My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!
It’s time to stop using SMS for security
91–100 of 149 posts
Re: It’s time to stop using SMS for security
#92Earlier quoted context omitted.
Even easier are the sites that do this: "Please enter the phone number where we should send your one-time 2FA code: [_______]" I've had that happen on more than one site. Surely anyone who stole my password would just put in their own number?
They would surely compare the number to the one they have registered, right ?
One of my accounts requires a phone number to verify every single time I login. I have no clue why, and it accepts absolutely any phone number.
I have no clue what the purpose is aside from forcing me to give sensitive information to other people when my phone isn't available or I'm traveling (which I've been forced to do already).
Re: It’s time to stop using SMS for security
#93Earlier quoted context omitted.
When I hear many reports of things flat-out not working in this way, I’m suspicious that it won’t work for me with my Samsung Galaxy J1 (2016) on Android 5.1, which Google has progressively broken by means of Google Play Services updates. As some typical examples of things that have been broken by Google Play Store updates: Fastmail notifications now only come through on wifi or (I found out last week) if Maps (by Go…
Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services. That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number…
I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town where an Optus tower a few hundred metres away became my best option for internet, 50/25Mbps and far more solid than any NBN anecdote I’ve heard.
Re: It’s time to stop using SMS for security
#94Earlier quoted context omitted.
I’m an Australian that was in India for the last year (just arrived back, up to day 2 of my 14 day quarantine). Anything that has needed to verify me through SMS (e.g. filing my Australian tax return via myGov, paying for things with my credit card if they used the fancy security thing, like most airlines do and Amazon apparently does, and logging into one or two things) has required me to contact my parents to turn…
> has required me to contact my parents to turn on and check the old phone I left with them Why didn't you use a sms to email forwarding app on a phone connected to a charger? They are free on play store and work really well.
Re: It’s time to stop using SMS for security
#95Earlier quoted context omitted.
Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.
But that is not really true for most countries. In my country, to get a sim ported you need to go to the shop and present your identification.
Re: It’s time to stop using SMS for security
#96Earlier quoted context omitted.
Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services. That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number…
“That old”, and yet the phone’s not even three years old (my instance of the model, that is; the model was at that point two years old and is thus now five years old). Sigh. I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town whe…
Well, Android 5.1 was EOL in 2015, so you willingly bought an unsupported model. I'm not saying Android has any sensible long-term support (in fact, I spent the last weekend installing LineageOS because my 2018 phone doesn't have support anymore), but this instance is hardly Google's fault.
Re: It’s time to stop using SMS for security
#97Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?
Is this an american thing, like SSN identity theft?
Or checks... let's not forget checks...
Re: It’s time to stop using SMS for security
#98Earlier quoted context omitted.
Oof yeah, if you're running an Android version that old I would not expect much to work that relies on Google services. That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number…
“That old”, and yet the phone’s not even three years old (my instance of the model, that is; the model was at that point two years old and is thus now five years old). Sigh. I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town whe…
In this case I think Android 5 was 2014, so almost 7 years old a this point.
Amaysim are pretty good, Though if you can convince them to add a security note to your account its worth it (Colleague of mine had his mobile number hijacked while on holiday and they used it to access a few of his online accounts)
Re: It’s time to stop using SMS for security
#99Re: It’s time to stop using SMS for security
#100So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…
Skype is an obvious choice, but there are many other providers.
Then you have a stable number and can read SMS via app web UI.
I switched to the same method a few years ago. It's useful even if you don't travel much, just to not tie 2FA to your phone and for not giving all those services your real number.