SMS is not 2FA-secure
issms2fasecure.com
SMS is not 2FA-secure
1–10 of 379 posts
Re: SMS is not 2FA-secure
#2https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...
Re: SMS is not 2FA-secure
#3Re: SMS is not 2FA-secure
#4Re: SMS is not 2FA-secure
#5Of course there are much better 2FA options, but for the general public, they are probably too complicated to use.
Everyone understands SMS.
Re: SMS is not 2FA-secure
#6This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with sufficient access and some entrepreneur attitude.
The rule of thumb to protect against it:
- do not use SMS 2FA
- if you do, use a foreign SIP number with SMS capabilities
- if you HAVE to use local sim, use SIM that belongs to someone else and noone knows you use it
Re: SMS is not 2FA-secure
#7The only problem is there are very few services that get it right. Get it right means support multiple tokens and allow to truly disable any other means of logging in or recovering the password.
Most services seem bent on allowing many ways of logging in without giving a choice. For example, they will advertise they use 2fa tokens but then if you can't produce one they will still allow you to log in with SMS or mail (ie. password recovery by mail). Facebook will not even let you set up tokens without having SMS set up as a factor and the phone number verified.
I hope slowly developers will get more aware and they will be better tooling (and stack exchange answers to ctrl+c ctrl+v...) to do it correctly.
Re: SMS is not 2FA-secure
#8The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.
Re: SMS is not 2FA-secure
#9Better than not having it? Yes.
Better than committing a 4,096Kb PK to memory and confirming all interactions with mental arithmetic? No.
Re: SMS is not 2FA-secure
#10Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no". https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...