Worth noting that this is just for US and for prepaid SIMs, from their paper “We examined the types of authentication mechanisms in place for such requests at 5 U.S. prepaid carriers—–AT&T, T-Mobile, Tracfone, US Mobile, and Verizon Wireless”. It doesn’t mean that for the rest of the world SMS 2FA is completely secure, it’s just a lot more difficult (or impractical/impossible) to do a SIM swap so easily. As mentioned…
These 5 carriers were studied, but where's the evidence that any other carrier is any better (or that you're any better off as a post paid customer of AT&T, T-Mobile or Verizon)?
SMS is not 2FA-secure
151–160 of 379 posts
Re: SMS is not 2FA-secure
#152What's with all the redacted entries? Without some context, I assume that these are companies that threatened some sort of legal action if their name was published?
Re: SMS is not 2FA-secure
#153This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…
> account recovery, as a sole factor, meaning you're substantially worse off with SMS authentication than you are without it at those services But if in those cases you disable SMS auth, then you can't recover your account right? That might be considered worse off in some cases.
Re: SMS is not 2FA-secure
#154Earlier quoted context omitted.
Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes. It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.
In a previous company, one of the employees enabled 2FA for their staff account (it was mandatory), stored the backup codes on his phone (presumably as a photo) and it fall in the ocean the next day. With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.
Re: SMS is not 2FA-secure
#155Worth noting that this is just for US and for prepaid SIMs, from their paper “We examined the types of authentication mechanisms in place for such requests at 5 U.S. prepaid carriers—–AT&T, T-Mobile, Tracfone, US Mobile, and Verizon Wireless”. It doesn’t mean that for the rest of the world SMS 2FA is completely secure, it’s just a lot more difficult (or impractical/impossible) to do a SIM swap so easily. As mentioned…
Re: SMS is not 2FA-secure
#156Ran Bar-Zik, from Israel, created a technique to hack most voice 2FA by using a weak voicemail password. It was largely used in 2019 to hack Brazilian politicians, including state ministers. The hacked telegram messages were passed to Glenn Greenwald, linked to Assange.
AFAIK, they were hacked using plain simple SIM swap/cloning.
Re: SMS is not 2FA-secure
#157Earlier quoted context omitted.
I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.
After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…
Re: SMS is not 2FA-secure
#158Earlier quoted context omitted.
I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.
After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…
Re: SMS is not 2FA-secure
#159Re: SMS is not 2FA-secure
#160Earlier quoted context omitted.
I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.
After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…