Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

371–379 of 379 posts

Re: SMS is not 2FA-secure

#371
post #165

Earlier quoted context omitted.

When you get the prompt to input the code, just choose "Did not get a verification code" and it will fall back to SMS. See: https://blog.elcomsoft.com/wp-content/uploads/2016/03/apple_...

Interesting, I did not realize that.

This is a great find too

Re: SMS is not 2FA-secure

#372

My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…

Does that mean an authoritarian government can read the location and sms of a number from foreign country without any cooperation from the carrier? Scary thought

Doesn't have to be government but any one

Re: SMS is not 2FA-secure

#373
post #344

Earlier quoted context omitted.

I think we just need to be prepared for these sorts of things. Travel with cash, your debit card, and one or two credit cards. If you can afford it, have a backup SIM (Twilio sells SIM cards for about $3 and the cost to keep them activated is $1/mo, and nothing more if you don't use it [0]). Use a Twilio or Google Voice number that you don't use for anything else for 2FA or account recovery for services that require…

It's about convenience. 99% of the people will take convenience over security. Changing behaviour is difficult

I get that, but if you want to remain reasonably safe from a SIM swap attack, this is what you have to do.

Re: SMS is not 2FA-secure

#374
post #350

Earlier quoted context omitted.

How would this work exactly?

The clerk has to use some kind of online system to connect the new sim to the customers phone number. The system would obviously require the clerk to authenticate himself and could require him to enter the passport number or other document ID he checked to verify the customers identity. If later it turns out this was a sim swapping attack you can verify if the clerk entered a valid document ID. He can’t do that witho…

Ah, thanks.

I wasn't sure how would you solve the problem of verifying the ID card without showing the previously recorded number to the clerk. But simply requiring to every time just punch in the ID (and maybe scan the whole card to check the photo later) could work - if the system only returns a big OK or BAD signal.

Currently here, in Hungary, the clerks just photocopy the IDs though. And there was a big scandal a few years ago (in connection to the ISIL/ISIS attacks in EU) about some groups obtaining hundreds of thousands of SIMs for just a few names.

Re: SMS is not 2FA-secure

#375

Earlier quoted context omitted.

You can get a federal ID. It's called a passport card. It costs $65. The US also has the REAL ID[0] standard that requires IDs to meet minimum standards in order to be accepted by the federal government. If carriers just required a REAL ID compliant ID in order to get a new SIM, and actually checked it via the chip or magnetic strip, I think we'd be good. [0] https://www.dhs.gov/real-id

You can get a federal ID. It's called a passport card. It costs $65. Which is usually a really crappy idea when you want to save a few bucks compared to a real passport. They're umpteen stories of heartbreak and hurt, by people not being allowed to board an international flight, or a cruise which stops at destinations not covered by a passport card. They're also those that thought it's a great idea to get them for th…

Obviously not, it's not a passport. It's a card.

I'm not saying use it for international travel, I'm saying use it as an ID? Literally any American citizen can get an ID card for $65 that is accepted everywhere someone asks you for ID.

If we started taking things a bit more seriously, we could also get that fee down by subsidizing it.

Re: SMS is not 2FA-secure

#377
post #16

I thought this was going to be one of the otherwise-plaintext black and white web pages with NO. centered in the middle, but interestingly it's actual research, and a nice read (even if nothing new) at that.

If it's nothing new then why do people keep saying it's better to have SMS 2FA then to not have it. The research says "websites should eliminate SMS based MFA altogether".

Re: SMS is not 2FA-secure

#378
post #26

Now I only need to find out on which ones of my 200+ accounts this feature is enabled… Honestly, it would be easier for me if the EU just made it illegal, forcing services to disable it for me.

Why? It's not "secure" but it's more secure than nothing. The paper mentions some websites that claim to use SMS 2FA, but actually use SMS as a single factor for password resey. While that's really bad I think the solution is to fix those broken implementations not to stop using SMS 2FA everywhere in favor of using nothing.

The paper also said, "websites should eliminate SMS based MFA altogether".

Re: SMS is not 2FA-secure

#379

Earlier quoted context omitted.

I've implemented something like this at Dontport. There are few work arounds but again security isn't something that's on top of traditional carrier because it's a problem with a small set of people

Nice product! https://dontport.com/ Do you know if something like this exists in europe?

Not yet, but soon we'll launch in Europe too
Post reply on HN