SMS is not 2FA-secure
101–110 of 379 posts
Re: SMS is not 2FA-secure
#102And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?
at least one of my banks cannot SMS me codes, I can't remmeber which, so I always forget, try it, and have to select another method. I THINK it's chase, but I'm not sure. They have my correct phone number, but for years now, the code just... never shows up.
Re: SMS is not 2FA-secure
#103Is SMS 2FA Secure? No, I agree. Is SMS 2FA enough for most of the people today? Yes Is SMS a cost-benefit solution for most uses? Yes
Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes. It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.
With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.
Re: SMS is not 2FA-secure
#104Earlier quoted context omitted.
My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.
>with appropriate DNA extraction procedures Carriers have already demonstrated their complete across the board failure to have appropriate security procedures. Your DNA isn't hard to find, you leave it literally everywhere you go. And do you really want mobile carriers creating a DNA database of their every customer? The same companies that already sell your location data to bounty hunters? That's going to be a big n…
Re: SMS is not 2FA-secure
#105Re: SMS is not 2FA-secure
#106Earlier quoted context omitted.
Awareness may make providers more willing to switch to a better 2FA, such as TOTP.
Sadly, providers seem to be going the other way. I had a service try to bully me into disabling TOTP in favor of SMS 2FA this week.
Hint: if a store ask for a phone number to get a discount, try the local areacode then 634 5789. This is from an old song, and many people seem to have created "anonymous" account with it!
Re: SMS is not 2FA-secure
#107Earlier quoted context omitted.
As another person said, you're literally leaving it everywhere you go. If you need a blood sample, then would donating blood be considered compromising security? Identity is what your DNA is. Password is a secret. Your DNA is not a secret.
Consider if you're kidnapped and extracted DNA in unwilling manner
Re: SMS is not 2FA-secure
#108The big benefit of SMS for the website is that it outsources the problem of lost 2FA tokens. What happens if the user loses a yubikey. Or changes phones and did not back up their TOTP. With SMS authentication, even if the user loses a phone, they can go down to the local cell phone store and get a new phone on their number and be back in business without the website having to get involved.
> What happens if the user loses a yubikey. Always buy two. ;-) Joking aside, I've moved almost every 2FA to hard token, soft-token, or google voice. But the root of trust is still LastPass & Google. I don't see an easy way out of dependency other than power of attorney. Even worse: I worry what happens to my protected assets as I age and possibly face memory loss.
I got bitten in a bad way!
Hopefully twilio will start creating "recognized" numbers someday, as my twilio number is unusable for TOTP. There seems to be a blacklist of all twilio voip numbers.
Re: SMS is not 2FA-secure
#109And yet my bank (Chase) only supports email and sms 2fa with no option for OTP/TOTP. Is this just a institution dragging their feet or are there more regulatory reasons why they won't allow more secure authentication?
Re: SMS is not 2FA-secure
#110My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…
https://www.kaspersky.com/blog/hacking-cellular-networks/106...