Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

81–90 of 149 posts

Re: It’s time to stop using SMS for security

#81
post #52

Did anybody experiment using Twillio (or similar) to receive 2FA SMS? There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-d…

A lot of services reject numbers from known VoIP providers as a way to reject fraud (and I guess prevent people from defeating number-based marketing/advertising tracking by using unique numbers?).

You can work around that by using lesser-known providers. In the UK, Andrews & Arnold (https://www.aa.net.uk) provide UK mobile numbers which don't seem to be rejected by anything.

Re: It’s time to stop using SMS for security

#82
post #52

Did anybody experiment using Twillio (or similar) to receive 2FA SMS? There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-d…

I tried this for a bit, but it turned out a number of services (Google, Facebook) would fail (silently) when sending an SMS to Twilio numbers.

It might no longer be true as there was a Twilio support page that confirmed this behaviour but is now just a 404[0] (though you can see a mention of it on StackOverflow[1])

[0] https://support.twilio.com/hc/en-us/articles/223134367-Sendi... [1] https://stackoverflow.com/a/55852784

Re: It’s time to stop using SMS for security

#83
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

In the US, most cell phone users are on unlimited voice/text plans. There is no cost to most consumers for sending and receiving SMS in the US. Also, the Line / What's App / WeChat equivalent in the US is Facebook Messenger. That is how sms has won.

Re: It’s time to stop using SMS for security

#84
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

This is why I switched over to a VOIP number instead. SMS works everywhere I have internet, and if I have to I just pick up a data-only sim card for wherever I am. Can even check my messages online. Probably not as secure, and wouldn't work well if I was regularly calling people, but for the most part it works fine and costs $1 a month.

Re: It’s time to stop using SMS for security

#85

Earlier quoted context omitted.

The app does work by the way. It is a steaming hot pile of garbage where the government has yet again decided to not use a widely accepted standard. But if you just need to login to myGov every few months to check something or do your tax return it works better then the SMS (Just don't lose the phone it is installed on, because you can't link it to a new one without ringing and wading through security checks)

When I hear many reports of things flat-out not working in this way, I’m suspicious that it won’t work for me with my Samsung Galaxy J1 (2016) on Android 5.1, which Google has progressively broken by means of Google Play Services updates. As some typical examples of things that have been broken by Google Play Store updates: Fastmail notifications now only come through on wifi or (I found out last week) if Maps (by Go…

Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services.

That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number.

Re: It’s time to stop using SMS for security

#86

Earlier quoted context omitted.

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

This is why I switched over to a VOIP number instead. SMS works everywhere I have internet, and if I have to I just pick up a data-only sim card for wherever I am. Can even check my messages online. Probably not as secure, and wouldn't work well if I was regularly calling people, but for the most part it works fine and costs $1 a month.

$1/mo? Which provider is that? Twilio?

Re: It’s time to stop using SMS for security

#87
post #79

Earlier quoted context omitted.

Even easier are the sites that do this: "Please enter the phone number where we should send your one-time 2FA code: [_______]" I've had that happen on more than one site. Surely anyone who stole my password would just put in their own number?

They would surely compare the number to the one they have registered, right ?

You'd think they would make it more clear ("verify your 2fa number"). Maybe they want to bait criminals into entering their own or something.

Re: It’s time to stop using SMS for security

#88
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

Beyond it being insecure, I see it used too often as the only alternative to yet another proprietary MFA app. Like Microsoft Authenticator. It wanted way too many permissions on my phone, and provided less security than my Yubikey authenticator. My yubikey provides a standard open OTP but requires the device to generate it (phone tap or plugin via USB to computer or phone). Open standards are better. I don't want a d…

TOTP is definitely an open standard. https://tools.ietf.org/html/rfc6238

Re: It’s time to stop using SMS for security

#89

Earlier quoted context omitted.

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

I’m an Australian that was in India for the last year (just arrived back, up to day 2 of my 14 day quarantine). Anything that has needed to verify me through SMS (e.g. filing my Australian tax return via myGov, paying for things with my credit card if they used the fancy security thing, like most airlines do and Amazon apparently does, and logging into one or two things) has required me to contact my parents to turn…

> has required me to contact my parents to turn on and check the old phone I left with them

Why didn't you use a sms to email forwarding app on a phone connected to a charger?

They are free on play store and work really well.

Re: It’s time to stop using SMS for security

#90
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

SMS is completely insecure. Not only can it be passively sniffed along the way, not only can malicious actors reroute your number, not only can pretty much any employee at your telco access it, not only can pretty much any employee at your telco get tricked into rerouting it, but by default (and therefore for the vast majority of users), it'll show up while the phone is locked!

It's equivalent to taping your key to your back door. Sure, someone has to go to your back door first to see it, but then they're in.

Post reply on HN