NIST SP 800-63B §5.1.3.3. https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB
Second factor SMS: Worse than its reputation
101–110 of 323 posts
Re: Second factor SMS: Worse than its reputation
#102A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
Turns out ads aren't just annoying little acts of psychological terrorism that eat up a lot of bandwidth and computing power, they are also the #1 vector for spreading scams and malware on the web. In other words: If you're trying to improve your security posture, installing an ad-blocker is one of the best things you can do. If you have less tech-savvy friends and relatives, I would strongly recommend setting up uBl…
Re: Second factor SMS: Worse than its reputation
#103A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
I’d much prefer to use a Yubikey over all other options at this point.
Re: Second factor SMS: Worse than its reputation
#104The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp.
But 2FA codes seem notably less worrying. They are the second factor and require an attacker to have the password too. For these cases I'm much more relaxed about the use of SMS and the risks of interception.
Re: Second factor SMS: Worse than its reputation
#105A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
How did entering login and 2fa do the following things. 1. Login 2. Add payee 3. Create transaction 4. Verify transaction This appears to be a banking issue where they do not try to maximize the attack surface. Sure people will try to game the system by doing phishing but its the responsibility of banks to actively make it harder
Re: Second factor SMS: Worse than its reputation
#106Re: Second factor SMS: Worse than its reputation
#107I've long suspected that companies which force SMS 2FA don't really care about security, they just want your phone number, and 2FA is a convenient bit of security theatre to make you give it to them.
I think the contribution of Spammers to the decline of the Internet is underrated.
Re: Second factor SMS: Worse than its reputation
#108I hope that this will in due course be recognised as a terrible mistake and rectified. Unfortunately my hope is only faint.
Re: Second factor SMS: Worse than its reputation
#109A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
Re: Second factor SMS: Worse than its reputation
#110The article conflates two issues that have different security implications. The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp. But 2FA codes seem notably less worrying. They are the second factor and require an attacker to have the password too. For these cases I'm much more relaxed about the use of SMS and the risks of interception.
For every leaked database of SMS messages there are 1000 leaked databases of account credentials