Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

31–40 of 149 posts

Re: It’s time to stop using SMS for security

#31

When dis medium become a paywalled site? Do writers on it know that you can only read 3 articles before you are required to create an account and login? (like pinterest)

Use a private window to get around this. It's not a very advanced mechanic (yet).

Re: It’s time to stop using SMS for security

#32
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I don't think that's true though. Maybe you haven't SEND any, but I bet you receive a lot. At least I do: from my bank, from some of my bank accounts, from my mobile service provider, from my parcel delivery service. From Coinbase, from PayPal... The list goes on and on.

Re: It’s time to stop using SMS for security

#33
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

It's still used a lot also in Europe for OTP codes (banking and such), as well as for shops/deliveries, where they send an SMS for order status changes (shipped from the warehouse, in transit, ...).

Re: It’s time to stop using SMS for security

#34
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

Absolutely this. I currently have a document from my bank, that they emailed me. Which I’m suppose to print, write all my personal info on, plus a copy of my passport and FAX to them!!

All because I want to change my phone number, and I’m overseas.

Which I only need to change (or even have associated with my account at all) because they refuse to offer any other 2FA option.

Re: It’s time to stop using SMS for security

#35
post #23

Earlier quoted context omitted.

Not all people have or want smartphones.

Don't know about the US but I haven't seen anybody using classic GSM for years now...

I wonder how much of an overlap there is between those still using classic GSM phones, and those who listen to vinyl records.

Re: It’s time to stop using SMS for security

#36
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

SMS is a standard and easy way to send/receive messages without using incompatible messaging apps owned by third parties. And the only way for me (except email) since I don't use Android or iOS.

Re: It’s time to stop using SMS for security

#37
post #32
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I don't think that's true though. Maybe you haven't SEND any, but I bet you receive a lot. At least I do: from my bank, from some of my bank accounts, from my mobile service provider, from my parcel delivery service. From Coinbase, from PayPal... The list goes on and on.

I live in Germany. Only SMS I receive nowadays is from PayPal. For whatever reason they use it arbitrarily in addition to the other 2FA I set up.

Banks all have their own 2FA apps.

Re: It’s time to stop using SMS for security

#38
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

There are several methods of hard and soft attack which are stupidly easy where ability to temporarily capture your phone number is the only necessary authentication factor. SMS isn’t used as an additional layer but the only necessary layer to “recover” an account.

This is not emphasized enough. Many companies enable SMS both as a second authentication factor AND a single-factor account recovery mechanism.

As bad as passwords, savvy users can use a password manager and generate unique high-entropy passwords, but if the web site is forcing SMS on you, you lose all that security and now have to rely on vulnerable telco infra that is out of your control and was never built to facilitate authentication.

Re: It’s time to stop using SMS for security

#39
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

In russia it is common for authorities to temporary switch phone to another sim card, then switch it back without user even noticing it. This method was widely used to target dissidents and access their accounts.

To sum it, 2fa via sms gives only an illusion of safety.

Re: It’s time to stop using SMS for security

#40
The title is misleading. This is not in fact "stop using SMS for anything", but "stop using SMS for security purposes". There is a great reason why SMS should still be in use: nothing interoperable exists with an equal adoption rate. I will not rehash the usual argument about WeChat and Whatsapp, there is plenty of discussion about them.
Post reply on HN