Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

261–270 of 379 posts

Re: SMS is not 2FA-secure

#261
post #205

Earlier quoted context omitted.

Problem with a government photo ID, There's no way to verify its authentic besides a visual inspection. I consider them as secure as SMS 2FA. For $200 and someone could get passable ID with your name on it.

That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…

>In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc.

Can you detail which "most" of Europe you are talking about?

In Italy, while obviously you have to produce an ID card, there is no way that it can be checked online by "an employer", only Police (and Carabinieri) can do those checks, and of course ony for Italian issued ID's, moreover in some other businesses besides SIM card selling where the ID is needed (as an example hotels, AirBnB's and similar, car or tools renting, etc.) the actual employee never had a formal, official training to recognize forged ID's so everything is demanded to the single employee common sense and experience/knowledge (often zero or next to zero).

Particularly with "foreign" or "uncommon" pieces of ID's even if Italian (besides the "normal" ID cards and passports there are a number of other documents that have ID value) it is extremely difficult to understand if it is forged.

In UK AFAIK there is no national ID card, so you are limited to passport and/or (if valid for the scope) the driver license.

Re: SMS is not 2FA-secure

#262

My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…

The SIM Swap would seem to be a bit more accessible to the average fraudster. Hacking SS7 apparently requires setting up a "hub" and obtaining a carrier license from a lax country. That is, until we get to the bit about "illicit merchants offering ‘Connection-as-a-Service’ to such hubs." https://www.kaspersky.com/blog/hacking-cellular-networks/106...

> obtaining a carrier license from a lax country

Carrier license sounds much more involved than what it is. It's not uncommon to sell full SS7 access to companies that are not operators in the regular sense.

Re: SMS is not 2FA-secure

#263
post #80

Earlier quoted context omitted.

I wish Apple added iMessage as a service to make 2FA more secure.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

In Norway most banks have been using 2FA for 15 years or more I think.

Recently however it has become somewhat less strict it feels[0] and I can now log in to my bank app using FaceID or a pin code.

Normal bank websites still demand a code from a hardware token (think RSA key, but with a pincode and sequence-based instead of time based.)

[0]: I realize it might be that they are just as strict only doing more work in background to verify me instead of bugging me.

Re: SMS is not 2FA-secure

#264
post #245
post #236

Earlier quoted context omitted.

Before you go abroad you could notify your bank. Then in period you declared you are abroad they should lower expectation from "in person and ID" to phone call and other means of verification. After that period you are automatically back to normal security. That is for example how my debit card works. If I want to use it abroad I have to turn that feature on for whatever time I am abroad.

In Europe you have a telephone PIN codes, you have number generators on the app. There are lots of ways to authenticate yourself. IN Europe you no longer need to tell them whether you're abroad or not; I guess the ML algo's that monitor for fraud are so much better than before that this isn't needed.

> IN Europe you no longer need to tell them whether you're abroad or not

The same is true with my major US bank (and probably other banks too).

Re: SMS is not 2FA-secure

#266
post #253
post #188

Earlier quoted context omitted.

Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.

> Walk into a store and provide a government ID and the original SIM card. This is how it works in Poland since September 2019, after some recent SIM-swap attacks. You can swap SIM or get a replacement if stolen only at store showing government ID. It is free of charge with Orange and not always free with T-mobile. But this has some downsides in real life. 1) I had to walk my 88 yo Mom to the store to swap SIM card.…

On your second point, a determined criminal could always deploy rubber-hose cryptanalysis on a 2-factor authentication scheme, but it's still a significant improvement.

Your first drawback is substantial, though.

Re: SMS is not 2FA-secure

#267

Earlier quoted context omitted.

I meant for the services currently relying on SMS for account recovery... for example, how should you recover your gmail account if you lose access?

Use backup verification codes and a recovery email address. Also, remember the date when you created your Google account. The best way to find that date may be to look at the first email you received in the account.

".. a recovery email address"

This just moves your security issues to another account.. how many layers of recovery email address are you willing to go before hitting the end?

Re: SMS is not 2FA-secure

#268
post #253

Earlier quoted context omitted.

> Walk into a store and provide a government ID and the original SIM card. This is how it works in Poland since September 2019, after some recent SIM-swap attacks. You can swap SIM or get a replacement if stolen only at store showing government ID. It is free of charge with Orange and not always free with T-mobile. But this has some downsides in real life. 1) I had to walk my 88 yo Mom to the store to swap SIM card.…

On your second point, a determined criminal could always deploy rubber-hose cryptanalysis on a 2-factor authentication scheme, but it's still a significant improvement. Your first drawback is substantial, though.

> criminal could always deploy rubber-hose cryptanalysis

That would be smart criminal with means. I was thinking more of a hood with fat neck passing $20 to clerk assistant to obtain SIM for $5k fraud.

Re: SMS is not 2FA-secure

#269

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked.

I am not sure this is true. Most people regularly get phishing e-mails and apparently fall for it.

SMS and TOTP (due to the window of time the TOTP code is valid) only provide limited protection against active phishing attacks, since phishing site can 'proxy' the the SMS/TOTP code besides the password.

I think I would prefer losing access to an account (since I make backups of critical stuff anyway) than my account getting compromised, which could lead to identity theft/fraud, etc.

Re: SMS is not 2FA-secure

#270
post #205

Earlier quoted context omitted.

Photo ID seems like enough, no?

Problem with a government photo ID, There's no way to verify its authentic besides a visual inspection. I consider them as secure as SMS 2FA. For $200 and someone could get passable ID with your name on it.

Not necessarily, all IDs here in Portugal have a chip that can be used to verify its authenticity.
Post reply on HN