It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
Two-factor authentication is a mess
101–110 of 112 posts
Re: Two-factor authentication is a mess
#102I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…
Your particular situation might be a bit more annoying since all you want to do is close the account, but how does AWS know that? For all they know, you could be a malicious person trying to delete someone else's data.
Re: Two-factor authentication is a mess
#103Earlier quoted context omitted.
>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…
> It seems like every time I read about how SMS2FA was hacked it was done by some state level power... It seems to be a lot more vulnerable than that. Perhaps the biggest problem is that the phone companies do not treat your phone number as being a component of a 2FA system (and, to be fair, that was never the intent). This is from the linked article by Cody Brown, "How to lose $8k worth of bitcoin in 15 minutes with…
I think this sums up the problem.
BUT
SMS is likely the most convenient way for non geeks to use. And, as far as I am concern it seems only ( or especially ) Telecoms in US are vulnerable. In places like China / Hong Kong / Japan / Korea, you cant change your recovery code or what ever without your personal ID.
Re: Two-factor authentication is a mess
#104Earlier quoted context omitted.
As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned." More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care? [1] https://blog.namecheap.com/account-security/
It's not that they don't care. It's that $CARE_AMOUNT That formula would immediately shift if a high profile website registered on Namecheap encounters an SMS hijacking.
Re: Two-factor authentication is a mess
#105It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
Re: Two-factor authentication is a mess
#106Earlier quoted context omitted.
I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.
I'll take poor SMS based over none at all. https://lolware.net/assets/images/netregistry.png
Re: Two-factor authentication is a mess
#107Earlier quoted context omitted.
Namecheap does have 2fa... https://www.namecheap.com/support/knowledgebase/article.aspx... Do you mean because they only support SMS based 2fa? Considering they have a drop down menu it's possible they just have not had time to develop the other options?
As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned." More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care? [1] https://blog.namecheap.com/account-security/
Re: Two-factor authentication is a mess
#108Earlier quoted context omitted.
What annoys me most about using SMS for 2FA is that it's useless if you ever travel to another country and don't have global roaming enabled.
SMS receiving is free everywhere, it has nothing to do with data roaming and generic roaming - available on the network - has been free since I had a mobile phone (~17 years). Doesn't make it a the best option though.
Re: Two-factor authentication is a mess
#109Earlier quoted context omitted.
I thought Authy was TOTP?
it's TOTP, but it backs up your TOTP codes in the cloud and will happily restore them to any device that can receive SMSes to your phone number.
I'm torn between the insecurity of the cloud and being thankful that all accounts could be restored with ease.
Re: Two-factor authentication is a mess
#110Earlier quoted context omitted.
I've just moved my domains to porkbun.com instead, since they support TOTP and have equivalent or better prices.
I just buy my domain from AWS since I'm already using them for hosting. One less account to deal with and one less attack surface.
Yes, but your Amazon attack surface just got bigger.