SMS is not 2FA-secure

#155

Worth noting that this is just for US and for prepaid SIMs, from their paper “We examined the types of authentication mechanisms in place for such requests at 5 U.S. prepaid carriers—–AT&T, T-Mobile, Tracfone, US Mobile, and Verizon Wireless”. It doesn’t mean that for the rest of the world SMS 2FA is completely secure, it’s just a lot more difficult (or impractical/impossible) to do a SIM swap so easily. As mentioned…

The rest of the developed world is using a same way to verify a person - by providing your document. ID card or passport.

Re: SMS is not 2FA-secure

#156

Ran Bar-Zik, from Israel, created a technique to hack most voice 2FA by using a weak voicemail password. It was largely used in 2019 to hack Brazilian politicians, including state ministers. The hacked telegram messages were passed to Glenn Greenwald, linked to Assange.

Do you have any sources on that (the specific technique that was used)? Google returned nothing.

AFAIK, they were hacked using plain simple SIM swap/cloning.

Re: SMS is not 2FA-secure

#157
post #131

Earlier quoted context omitted.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

Why not use an open TOTP app like AndOTP. I use it all the time for sites that claim to require Google Authenticator, it works, and its easy to backup the secrets as plain text or encrypted with a password. I keep it current on my primary phone and a cheap offline backup, in addition to backing up the encrypted secrets file.

Re: SMS is not 2FA-secure

#158
post #131

Earlier quoted context omitted.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

Don’t put them in google authenticator.

https://support.1password.com/one-time-passwords/

Re: SMS is not 2FA-secure

#159
It would be nice if the carriers allowed you to specify you wanted to restrict SIM swapping. When I lost my 3 SIM to get the number transferred to a new one I went to a 3 store with my passport. I'd be fine with that being the only method they'd allow.

Re: SMS is not 2FA-secure

#160
post #131

Earlier quoted context omitted.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

Isn't that solvable by not requiring 2fa for "registered" devices?
Post reply on HN