I knew it had to be a scam, but hadn’t put the pieces together.
SMS is not 2FA-secure
231–240 of 379 posts
Re: SMS is not 2FA-secure
#232Earlier quoted context omitted.
So how SHOULD this problem be solved? How should account recovery work?
Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.
Re: SMS is not 2FA-secure
#233Earlier quoted context omitted.
I use Authy on iPhone and Mac. I am looking for an OSS replacement but would not want to setup everything from scratch after I change device reinstall the app like Google Authenticator.
Bitwarden does a decent job of storing and syncing TOTP codes. Make sure you always use a long password with Bitwarden though, to avoid a known and unpatched issue with their password-based key derivation.
Re: SMS is not 2FA-secure
#234Not in Russia. Numerous examples exist when victim's number was linked to attacker's sim card to obtain 2FA code, then linked back to victim's sim so he does not notice anything. This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with su…
> if you do, use a foreign SIP number with SMS capabilities Any good providers? I've tried Twilio SMS forwarding, but different services (e.g. Steam) reject it for 2FA since they're pretty much considered throwaway numbers, I suppose there's some sort of blacklist
Re: SMS is not 2FA-secure
#235Earlier quoted context omitted.
At least they offer codes via email. I can (and do) secure access to my email account and domain registration with a very long password and a Yubikey. That’s “good enough” for my purposes.
Most email is unencrypted during transit, so a state level adversary can still easily intercept it. For most people this is however sufficient.
Re: SMS is not 2FA-secure
#236Earlier quoted context omitted.
Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.
What if you are abroad? My debit card was recently blocked and I had to wait until I went back, walked in the bank and show my face and ID.
That is for example how my debit card works. If I want to use it abroad I have to turn that feature on for whatever time I am abroad.
Re: SMS is not 2FA-secure
#237Earlier quoted context omitted.
Problem with a government photo ID, There's no way to verify its authentic besides a visual inspection. I consider them as secure as SMS 2FA. For $200 and someone could get passable ID with your name on it.
That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…
A few years back I have lost my phone and went to get a new SIM. The attendant in the shop only had a quick look over my ID card. He didn't scan it nor did he enter the ID number in the computer to check anything. I think he only verified that the name was the same as the one on file and the photo looked like me.
The same happens at the post office when you go to collect a parcel / registered mail.
On the other hand, in almost every bar I've been, staff would do a quick check with a pen on every 50 € note they would get, and those notes are fairly common (two cocktails in a random bar in Paris can often cost more than 20 €). I don't know how effective that is in actually detecting counterfeit bills, but there's clearly more effort that what the other clerk did.
Re: SMS is not 2FA-secure
#238https://security.googleblog.com/2019/05/new-research-how-eff...
Re: SMS is not 2FA-secure
#239Earlier quoted context omitted.
So how SHOULD this problem be solved? How should account recovery work?
What about setting up two mobile phone numbers for recipients of the recovery code: 123 sent to phone #1 and 456 sent to phone #2? (Phone #1 is yours and phone #2 is your elected trusted partner’s) Won’t this work?
This is a terrible scheme.
Re: SMS is not 2FA-secure
#240Earlier quoted context omitted.
I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.
After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…
Classic Google Authenticator does not seem much more friction than that.