Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

111–120 of 149 posts

Re: It’s time to stop using SMS for security

#111
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I’d love a parable of how using SMS as part of a layered security verification is somehow unacceptably vulnerable.

The article gives plenty of examples. Here they are as links:

https://www.vice.com/en/article/a37epb/t-mobile-alert-victim... https://www.vice.com/en/article/xyezmn/we-were-warned-about-... https://www.vice.com/en/article/mg7bd4/how-a-hacker-can-take... https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...

The latest is the most severe, in summary - a gaping flaw in SMS lets hackers take over phone numbers in minutes by simply paying a company to reroute text messages.

So if you insert SMS 2FA in your security chain as a fallback authentication method, you're leaving it wide open to exploits and none of your other 2FA security like TOTP or tokens matters, because the attacker can just take over a customer/admin account using the SMS authentication to prove they are the user concerned then change those methods. In some cases you'll require an email as well, and in some you'll manage to send an email to that old email address before it can be changed, but many places don't, particularly mobile apps tend to rely on the phone number, and most people don't monitor every email address 24/7, so lots of damage can be done in a short period.

SMS really needs to be fixed and it's really debatable whether it adds security or subtracts security in the meantime, even in a layered approach.

Re: It’s time to stop using SMS for security

#112
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

SMS is not secure, that's why. Police have used special devices to intercept messages on a broad scale without any warrent, which means individuals can too. Service providers are well known to send "replacement" sim cards out to people who then use it to access 2FA accounts. Happened to H3H3 on YouTube. Phone numbers in general are insecure. There is no enforced verification system - people can receive calls from the…

> Happened to H3H3 on YouTube

Also same attack vector used to get access to Jack Dorsey's Twitter account I believe.

Re: It’s time to stop using SMS for security

#113
post #9
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

Probably the SIM porting attacks, where telco employees are vulnerable to being socially engineered to letting an attacker port your phone number over to another device. Also this new attack, which is more stealthy.

Or even porting accidents. If anything goes wrong when you are switching carriers and intentionally having your number ported to the new carrier, you could be left with a non-working number until you get it resolved (which can be difficult because your phone is no longer working...).

And even if nothing goes wrong, it can take up to a day for the number to port in the US. That's a day without being about to login to anyplace that requires SMS 2FA.

A TOTP app on my phone, on the other hand, works fine regardless of whether or not my phone number currently works with the SIM in that phone.

Re: It’s time to stop using SMS for security

#114
post #12

Yahoo! Japan, One of the most famous website in Japan, forces users to use insane auth method: SMS 1FA. It even accepts phone number as login ID. This is really stupid.

EDF, the largest electricity provider in Europe does the same in France. Actually, it even manages to do a bit worse: 1FA using SMS or email, but choice is left to the potential attacker. I've spent countless hours trying to explain them the issue in 2019 and gave up as nobody cared.

What's the incentive for attackers?

Re: It’s time to stop using SMS for security

#115

Earlier quoted context omitted.

“That old”, and yet the phone’s not even three years old (my instance of the model, that is; the model was at that point two years old and is thus now five years old). Sigh. I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town whe…

> the phone’s not even three years old Well, Android 5.1 was EOL in 2015, so you willingly bought an unsupported model. I'm not saying Android has any sensible long-term support (in fact, I spent the last weekend installing LineageOS because my 2018 phone doesn't have support anymore), but this instance is hardly Google's fault.

> you willingly bought an unsupported model

I think most people on HN are comfortable doing a bit of research to see when a device will stop receiving support, but I don't think that's reasonable to expect from everyone.

If I walk into a shop and buy a phone, new in the box, it seems pretty reasonable to assume that it's operating system will work with whatever apps I install from it's built in store, and that it will receive security patches for at least a few years. That seems to me like a pretty low bar, but it's absolutely not the case in the Android ecosystem.

Re: It’s time to stop using SMS for security

#116
post #16
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I dont think this is a one sided debate. Pro: SMS 2FA is better than just passwords. In practise 2FA is primarily a hedge against credential surfing, with its other security properties more theoretical than practical, and it mostly works good enough for that use case. (Perfect is the enemy of good) Con: there's lots of attacks related to social engineering the telecom into transfering your phone number. Real people h…

While a password+SMS 2FA would be better than just password, the problem is that SMS often gets also turned into a single-factor password recovery mechanism; and SMS alone is worse security-wise than a decent password.

Re: It’s time to stop using SMS for security

#117
post #54

Earlier quoted context omitted.

SMS 2FA costs money per message. It's also subject to telecom rules -- you usually need to buy short codes by geography if you're sending at scale, and that involves dealing with bureaucracies at scale, too. Getting a short code can take weeks and cost thousands of dollars. Of course you can always pay to have other people do that management for you. But you're going to pay, nonetheless. Then you have to worry about…

> SMS 2FA costs money per message. This is only because the telephone cartels control the networks. The same is more or less true of Internet. Operators have advocated for anti-open-wifi laws across the globe so they can sell their internet access plans (xDSL/3G), when we could have free networking for all in all places. Seriously though, why couldn't we have FREE privacy-friendly networking as a public service?

Why?

Here you have to buy access to certain frequency ranges(big money required). The bidding happens from time to time. Building the network infrastructure is not cheap either and requires specialists to work for you.

I'd rather buy that 4G from a company that can deliver it everywhere I go than move backwards in progress to use some random WIFI hosted by Joe that fights over the same frequency as John's across the road.

The "cartel" networks work pretty good tbh. They just have stagnated in everything else but networking.

Re: It’s time to stop using SMS for security

#118
post #23

Earlier quoted context omitted.

Not all people have or want smartphones.

Don't know about the US but I haven't seen anybody using classic GSM for years now...

I've seen that many elderly folk prefer phones with tactile buttons to touchscreens, so they keep using non-smartphones.

Re: It’s time to stop using SMS for security

#119
post #5

Earlier quoted context omitted.

Should be optional. I feel equally threatened by a potentially weak bank app running on my phone all the time as I would my carrier giving away the keys to the castle.

If only there were any perfectly good open standards for 2FA that were implemented by numerous free apps and/or secure hardware tokens...

TOTP is not good enough for banking where you really want to confirm specific transactions, not generate codes that an active attacker intercepting your session could use to do anything.

Re: It’s time to stop using SMS for security

#120
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

I have also travelled a lot in the past...

You presumably do have a "home" country in the sense of where your bank accounts are, get a cheap permanent sim/phone no with roaming, buy the tiniest phone you can off amazon and stick it in as your 2factor permanent number.

Yes, you have to keep that phone charged, but your problem is now permanently solved, it's how I did it.

Post reply on HN