So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.
A hacker got all my texts for $16
101–110 of 296 posts
Re: A hacker got all my texts for $16
#102Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…
But what is an appropriate level of liability here? Phone companies never signed up to be the guardians of our digital lives, and the tech industry at large has just built a castle on shakey foundations. And there are obvious trade-offs here, if we make number portability harder, it means you're somewhat hostage to your phone provider.
Re: A hacker got all my texts for $16
#103Earlier quoted context omitted.
Authenticator Apps?
TOTP is only better than SMS against SIM swapping, a rare threat. They are identical against phishing, an enormously more common problem. For a typical user the delta in security when transitioning from SMS to TOTP is minimal.
Depends on your threat model, but unlike SIM swapping this may not be out of the reach of even a mildly technical angry ex.
Re: A hacker got all my texts for $16
#104Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…
But what is an appropriate level of liability here? Phone companies never signed up to be the guardians of our digital lives, and the tech industry at large has just built a castle on shakey foundations. And there are obvious trade-offs here, if we make number portability harder, it means you're somewhat hostage to your phone provider.
Re: A hacker got all my texts for $16
#105> While adding a number, Sakari provides the Letter of Authorization for the user to sign. Sakari's LOA says that the user should not conduct any unlawful, harassing, or inappropriate behaviour with the text messaging service and phone number. But as Lucky225 showed, a user can just sign up with someone else's number and receive their text messages instead. Um, what?!
This is bad news because following the law isn't a top priority when trying to hack someone.
Re: A hacker got all my texts for $16
#106Earlier quoted context omitted.
This would also be impossible if services stopped demanding your phone number to make an account. This is a growing trend in consumer services, and it's a privacy nightmare. Imagine if they demanded your SSN to sign up? A phone number is no different or less sensitive a unique identifier, perhaps even moreso these days. There are widespread reports of delivery businesses selling their phone number databases (with ass…
> Imagine if they demanded your SSN to sign up? A phone number is no different or less sensitive a unique identifier, perhaps even moreso these days. I have extremely bad news for you. US Social Security Numbers are not in fact unique, and the fact they're "sensitive" is a terrible joke because it's pretty easy to discover the SSN for an individual based on public information, especially older people because SSNs wer…
We should all stop doing either.
Re: A hacker got all my texts for $16
#107So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.
If they have a nice phone (modern iPhone or Android phone that is able to recognise who you are by fingerprint or facial recognition ought to be enough) that can do WebAuthn too, the actual recognition remains local to your device (so you're not giving some mysterious entity your face or fingerprint).
I'm assuming since they're "nontechnical" that you mean as a user, the user experience for WebAuthn is trivial, one touch. You do this to enroll the Yubikey, and then you do it whenever you need to prove who you are to the same site. It's entirely phishing proof, the credentials can't be stolen, you can keep one on your keyring or just leave it plugged into a personal PC all the time, it has excellent privacy properties, the biggest problem is too few sites do WebAuthn but Google and Facebook do, so that's a good start for non-technical people.
Which brings me to the other side, if your non-technical friends are wondering what their organisation should mandate, then again, WebAuthn, but this time I admit it's somewhat complicated. Somebody is going to need to at least research what product suits the userbase, and check boxes in the software they use, and at worst they need to do a bunch of software development. It's not crazy hard, but it's a bit trickier than yet another stupid password rule requirement. However unlike requiring passwords to contain at least two state birds and the name of an African country requiring WebAuthn will actually make you safer.
Re: A hacker got all my texts for $16
#108Earlier quoted context omitted.
This would also be impossible if services stopped demanding your phone number to make an account. This is a growing trend in consumer services, and it's a privacy nightmare. Imagine if they demanded your SSN to sign up? A phone number is no different or less sensitive a unique identifier, perhaps even moreso these days. There are widespread reports of delivery businesses selling their phone number databases (with ass…
> Imagine if they demanded your SSN to sign up? A phone number is no different or less sensitive a unique identifier, perhaps even moreso these days. I have extremely bad news for you. US Social Security Numbers are not in fact unique, and the fact they're "sensitive" is a terrible joke because it's pretty easy to discover the SSN for an individual based on public information, especially older people because SSNs wer…
Re: A hacker got all my texts for $16
#109Earlier quoted context omitted.
The difficulty there is evaluating which ones are reliable, secure, and easy to use. I'd welcome recommendations.
The integrated TOTP in 1Password is pretty good, it can grab the QR code off the screen and everything. https://support.1password.com/one-time-passwords/
Re: A hacker got all my texts for $16
#110Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…
When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.