Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

21–30 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#21

This is a really good point, "cell service will always be available" is a classic incorrect assumption that needs to be shattered. I do kinda wonder what the correct way forward is, I think it's silly that ISPs don't support this type of SMS over wifi but I have no clue why. Meanwhile TOTP apps are rightly pointed out to be too numerous with unclear trade offs, I'm surprised ios and android don't have native TOTP app…

> I'm surprised ios and android don't have native TOTP apps (afaik). They do. Google's Authenticator is as close as it gets to a native Android app, and your secret keys are sync'ed in Google's cloud for a while now (it's a shame they waited so long). Apple's Keychain has supported TOTP for ages too. That said OTPs over RCS instead of SMS are a major improvement if you don't mind your phone number being used as an id…

Google Authenticator is a separate app that you need to download from Google Play. Native android solution is Google Password app which is pre-installed (at least on Pixel) and its functionality is extremely rudimentary even compared to Apple Passwords. No TOTP support there.

I think that Google does not care about security for their users, because their passwords app is clearly some intern work, not something really well thought. They just slapped it to mark a checkbox in their "Chrome password autofill" TODO list and moved on to a more pressing issues like implementing user tracking and extracting more ads revenue. Apple had similar issues for years, but I think that their recent releases significantly improved.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#22
post #14

TOTP, HOTP. SMS needs your number, your data is more valuable if marketers can assign your real name to your data. or aggregating all data about you, phone number helps with that.

>your data is more valuable if marketers can assign your real name to your data. or aggregating all data about you, phone number helps with that. This is mostly a red herring because most of the places that require SMS TOP already have your full name/address (eg. financial institutions, healthcare providers) or are in a position to intercept communications that they can infer that information (eg. google). If apps/si…

yes marketer gets your name from bank etc, you can not lie there about your name. and everywhere else, your data is connected just your number.

same problem with signal messenger or facebook messenger building databases of numbers and contacts. neo4j clone from palantir.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#23
> other options available to her include

> port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi

That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do).

I really wish that were illegal. A phone number is a phone number.

> she turned on wifi calling on her phone. now she could receive SMS messages from friends and family, but 2FA codes still weren't coming through.

Interesting, I was under the impression that SMS over IMS was implemented transparently to external senders. But given what a hack the entire protocol is, I'm not really surprised.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#25
post #12

Earlier quoted context omitted.

> When you choose an eccentric lifestyle Many "eccentric" lifestyles are not chosen. For instance not owning a smartphone or not having access to power easily is not necessarily limited to well-off tech-savv hipsters who want to make a statement, homeless people, older people in less connected areas or people in developing countries can also be in that situation. When you make your services depend on specific access,…

Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.

> Not all choices need to be subsidized.

Interesting choice of vocabulary.

You could decide not to serve people without also describing them as freeloaders in order to feel morally righteous about your choice.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#26
post #13

Much agreement with the others that there's too much expectation. I rented a lime scooter for the first time last year. But, I messed up my VPN settings so I had no Internet. There was no way to tell the scooter I'm done. Even though it was stopped, no button to end the ride. They refunded me the extra time (which was maybe 5 of the 10 minutes) because they could see it was just stopped at a bike rack on gps. Idk wha…

Reminds me of DHL parcel lockers in Germany. The new ones don't have a screen anymore, so you are forced to use their app to use the locker, which somehow requires both a working bluetooth connection to communicate with the locker, AND you need a working internet connection on your phone. What's the point of that?! The parcel locker evidently already has a working internet connection, that should be enough.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#27
post #14

TOTP, HOTP. SMS needs your number, your data is more valuable if marketers can assign your real name to your data. or aggregating all data about you, phone number helps with that.

>your data is more valuable if marketers can assign your real name to your data. or aggregating all data about you, phone number helps with that. This is mostly a red herring because most of the places that require SMS TOP already have your full name/address (eg. financial institutions, healthcare providers) or are in a position to intercept communications that they can infer that information (eg. google). If apps/si…

I don't understand how this post stacks up against the myriad of communications apps that not only require phone verification when creating a new profile (and maybe SMS2FA), but put great effort into blocking as many VoIP/burner/prepaid numbers as possible.

"Most"? maybe "a troubling few"?

Phone verification is absolutely a widely exploited data mining opportunity, I don't see how it's a red herring at all. It's one of the worst surveillance mechanisms we live with today, only partially waved away with the 2000's concept of burner numbers.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#28

TOTP are okay for some things but often regulation means each code/challenge needs to be tied to a specific action. TOTP codes typically last for 30s and mulitple actions can happen within 30s, so it's not possible to use TOTP in many cases. PUSH approval could be used instead but then you need to download an app for every service you use, which isn't very convenient. PASSKEYS offer a solution which will work on both…

Beyond "just" being phishing resistant, for banking/payments, WebAuthN even has the opportunity of providing "what you see is what you sign":

The Secure Payment Confirmation [1] extension to WebAuthN supports using passkeys on third-party sites (think merchant checkouts) and including signed structured messages (think "confirm payment of at on ").

It wouldn't be crazy to imagine authenticators with small OLED displays to provide an end-to-end secure channel for displaying that information, similarly to how cryptocurrency hardware wallets already do it.

Of course, this would require a certain popular hardware and software manufacturer with a competing payment solution to implement the extension...

[1] https://www.w3.org/TR/secure-payment-confirmation/

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#29
post #25

Earlier quoted context omitted.

Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.

> Not all choices need to be subsidized. Interesting choice of vocabulary. You could decide not to serve people without also describing them as freeloaders in order to feel morally righteous about your choice.

People choosing to live in rural areas aren't freeloaders. Until they demand the rest of us subsidize them. The demand for subsidies is what makes a freeloader, not the lifestyle choice.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#30

1. Download the Google Voice app. This phone number works for some but not all 2FA services. Not all, because some explicitly forbid GV numbers because they're afraid of fraud. GV can receive SMS messages over wifi. 2. Ask the cell phone company for a femtocell. These used to be called "AT&T Microcells" and they were cheap. I used one before cell service improved because I live in the mountains. But apparently AT&T d…

> Subscribe to mightytext.net so you can get SMS on your computer. I don't know if this works if your cell phone can't get signal

It can't – how would it?

The only entity that can forward texts is the carrier, and I doubt that that service is integrated with all US carriers to somehow get them forwarded (which is technically quite difficult for various legacy protocol reasons).

Apple's satellite messaging service is the only solution I know of that can somehow hook into carriers' SMS home router (or IMS equivalent) infrastructure to intercept and out-of-band forward SMS.

Post reply on HN