Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

231–240 of 379 posts

Re: SMS is not 2FA-secure

#231
This may explain why I get called every week from all over Europe by people that think they missed a call from me.

I knew it had to be a scam, but hadn’t put the pieces together.

Re: SMS is not 2FA-secure

#232
post #188

Earlier quoted context omitted.

So how SHOULD this problem be solved? How should account recovery work?

Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.

Cool. What store? Do all services that provide accounts need physical stores now? How do you ensure the store endpoints are trustworthy, and actually checking said IDs and SIMs?

Re: SMS is not 2FA-secure

#233
post #214

Earlier quoted context omitted.

I use Authy on iPhone and Mac. I am looking for an OSS replacement but would not want to setup everything from scratch after I change device reinstall the app like Google Authenticator.

Bitwarden does a decent job of storing and syncing TOTP codes. Make sure you always use a long password with Bitwarden though, to avoid a known and unpatched issue with their password-based key derivation.

Oh, didn’t know BitWarden did it. That’s my password manager :)

Re: SMS is not 2FA-secure

#234

Not in Russia. Numerous examples exist when victim's number was linked to attacker's sim card to obtain 2FA code, then linked back to victim's sim so he does not notice anything. This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with su…

> if you do, use a foreign SIP number with SMS capabilities Any good providers? I've tried Twilio SMS forwarding, but different services (e.g. Steam) reject it for 2FA since they're pretty much considered throwaway numbers, I suppose there's some sort of blacklist

I have used zadarma.com, they are very cheap and have an app for Android that works rather well

Re: SMS is not 2FA-secure

#235

Earlier quoted context omitted.

At least they offer codes via email. I can (and do) secure access to my email account and domain registration with a very long password and a Yubikey. That’s “good enough” for my purposes.

Most email is unencrypted during transit, so a state level adversary can still easily intercept it. For most people this is however sufficient.

You hardly need to be "state-level" to spoof bgp or dns.

Re: SMS is not 2FA-secure

#236
post #197
post #188

Earlier quoted context omitted.

Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.

What if you are abroad? My debit card was recently blocked and I had to wait until I went back, walked in the bank and show my face and ID.

Before you go abroad you could notify your bank. Then in period you declared you are abroad they should lower expectation from "in person and ID" to phone call and other means of verification. After that period you are automatically back to normal security.

That is for example how my debit card works. If I want to use it abroad I have to turn that feature on for whatever time I am abroad.

Re: SMS is not 2FA-secure

#237
post #205

Earlier quoted context omitted.

Problem with a government photo ID, There's no way to verify its authentic besides a visual inspection. I consider them as secure as SMS 2FA. For $200 and someone could get passable ID with your name on it.

That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…

I have a counterpoint from my experience in France.

A few years back I have lost my phone and went to get a new SIM. The attendant in the shop only had a quick look over my ID card. He didn't scan it nor did he enter the ID number in the computer to check anything. I think he only verified that the name was the same as the one on file and the photo looked like me.

The same happens at the post office when you go to collect a parcel / registered mail.

On the other hand, in almost every bar I've been, staff would do a quick check with a pen on every 50 € note they would get, and those notes are fairly common (two cocktails in a random bar in Paris can often cost more than 20 €). I don't know how effective that is in actually detecting counterfeit bills, but there's clearly more effort that what the other clerk did.

Re: SMS is not 2FA-secure

#239
post #229

Earlier quoted context omitted.

So how SHOULD this problem be solved? How should account recovery work?

What about setting up two mobile phone numbers for recipients of the recovery code: 123 sent to phone #1 and 456 sent to phone #2? (Phone #1 is yours and phone #2 is your elected trusted partner’s) Won’t this work?

Who should single people sign up as #2? Their mom? And what if your SO is currently unavailable?

This is a terrible scheme.

Re: SMS is not 2FA-secure

#240
post #131

Earlier quoted context omitted.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

AFAIK, in the EU all banks are required to have "strong authentication" which usually means using 2FA via biometric authentication on your phone.

Classic Google Authenticator does not seem much more friction than that.

Post reply on HN