Live data from Hacker News

I know someone whose 2-factor phone authentication was hacked...

williamedwardscoder.tumblr.com

71–75 of 75 posts

Re: I know someone whose 2-factor phone authentication was hacked...

#71
Relatedly, it is possible to read the 2FA SMS message on android without pattern unlocking the phone -- it appears in the notification bar briefly.

I don't know whether it amounts to a security vulnerability, but it certainly makes it that little bit weaker.

Re: I know someone whose 2-factor phone authentication was hacked...

#72
post #46
post #31

Earlier quoted context omitted.

The attack was on a phone call message for 2-factor authentication "Your one time password is XXXXXX. Please use this to login now" not an RSA token.

I believe the OP is referring to http://www.finextra.com/news/fullstory.aspx?newsitemid=22375

The point of multi-factor authentication is not that the additional factors are infallible. Rather, the point is, when one factor fails, there remain other factors still in place.

When RSA was compromised, accounts in which RSA was used as an additional factor remained protected by their remaining uncompromised factors - allowing time to replace the RSA factor.

Re: I know someone whose 2-factor phone authentication was hacked...

#73

Two factor authentication is still, in my opinion, the strongest way to go. This case is really the phone company's fault, maybe they'll learn from this and start teaching the customer support reps what the difference is between a correct password and an incorrect password.

(TL;DR at bottom) I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account. So, it seems to me that it's worse than having no second factor at all. After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact informati…

"it seems to me that it's worse than having no second factor at all"

I agree with you totally. A second authentication that is much weaker than the first (prone to social engineering or even googling like the endemic first name of your favorite uncle questions) can be worse than just having one strong authentication. For some reason many companies think that building a bridge out of very many weak components makes a strong bridge. That is not true though, you have a weak bridge in the end.

Re: I know someone whose 2-factor phone authentication was hacked...

#74

Relatedly, it is possible to read the 2FA SMS message on android without pattern unlocking the phone -- it appears in the notification bar briefly. I don't know whether it amounts to a security vulnerability, but it certainly makes it that little bit weaker.

Message previews in the notification bar can be disabled.

Re: I know someone whose 2-factor phone authentication was hacked...

#75

Earlier quoted context omitted.

No, I don't think that's the point. The point is more like "something I can access" is not a factor that's as strong as "something I know/am/have".

I liked this so much I added it to the article at the bottom :)

Thanks!
Post reply on HN