Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

11–20 of 149 posts

Re: It’s time to stop using SMS for security

#11
post #9
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.

But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.

Re: It’s time to stop using SMS for security

#13
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

SMS is not secure, that's why. Police have used special devices to intercept messages on a broad scale without any warrent, which means individuals can too. Service providers are well known to send "replacement" sim cards out to people who then use it to access 2FA accounts. Happened to H3H3 on YouTube.

Phone numbers in general are insecure. There is no enforced verification system - people can receive calls from their own phone number, and people can fake the presented numbers. There is such a significant amount of spam callers as well. The FCC doesnt care.

The entire phone system in the U.S. needs to be remade with security, but powers that be really don't want that.

Re: It’s time to stop using SMS for security

#14
post #5

My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!

Should be optional. I feel equally threatened by a potentially weak bank app running on my phone all the time as I would my carrier giving away the keys to the castle.

It is optional. I'm a USAA customer as well, here's a screenshot from thirty seconds ago: https://i.imgur.com/boA4dc1.png

Re: It’s time to stop using SMS for security

#15
post #9

Earlier quoted context omitted.

Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.

But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.

Well, if somebody can mess with ss7 they wouldn't need even that.

Re: It’s time to stop using SMS for security

#16
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I dont think this is a one sided debate.

Pro: SMS 2FA is better than just passwords. In practise 2FA is primarily a hedge against credential surfing, with its other security properties more theoretical than practical, and it mostly works good enough for that use case. (Perfect is the enemy of good)

Con: there's lots of attacks related to social engineering the telecom into transfering your phone number. Real people have been compromised this way albeit this attack is pretty targeted.

There is also some concerns about evesdropping/mitm attacks. This is pretty unrealistic in my mind. If you're an on-path attacker for someone's cell phone convo that implies you have direct access to the victim, so the victim is pretty screwed regardless.

So in the end its a usability vs security tradeoff. Its a pretty close tradeoff so its not exactly a slam dunk in either direction.

Re: It’s time to stop using SMS for security

#17
post #9

Earlier quoted context omitted.

Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.

But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.

Social engineering is all about convincing people to do things they aren't supposed to do.

Re: It’s time to stop using SMS for security

#19
Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

Re: It’s time to stop using SMS for security

#20
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

There are several methods of hard and soft attack which are stupidly easy where ability to temporarily capture your phone number is the only necessary authentication factor.

SMS isn’t used as an additional layer but the only necessary layer to “recover” an account.

Post reply on HN