Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?
It's still used a lot also in Europe for OTP codes (banking and such), as well as for shops/deliveries, where they send an SMS for order status changes (shipped from the warehouse, in transit, ...).
It’s time to stop using SMS for security
51–60 of 149 posts
Re: It’s time to stop using SMS for security
#52There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-day number.
Re: It’s time to stop using SMS for security
#53Yahoo! Japan, One of the most famous website in Japan, forces users to use insane auth method: SMS 1FA. It even accepts phone number as login ID. This is really stupid.
That being said, a certain class of SIM cards (SMS-only cards, without voice functionality) is exempt from most of these strict checks as far as I know, and there are other technical vulnerabilities that are probably just waiting to happen in Japan before they're taking seriously.
I'm a little bit surprised that Yahoo! Japan went for SMS as the only authentication method, since their one of the main sponsors of the FIDO Japan WG.
Re: It’s time to stop using SMS for security
#54So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
Then you have to worry about fraud, and whether telcos in have been hacked, or are corrupt, and are leaking messages to bad guys.
I've seen entire (small) countries drop out, too. Usually the way you find out about this is that support notices an uptick in users in complaining about not getting messages, or you notice that the entirety of some geography isn't successfully completing the transactions you tried to protect with SMS. Er, you did consult the (changing) prefix database and phone number parser to (semi) reliably determine a geography from a phone number, right? Isn't parsing phone numbers fun?
It's fractally terrible and expensive, and I haven't even talked about APIs yet.
Re: It’s time to stop using SMS for security
#55Did anybody experiment using Twillio (or similar) to receive 2FA SMS? There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-d…
Re: It’s time to stop using SMS for security
#56Earlier quoted context omitted.
Not all people have or want smartphones.
Don't know about the US but I haven't seen anybody using classic GSM for years now...
Re: It’s time to stop using SMS for security
#57So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
SMS 2FA costs money per message. It's also subject to telecom rules -- you usually need to buy short codes by geography if you're sending at scale, and that involves dealing with bureaucracies at scale, too. Getting a short code can take weeks and cost thousands of dollars. Of course you can always pay to have other people do that management for you. But you're going to pay, nonetheless. Then you have to worry about…
This is only because the telephone cartels control the networks. The same is more or less true of Internet. Operators have advocated for anti-open-wifi laws across the globe so they can sell their internet access plans (xDSL/3G), when we could have free networking for all in all places.
Seriously though, why couldn't we have FREE privacy-friendly networking as a public service?
Re: It’s time to stop using SMS for security
#58So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…
Actually, the myGov thing was a real piece of work. They offer secret questions as a second factor that you can opt to use instead of SMS codes (and yes, secret questions are stupid), but when I did that, it silently unlinked my Australian Tax Office account. I tried to link it up again (a bit of a pain in its own right), and it told me that ATO has decided that it won’t let you link it up if you use secret questions as the second factor technique. Seriously. So I had to switch back. Oh yeah, they do also have a third option, an app of their own that can generate codes (not TOTP), but that app had something like 2 stars on Google Play Store, with many reviews saying it didn’t work at all, so I didn’t even bother trying that.
When I’m in Australia with my phone handy, SMS verification seems not too bad, but when out of the country and not roaming, it may vary between very inconvenient and completely debilitating.
Re: It’s time to stop using SMS for security
#59So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…
Re: It’s time to stop using SMS for security
#60So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
Like Microsoft Authenticator. It wanted way too many permissions on my phone, and provided less security than my Yubikey authenticator. My yubikey provides a standard open OTP but requires the device to generate it (phone tap or plugin via USB to computer or phone).
Open standards are better. I don't want a different authenticator app for every website. It's so much simpler to use a single app.