Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

11–20 of 379 posts

Re: SMS is not 2FA-secure

#11
The big benefit of SMS for the website is that it outsources the problem of lost 2FA tokens. What happens if the user loses a yubikey. Or changes phones and did not back up their TOTP. With SMS authentication, even if the user loses a phone, they can go down to the local cell phone store and get a new phone on their number and be back in business without the website having to get involved.

Re: SMS is not 2FA-secure

#12
I wish more websites (and other application protocols) would support client-side certificates in addition to the username and password for authentication.

Re: SMS is not 2FA-secure

#13
My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1].

0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s...

1: https://www.kaspersky.com/blog/ss7-hacked/25529/

I thought both these vectors were already common knowledge to HN readers.

Re: SMS is not 2FA-secure

#14
Now I only need to find out on which ones of my 200+ accounts this feature is enabled… Honestly, it would be easier for me if the EU just made it illegal, forcing services to disable it for me.

Re: SMS is not 2FA-secure

#15

But how else are you supposed to encourage users to give you their phone numbers so you can track them better?

No company would ever do that, right? Especially a social media company. Clearly there would be public outrage and their stock would plummet.

Re: SMS is not 2FA-secure

#16
I thought this was going to be one of the otherwise-plaintext black and white web pages with NO. centered in the middle, but interestingly it's actual research, and a nice read (even if nothing new) at that.

Re: SMS is not 2FA-secure

#17

Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no". https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...

Not sure why you're getting downvoted, I hadn't heard of this before and found it quite amusing as well as somewhat relevant to the topic, although a blanket statement providing not much value.

My vote would just be not to vote (neutral). There is certainly more (in)appropriate stuff to downvote.

Re: SMS is not 2FA-secure

#18

The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.

I think at some point goolge used SMS 2FA as a sole factor in account recovery. So there, you really were worse off with SMS 2FA enabled.

Re: SMS is not 2FA-secure

#19

The answer is no, but is it more secure than no 2FA? Of course there are much better 2FA options, but for the general public, they are probably too complicated to use. Everyone understands SMS.

Well if that's the case they could still offer true MFA. Make at least SMS 2FA mandatory but offer OTP/token based MFA.

Obviously banks are a place with a lot of low-value targets and a few very high-value targets, but the cost to implement MFA is the same so they might as well do it.

Re: SMS is not 2FA-secure

#20
post #15

But how else are you supposed to encourage users to give you their phone numbers so you can track them better?

No company would ever do that, right? Especially a social media company. Clearly there would be public outrage and their stock would plummet.

For anyone who doesn't detect the sarcasm or is unfamiliar: https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
Post reply on HN