Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

101–110 of 323 posts

Re: Second factor SMS: Worse than its reputation

#102
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

Turns out ads aren't just annoying little acts of psychological terrorism that eat up a lot of bandwidth and computing power, they are also the #1 vector for spreading scams and malware on the web. In other words: If you're trying to improve your security posture, installing an ad-blocker is one of the best things you can do. If you have less tech-savvy friends and relatives, I would strongly recommend setting up uBl…

It's to the point that even the US government (even with all its faults and lobbying) recommends using an ad blocker for this reason.

Re: Second factor SMS: Worse than its reputation

#103
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

I still don’t understand why banks just don’t use FIDO2/WebAuthn yet.

I’d much prefer to use a Yubikey over all other options at this point.

Re: Second factor SMS: Worse than its reputation

#104
The article conflates two issues that have different security implications.

The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp.

But 2FA codes seem notably less worrying. They are the second factor and require an attacker to have the password too. For these cases I'm much more relaxed about the use of SMS and the risks of interception.

Re: Second factor SMS: Worse than its reputation

#105
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

How did entering login and 2fa do the following things. 1. Login 2. Add payee 3. Create transaction 4. Verify transaction This appears to be a banking issue where they do not try to maximize the attack surface. Sure people will try to game the system by doing phishing but its the responsibility of banks to actively make it harder

I read it as the first 2fa code was used to login, then the system quickly attempted to add this new payee which required a second 2fa code, so the phishing site quickly sends another request stating the code saying the first was rejected.

Re: Second factor SMS: Worse than its reputation

#107
post #69

I've long suspected that companies which force SMS 2FA don't really care about security, they just want your phone number, and 2FA is a convenient bit of security theatre to make you give it to them.

No, most companies actually want your phone number for spam prevention.

I think the contribution of Spammers to the decline of the Internet is underrated.

Re: Second factor SMS: Worse than its reputation

#108
In the UK it seems that almost all online banking transactions are now verified by SMS. As far as I can tell this is required by law, and replaced the previous, bank card + card reader + pin verification system, which was not only more secure but also did not depend on having a working mobile phone with signal.

I hope that this will in due course be recognised as a terrible mistake and rectified. Unfortunately my hope is only faint.

Re: Second factor SMS: Worse than its reputation

#109
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

Kraken is a cryptocurrency exchange that utilizes (at least) two different TOTP codes, one for login and one for money transfers.

Re: Second factor SMS: Worse than its reputation

#110
post #104

The article conflates two issues that have different security implications. The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp. But 2FA codes seem notably less worrying. They are the second factor and require an attacker to have the password too. For these cases I'm much more relaxed about the use of SMS and the risks of interception.

> They are the second factor and require an attacker to have the password too.

For every leaked database of SMS messages there are 1000 leaked databases of account credentials

Post reply on HN