Let's Ban SMS 2FA
lorendb.dev
Let's Ban SMS 2FA
1–10 of 46 posts
Re: Let's Ban SMS 2FA
#2Re: Let's Ban SMS 2FA
#3“There are two factors, but the second factor is something a determined actor can get around by SIM swapping.”
But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people.
This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be a vault door and fines if you leave a hide-a-key rock anywhere near your house.”
Re: Let's Ban SMS 2FA
#4Re: Let's Ban SMS 2FA
#5So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…
Re: Let's Ban SMS 2FA
#6And even if I assume all the premises are true and roll with it, shouldn't password based logins be "banned" first? And we all know that's infeasible.
Re: Let's Ban SMS 2FA
#7Re: Let's Ban SMS 2FA
#8This installing work 2fa apps on my personal phone also needs to go. I actually have no idea how to transfer all of these things if I drop my phone and break it. Absolutely crazy that so much is tied up in this terrible idea.
Relatedly, I have to manually maintain a text file of all of the sites I've used my Yubikeys on so that if I lose one I know where-all I have to rotate to a new one.
Re: Let's Ban SMS 2FA
#9Re: Let's Ban SMS 2FA
#10This installing work 2fa apps on my personal phone also needs to go. I actually have no idea how to transfer all of these things if I drop my phone and break it. Absolutely crazy that so much is tied up in this terrible idea.