So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.
It’s time to stop using SMS for security
11–20 of 149 posts
Re: It’s time to stop using SMS for security
#12Re: It’s time to stop using SMS for security
#13So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
Phone numbers in general are insecure. There is no enforced verification system - people can receive calls from their own phone number, and people can fake the presented numbers. There is such a significant amount of spam callers as well. The FCC doesnt care.
The entire phone system in the U.S. needs to be remade with security, but powers that be really don't want that.
Re: It’s time to stop using SMS for security
#14My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!
Should be optional. I feel equally threatened by a potentially weak bank app running on my phone all the time as I would my carrier giving away the keys to the castle.
Re: It’s time to stop using SMS for security
#15Earlier quoted context omitted.
Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.
But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.
Re: It’s time to stop using SMS for security
#16So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
Pro: SMS 2FA is better than just passwords. In practise 2FA is primarily a hedge against credential surfing, with its other security properties more theoretical than practical, and it mostly works good enough for that use case. (Perfect is the enemy of good)
Con: there's lots of attacks related to social engineering the telecom into transfering your phone number. Real people have been compromised this way albeit this attack is pretty targeted.
There is also some concerns about evesdropping/mitm attacks. This is pretty unrealistic in my mind. If you're an on-path attacker for someone's cell phone convo that implies you have direct access to the victim, so the victim is pretty screwed regardless.
So in the end its a usability vs security tradeoff. Its a pretty close tradeoff so its not exactly a slam dunk in either direction.
Re: It’s time to stop using SMS for security
#17Earlier quoted context omitted.
Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.
But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.
Re: It’s time to stop using SMS for security
#18My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!
Re: It’s time to stop using SMS for security
#19Re: It’s time to stop using SMS for security
#20So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
SMS isn’t used as an additional layer but the only necessary layer to “recover” an account.