Live data from Hacker News

Let's Ban SMS 2FA

lorendb.dev

11–20 of 46 posts

Re: Let's Ban SMS 2FA

#11
I like Fastmail’s position on SMS 2FA: https://www.fastmail.help/hc/en-us/articles/360058752374-Usi...

In short: offer SMS 2FA, and indeed push users reasonably firmly¹ into adding SMS recovery at the least because for almost all users that’s the right balance of convenience and security, but certainly don’t limit it to SMS, offering better methods like U2F and TOTP.

(Disclosure: I was employed by Fastmail for a few years, but these decisions had been made long before I got there.)

—⁂—

¹ When you set up 2FA, it forces you to add a recovery phone number, except that you can skip that by holding down Ctrl or something, undocumented but support will tell you if you complain about having to do it; or, after creation, you can just remove it again. So yeah, “reasonably firmly”.

Re: Let's Ban SMS 2FA

#12
post #5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

[deleted]

Re: Let's Ban SMS 2FA

#13
post #5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

>When the barrier to adoption and inconvenience to the user is so low

Is it low though? I'm not sure my parents could figure out how to use an authenticator app.

Re: Let's Ban SMS 2FA

#14
post #5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

Tell that to my retirement-age mother.

Re: Let's Ban SMS 2FA

#15
post #5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

One of my coworkers (at a social services agency) was the victim of a sim swap. If it can happen to her it can happen to anyone. They gained access to her bank accounts, all her email, as well as PayPal and Venmo. She ended up switching phone providers.

Re: Let's Ban SMS 2FA

#16
post #6

Sure, SMS 2FA isn't great. It may even be bad. But calling for government legislation to make that decision for other people is definitely bad. This is something you ban internally at your company or chose not to use yourself. Calling for government use of force against people who use SMS 2FA is really nasty. That said, maybe I'm missing come implicit context here and he's only taking about banning it for incorporate…

I'm talking about banning implementation of SMS 2FA server side. Individual users wouldn't be banned from using it, but it would be illegal to provide it as a company (or at least for important sectors like banks).

Re: Let's Ban SMS 2FA

#17
post #5

Earlier quoted context omitted.

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

One of my coworkers (at a social services agency) was the victim of a sim swap. If it can happen to her it can happen to anyone. They gained access to her bank accounts, all her email, as well as PayPal and Venmo. She ended up switching phone providers.

Yes, and sometimes even locked houses are broken into.

Re: Let's Ban SMS 2FA

#18

I like Fastmail’s position on SMS 2FA: https://www.fastmail.help/hc/en-us/articles/360058752374-Usi... In short: offer SMS 2FA, and indeed push users reasonably firmly¹ into adding SMS recovery at the least because for almost all users that’s the right balance of convenience and security, but certainly don’t limit it to SMS, offering better methods like U2F and TOTP. (Disclosure: I was employed by Fastmail for a few…

100%

Banning SMS 2FA is the wrong approach, because it is better than no 2FA and every cell phone supports it, out of the box.

What should be mandated is (a) giving users choice of a non-SMS 2FA method (probably just pick one for a standard, e.g. TOTP) & (b) allowing users to explicitly disable SMS 2FA on their account.

As a least common denominator, SMS is fair. But there should be an option to do better, securely, if a user wishes.

Re: Let's Ban SMS 2FA

#19
Doesn't a SIM swap attack impact more than just a single user account of a service? They lose access to SMS and calls from their phone. I'd argue they learn that there's a security issue earlier and cause them to take action (contact carrier or authorities).

A friend's Mom's Facebook account was recently hacked. They didn't have 2FA set. Hacker changed her email address in the Meta account. Meta did not notify her via email of the email address change. She did not use fb for a couple of months and had no idea this had happened. Then she began receiving calls from cousins and relatives saying their account was hacked after receiving a link in a message from her.

I would've advised her to use SMS 2FA. A lot of non-technical folks from an older generation don't even bother with email.

Re: Let's Ban SMS 2FA

#20
post #5

Earlier quoted context omitted.

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

>When the barrier to adoption and inconvenience to the user is so low Is it low though? I'm not sure my parents could figure out how to use an authenticator app.

I've noticed that for sites I visit rarely there will be some sort of drift from the auth app and I'm often forced to use a backup code.

I'd rather just have a whole list of allowable factors and the opportunity to configure one or more of them depending on my personal risk tolerance.

Post reply on HN