Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

181–190 of 379 posts

Re: SMS is not 2FA-secure

#181
post #165

Earlier quoted context omitted.

It depends. If your iMessage account is tied to an Apple ID used on multiple devices with 2FA enabled then the code is sent to one of those other devices to validate the login on the new device. So if you are fully in the Apple ecosystem and have 2FA enabled then I believe it would be secure. I know I get alerts on my other devices any time I have had to re-add my phone number to an Apple ID. It tells me my phone num…

When you get the prompt to input the code, just choose "Did not get a verification code" and it will fall back to SMS. See: https://blog.elcomsoft.com/wp-content/uploads/2016/03/apple_...

Interesting, I did not realize that.

Re: SMS is not 2FA-secure

#182
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

So how SHOULD this problem be solved? How should account recovery work?

[deleted]

Re: SMS is not 2FA-secure

#183
post #80

Earlier quoted context omitted.

I wish Apple added iMessage as a service to make 2FA more secure.

I could see Apple offering 2FA as a core feature, at least on iOS. In fact, Apple should redesign Keychain into a user friendly, 1Password-lite product with 2FA built-in (1Password offers this too) or as a separate app that works with Keychain.

iCloud Keychain is already a better-than-1Password 1Password-lite and 2FA itself for your Apple id is built into iOS and macOS. I think the limiting thing there is desktop Safari - you don't really notice the full integration unless you're using Safari on macOS as well.

Re: SMS is not 2FA-secure

#185

Earlier quoted context omitted.

Consider if you're kidnapped and extracted DNA in unwilling manner

I've built something around it. It's not 100% but gets you to 99%. Dontport.com

I'd be curious to know what the 11 potential tests are. Your website doesn't seem to list them anywhere.

Re: SMS is not 2FA-secure

#186
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

So how SHOULD this problem be solved? How should account recovery work?

Apps like Google authenticator, or more conveniently, a Google voice number. The Google voice solution works well since it can't be Sim swapped, and can be accessed via email (admittedly, a potential downside).

Re: SMS is not 2FA-secure

#187

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

> I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity.

Anytime you have a human in the loop you have the risk of human failings. I.e., that human forgets to follow critical step X in the protocol. Or that human falls for the attackers emotional sob story and takes pity on the attacker and lets the attacker unlock your account. Or that particular human is amenable to bribery to obtain the outcome the attacker wants.

In fact, many sim swaps have been reported to have occurred because of "human at cell phone store did not follow protocol" or "human at cell phone store was taking bribes".

So having a human in the loop is not an absolute solution to solving the problem.

Re: SMS is not 2FA-secure

#188
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

So how SHOULD this problem be solved? How should account recovery work?

Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.

Re: SMS is not 2FA-secure

#189

Ran Bar-Zik, from Israel, created a technique to hack most voice 2FA by using a weak voicemail password. It was largely used in 2019 to hack Brazilian politicians, including state ministers. The hacked telegram messages were passed to Glenn Greenwald, linked to Assange.

Do you have any sources on that (the specific technique that was used)? Google returned nothing. AFAIK, they were hacked using plain simple SIM swap/cloning.

https://politica.estadao.com.br/blogs/fausto-macedo/wp-conte...

(Portuguese)

Re: SMS is not 2FA-secure

#190
post #186

Earlier quoted context omitted.

So how SHOULD this problem be solved? How should account recovery work?

Apps like Google authenticator, or more conveniently, a Google voice number. The Google voice solution works well since it can't be Sim swapped, and can be accessed via email (admittedly, a potential downside).

[deleted]
Post reply on HN