Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

91–100 of 149 posts

Re: It’s time to stop using SMS for security

#91

My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!

What did they switch to? I've been wanting to use my u2f token for my bank account for awhile but haven't seen any that support that yet

Re: It’s time to stop using SMS for security

#92
post #79

Earlier quoted context omitted.

Even easier are the sites that do this: "Please enter the phone number where we should send your one-time 2FA code: [_______]" I've had that happen on more than one site. Surely anyone who stole my password would just put in their own number?

They would surely compare the number to the one they have registered, right ?

Google oftentimes doesn't.

One of my accounts requires a phone number to verify every single time I login. I have no clue why, and it accepts absolutely any phone number.

I have no clue what the purpose is aside from forcing me to give sensitive information to other people when my phone isn't available or I'm traveling (which I've been forced to do already).

Re: It’s time to stop using SMS for security

#93

Earlier quoted context omitted.

When I hear many reports of things flat-out not working in this way, I’m suspicious that it won’t work for me with my Samsung Galaxy J1 (2016) on Android 5.1, which Google has progressively broken by means of Google Play Services updates. As some typical examples of things that have been broken by Google Play Store updates: Fastmail notifications now only come through on wifi or (I found out last week) if Maps (by Go…

Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services. That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number…

“That old”, and yet the phone’s not even three years old (my instance of the model, that is; the model was at that point two years old and is thus now five years old). Sigh.

I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town where an Optus tower a few hundred metres away became my best option for internet, 50/25Mbps and far more solid than any NBN anecdote I’ve heard.

Re: It’s time to stop using SMS for security

#94

Earlier quoted context omitted.

I’m an Australian that was in India for the last year (just arrived back, up to day 2 of my 14 day quarantine). Anything that has needed to verify me through SMS (e.g. filing my Australian tax return via myGov, paying for things with my credit card if they used the fancy security thing, like most airlines do and Amazon apparently does, and logging into one or two things) has required me to contact my parents to turn…

> has required me to contact my parents to turn on and check the old phone I left with them Why didn't you use a sms to email forwarding app on a phone connected to a charger? They are free on play store and work really well.

It never occurred to me to seek such a thing. As I wrote my earlier comment here, I wondered to myself whether there might be an app or service to help with this, but it’s too late now. But even then, I’m not sure I’d want to leave a phone plugged in all year, even with its battery removed.

Re: It’s time to stop using SMS for security

#95
post #9

Earlier quoted context omitted.

Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.

But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.

In all countries, you have but to prove to some lowly paid telco employee's satisfaction that you are the owner of the number. That is not a serious impediment.

Re: It’s time to stop using SMS for security

#96

Earlier quoted context omitted.

Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services. That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number…

“That old”, and yet the phone’s not even three years old (my instance of the model, that is; the model was at that point two years old and is thus now five years old). Sigh. I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town whe…

> the phone’s not even three years old

Well, Android 5.1 was EOL in 2015, so you willingly bought an unsupported model. I'm not saying Android has any sensible long-term support (in fact, I spent the last weekend installing LineageOS because my 2018 phone doesn't have support anymore), but this instance is hardly Google's fault.

Re: It’s time to stop using SMS for security

#97
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

Tbh I haven't heard of SMS hijacking in Europe either.

Is this an american thing, like SSN identity theft?

Or checks... let's not forget checks...

Re: It’s time to stop using SMS for security

#98

Earlier quoted context omitted.

Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services. That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number…

“That old”, and yet the phone’s not even three years old (my instance of the model, that is; the model was at that point two years old and is thus now five years old). Sigh. I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town whe…

Yeah the unfortunate situation of Android devices means that you may have only just bought the phone but if it isn't supported you could be running a very old OS version.

In this case I think Android 5 was 2014, so almost 7 years old a this point.

Amaysim are pretty good, Though if you can convince them to add a security note to your account its worth it (Colleague of mine had his mobile number hijacked while on holiday and they used it to access a few of his online accounts)

Re: It’s time to stop using SMS for security

#100
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

Why don't you just get a dedicated "virtual" phone number for this purpose? It's not expensive.

Skype is an obvious choice, but there are many other providers.

Then you have a stable number and can read SMS via app web UI.

I switched to the same method a few years ago. It's useful even if you don't travel much, just to not tie 2FA to your phone and for not giving all those services your real number.

Post reply on HN