Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

21–30 of 149 posts

Re: It’s time to stop using SMS for security

#21
post #12

Yahoo! Japan, One of the most famous website in Japan, forces users to use insane auth method: SMS 1FA. It even accepts phone number as login ID. This is really stupid.

EDF, the largest electricity provider in Europe does the same in France. Actually, it even manages to do a bit worse: 1FA using SMS or email, but choice is left to the potential attacker.

I've spent countless hours trying to explain them the issue in 2019 and gave up as nobody cared.

Re: It’s time to stop using SMS for security

#22
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

US was the last to start using SMS and will apparently be the last to stop. The US was behind the curve because it was one of the few places in the world where local calls were free so people didn't bother with SMS for a long time. As for why it's still here, my guess is that the messaging space is extremely fractured here and it's the only text messaging someone is guaranteed to receive.

Re: It’s time to stop using SMS for security

#23
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

Not all people have or want smartphones.

Re: It’s time to stop using SMS for security

#24
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

US mobile plans gave enormous buckets (thousands) of SMS messages a month to mobile users 10-15 years ago, so there was little incentive to move to other mobile messaging systems.

Conversely, the lack of such generous SMS allotments in most non-US countries drove widespread adoption of WhatsApp/Facebook Messenger/etc.

Re: It’s time to stop using SMS for security

#25
post #18

My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!

Email is much worse than SMS.

It could be better if the sender's SMTP server forced the use of TLS. Most emails are now sent encrypted but it isn't usually enforced.

If your control your own receiving server then it would be hard for someone to intercept the message.

Re: It’s time to stop using SMS for security

#27
post #9

Earlier quoted context omitted.

Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.

But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.

Same here (Denmark with Hi3G), but they often forget. I've had a new SIM issued for myself just by saying the phone number.

Of course that's several orders of magnitudes harder to do than just finding a leaked password somewhere, so it's still nice to have SMS as 2FA compared to nothing. It'll stop the mass bots.

Re: It’s time to stop using SMS for security

#28
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS.

This has bitten me a few times, sometimes in desperate situations. Like when I've needed to log in to Airbnb to message a host, transfer some cash from my bank account, access my frequent flyer account, etc. Far too many sites don't provide 2FA over email, or through an app like Google Authenticator - they can only do it over SMS.

Yeah, I know I could set up roaming. But it's an easy thing to forget, since I change phone numbers every couple of years (for both personal and work phones). And it's not always cheap.

It's also just a huge pain to have to go through and change every account I have, any time I change numbers. A lot of accounts that I only use occasionally are configured with one of my many old phone numbers, which don't work anymore. This usually involves a call to tech support to fix it.

Re: It’s time to stop using SMS for security

#29
post #23
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

Not all people have or want smartphones.

Don't know about the US but I haven't seen anybody using classic GSM for years now...

Re: It’s time to stop using SMS for security

#30
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I think is because of Apple iMessage, since a lot of Americans gave iPhone and they use iMessage, which sends SMS when the phone on the other end is not an iPhone.
Post reply on HN