If RSA 2-factor tokens can be hacked (or "stolen" I guess, but the effect is the same), there's not much hope for the rest of us. Still a whole lot better than not doing 2 factor.
I know someone whose 2-factor phone authentication was hacked...
31–40 of 75 posts
Re: I know someone whose 2-factor phone authentication was hacked...
#32Earlier quoted context omitted.
(TL;DR at bottom) I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account. So, it seems to me that it's worse than having no second factor at all. After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact informati…
2FA using phone calls/SMS is basically lameness (similar to KBA; it protects against huge numbers of users with bad passwords being a vulnerability to the bank, and is a cheap compliance step, but provides no additional security to a targeted victim). Overarching all of this, there's a great opportunity to fix things in the desktop -> mobile transition; desktop OS security is IMO a lost cause, but mobile started from…
Re: I know someone whose 2-factor phone authentication was hacked...
#33I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...
Is it possible that the app runs in sandbox? Or is that already the case?
Why does that matter?
Re: I know someone whose 2-factor phone authentication was hacked...
#34Earlier quoted context omitted.
2FA using phone calls/SMS is basically lameness (similar to KBA; it protects against huge numbers of users with bad passwords being a vulnerability to the bank, and is a cheap compliance step, but provides no additional security to a targeted victim). Overarching all of this, there's a great opportunity to fix things in the desktop -> mobile transition; desktop OS security is IMO a lost cause, but mobile started from…
Apple cares too much about user experience than to foist this type of inanity on users.
Enter your passcode (or otherwise ID yourself to the device), and then everything "just works", with no need to remember or type passwords to every single site. Apple's already perfectly content to consider iPads and iPhones single-user devices, and with OS X, you can have multiple user logins with fast user switching.
Re: I know someone whose 2-factor phone authentication was hacked...
#35Wish he had stated which UK bank since most of the ones I am aware of use 2-factor authentication using a card reader device. They even seem to use an identical card reader!
I looked into this a while ago and I believe that Lloyds TSB must be the bank as it uses telephone authentication as follows: http://www.lloydstsb.com/security/security_improvements_we_h... "When you set up a new payment, we’ll give you a call to ensure that the instruction is coming from you. Step-by-step payment security: All you need is a telephone near you. You’ll be able to choose which number we call you on, pr…
While it's convenient as you don't have to remember the card reader when you want to login, it does worry me that it is less secure and vulnerable to keyloggers.
Edit: Halifax is also the same, but then it is owned by Lloyds and has recently transitioned its backend to the same platform as Lloyds uses.
Re: I know someone whose 2-factor phone authentication was hacked...
#36Earlier quoted context omitted.
(TL;DR at bottom) I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account. So, it seems to me that it's worse than having no second factor at all. After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact informati…
> I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. (Disclaimer: I work for a telephone and software-based 2factor provider) If your telephone-based 2 factor authentication is being thwarted by voice mail hacking, the problem lies in the implementation of the phone call itself, not necessarily the method. Unfortunately, certain solutions a…
Several companies were in the news after they got burned with it.
Re: I know someone whose 2-factor phone authentication was hacked...
#37I'm a pretty big fan of the rolling token 2-factor authentication model, with the app on your phone presenting you the rolling token. The Blizzard login app is the biggest single example that comes to mind. SMS really isn't secure, I think something like this could be a good next step to phase in.
Re: I know someone whose 2-factor phone authentication was hacked...
#38I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...
You can still press "don't have your phone?" and send a code through SMS, unless there's a way to disable that.
Re: I know someone whose 2-factor phone authentication was hacked...
#39I'm a pretty big fan of the rolling token 2-factor authentication model, with the app on your phone presenting you the rolling token. The Blizzard login app is the biggest single example that comes to mind. SMS really isn't secure, I think something like this could be a good next step to phase in.
How would this help preventing the situation described in the article?
Re: I know someone whose 2-factor phone authentication was hacked...
#40Earlier quoted context omitted.
You can still press "don't have your phone?" and send a code through SMS, unless there's a way to disable that.
Wait what? What good would receiving an SMS be if you don't have your phone?
Don't do what I did and stupidly use your google voice number. facepalm