Live data from Hacker News

Let's Ban SMS 2FA

lorendb.dev

1–10 of 46 posts

Re: Let's Ban SMS 2FA

#2
This installing work 2fa apps on my personal phone also needs to go. I actually have no idea how to transfer all of these things if I drop my phone and break it. Absolutely crazy that so much is tied up in this terrible idea.

Re: Let's Ban SMS 2FA

#3
So the case against SMS 2FA boils down to

“There are two factors, but the second factor is something a determined actor can get around by SIM swapping.”

But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people.

This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be a vault door and fines if you leave a hide-a-key rock anywhere near your house.”

Re: Let's Ban SMS 2FA

#4
Tell that big fintech banks in Europe. I think they it boils down that they really do not want to deal with people locking themselves out of their account by losing a normal 2fa totp.

Re: Let's Ban SMS 2FA

#5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

Re: Let's Ban SMS 2FA

#6
Sure, SMS 2FA isn't great. It may even be bad. But calling for government legislation to make that decision for other people is definitely bad. This is something you ban internally at your company or chose not to use yourself. Calling for government use of force against people who use SMS 2FA is really nasty. That said, maybe I'm missing come implicit context here and he's only taking about banning it for incorporated persons like the Digital Markets Act. That would be okay. But if it applies to human persons that's really bad.

And even if I assume all the premises are true and roll with it, shouldn't password based logins be "banned" first? And we all know that's infeasible.

Re: Let's Ban SMS 2FA

#8
post #2

This installing work 2fa apps on my personal phone also needs to go. I actually have no idea how to transfer all of these things if I drop my phone and break it. Absolutely crazy that so much is tied up in this terrible idea.

Yes, keeping track of second factors is... definitely not a solved problem.

Relatedly, I have to manually maintain a text file of all of the sites I've used my Yubikeys on so that if I lose one I know where-all I have to rotate to a new one.

Re: Let's Ban SMS 2FA

#10
post #2

This installing work 2fa apps on my personal phone also needs to go. I actually have no idea how to transfer all of these things if I drop my phone and break it. Absolutely crazy that so much is tied up in this terrible idea.

I managed to convince a company to give the option of TOTP once I made it clear that they would have to provide me a phone (and pay for its service) if they required one as my contact clearly stated the company was responsible for providing the necessary tools for work, and that TOTP is otherwise completely free.
Post reply on HN