Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

51–60 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#51
post #38

TOTP, HOTP. SMS needs your number, your data is more valuable if marketers can assign your real name to your data. or aggregating all data about you, phone number helps with that.

Neither TOTP nor HOTP provide "what you see is what you sign" property, unfortunately, which can be critical for bank and other transactions. "Enter this code only if you want to pay to " is much more secure than "enter your TOTP here", which is a lot like issuing a blank check in comparison (and in fact required by regulation in the EU, for example). Not even WebAuthN provides that property on a compromised computer…

Yeah this is a big problem. I have been sent 2F messages via WhatsApp by some services (e.g. PayPal).

This isn't great, but better then SMS and having to have a separate app for each authenticating service though.

A vendor neutral service would be a lot nicer.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#52
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me.

It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#53
She should switch cell phone providers. I’ve never had a problem receiving 2FA SMS from five digit numbers over WiFi, and heavily rely on it working. I know this for sure because I have an automation set to put my phone in airplane mode + wifi when I get home. (It eats battery when there’s a weak 5g signal.)

SMS 2FA is terrible though.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#54

Earlier quoted context omitted.

Google Authenticator is a separate app that you need to download from Google Play. Native android solution is Google Password app which is pre-installed (at least on Pixel) and its functionality is extremely rudimentary even compared to Apple Passwords. No TOTP support there. I think that Google does not care about security for their users, because their passwords app is clearly some intern work, not something really…

It's not ideal but there's been some progress. I'm not sure we can blame Google for not pushing their Authenticator more, most services have been dead set on SMS and are now slowly moving to Passkeys, probably for the best.

I don't want Google to push their Authenticator, I want Google to retire their Authenticator, implement TOTP codes in their Passwords app (it's very trivial to implement) and implement passkeys on Google Chrome Linux (now those are not trivial, but if they push passkeys so hard, they could at least implement them). I also want to be able to store any items in Google Passwords manager, like ssh username/password, my bank cards, software serial codes and other sensitive information (again trivial to implement, just provide me multiline textedit with notes). I also want password generator in their app. I also want to configure multiple domains for entry, like microsoft.com + live.com. Are those big requests? I don't think so.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#55
post #35

Earlier quoted context omitted.

We should support the rural lifestyle choice. For one, the food you eat comes from there.

Food doesn't come from remote mountainous areas. Farm fields may not have cell service but living way out there isn't required even for farmers. I grew up on a farm so it's funny when people on the internet try to educate me about farms as if I've never heard of them.

>Food doesn't come from remote mountainous areas.

I must be imagining the farms that I pass in the mountains in the middle of nowhere when I go backpacking. Surely your argument isn't, "My farm was here, so it's impossible for other farms to be in different locales"?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#56

If cell service is available in at least one area of the property, you could have a dedicated sim for receiving SMS 2FA and use a 4G router to forward the SMS to an email, e.g. Teltonika have this functionality [1]. The 4G router also has the benefit of being able to use externally mounted antennas. Which might help in low signal areas. Not ideal, but might at least be a solution for some people. [1]: https://wiki.te…

While that is a solution someone could use, it wouldn't work for the subject here: > she usually doesn't even have service 100 meters down the road.

Yeah wont work for everyone, but a directional antenna mounted high up on house might have a better chance than a phone antenna.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#57
post #25

Earlier quoted context omitted.

> Not all choices need to be subsidized. Interesting choice of vocabulary. You could decide not to serve people without also describing them as freeloaders in order to feel morally righteous about your choice.

People choosing to live in rural areas aren't freeloaders. Until they demand the rest of us subsidize them. The demand for subsidies is what makes a freeloader, not the lifestyle choice.

>Until they demand the rest of us subsidize them.

I think the discussion is less around "subsidizing" them and more why requiring a cellphone with 2FA to exist and do basic things is kinda stupid.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#58
1. 2FA over SMS is only $23 away from a compromised phone service

2. People love binding individual accounts to specific IP addresses, and large marketing firms especially like websites that use free DNS service to quietly track said users across the session

3. Much like DRM, the account auto constrains a single user to a single IP. Makes sense... unless you run a business account with a dozen people clearing a shared inbox

4. SMS inbox phone numbers are $2.75, and that requirement is bypassed if the company smartphone hardware/emulation is in use for account "recovery"

5. SIM hijacking and email server snooping is far more common than people like to admit

6. People feel safer, but it only increases the CVE difficulty level slightly above third world skill levels

This is why we can't have nice things =3

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#59

Earlier quoted context omitted.

Every second SMS authorization does not reach my phone. Just yesterday I couldn't log in to my GitHub from new computer, because my phone did not receive authentication code. I didn't have any bans because of that. I think that a lot of people experience similar problems, so it makes no sense to look for fraudsters, 99.9999% will be false negatives.

There's really no reason to use SMS 2FA for GitHub though, you can literally pick anything else.

Anything else could be lost. I can always get new SIM card for this number. I don't need to backup it and I can't accidentally delete it. That's the biggest reason for me to link phone number everywhere. I'd hate to lose access to my GitHub account.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#60
post #30

1. Download the Google Voice app. This phone number works for some but not all 2FA services. Not all, because some explicitly forbid GV numbers because they're afraid of fraud. GV can receive SMS messages over wifi. 2. Ask the cell phone company for a femtocell. These used to be called "AT&T Microcells" and they were cheap. I used one before cell service improved because I live in the mountains. But apparently AT&T d…

> Subscribe to mightytext.net so you can get SMS on your computer. I don't know if this works if your cell phone can't get signal It can't – how would it? The only entity that can forward texts is the carrier, and I doubt that that service is integrated with all US carriers to somehow get them forwarded (which is technically quite difficult for various legacy protocol reasons). Apple's satellite messaging service is…

Sms and signaling system 7 are incredibly insecure. It has to be so it can support scammers that call you from spoofed numbers.

Anyway, it’s probably possible to make a service like that. You might need to route through a country with permissive laws.

Post reply on HN