Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

101–110 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#101
post #62

I remember in 2014 going to play a Bitcoin poker game at some Google VP's house way up in the hills, Charlie Lee was there. We tried to buy-in at the beginning to a pot address but no one could get their Coinbase SMS 2FA to work because we had no reception so we ended up writing IOUs on scraps of paper.

[deleted]

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#102
post #52

Earlier quoted context omitted.

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?

yeah, I use GV with all sorts of things that don't normally allow most likely as a result of being grandfathered in - i.e., I suspect they don't recheck old active numbers as being invalid per VOIP classifications/etc.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#103

Earlier quoted context omitted.

I'm pretty sure you could always manually export a QR code for every one of your secret keys.

This was around 2016 and that was not an option at the time. edit: the app used to be open source: https://github.com/google/google-authenticator-android/ "By design, there are no account backups in any of the apps."

My bad, that's too far in the past. I've changed Android phones several times between 2017 and 2020, and I remember using the QR codes exports.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#105
post #94

Earlier quoted context omitted.

Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.

Exactly! Why should I subsidize sewers in town?

[flagged]

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#106
post #81

Earlier quoted context omitted.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

This is probably compliance-related. For me, TOTP isn’t “something I have”, it’s another thing I toss into my password manager and sync to all devices. I really agree with it, but that’s probably their rationale.

I do the same, and it somewhat defeats the spirit of 2FA, but I still believe it's more secure. It's basically a second password where intercepting it in transit once isn't enough to be able to repeat the login in the future.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#107
post #68

Earlier quoted context omitted.

compared to prices for the rest of the world, you wouldn't want to use Fi for data anyway... just get a local or even "travel" esim and run with dual sims.

I’ve found that it’s easy to data-only eSIM package through an app store app such as Saily, but it’s harder to find a service that gives you a “real” phone number when traveling internationally. Any recommendations?

I don’t have direct experience, but I’ve heard about or seen the following online (there may be many other MVNOs). All of them are activated with an eSIM and they have WiFi calling, which means it’s a real US phone number as any other and you can make/receive calls and send/receive SMS as long as you’re connected to the internet via WiFi or through a data connection on your second SIM on the phone. If you wish, you can buy real roaming too, but that tends to be expensive.

* Tello

* Red Pocket

* Good to Go Mobile

If you’re looking for a real local phone number in the location you’re traveling to, then eSIM providers like Airalo can handle that (Airalo has “global plans” that support voice and SMS). Getting such a connection for voice and SMS, as compared to a data SIM alone, would be expensive. So you could get a data eSIM that works locally and use that for “WiFi” calling/SMS with the providers mentioned above.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#108
post #30

Earlier quoted context omitted.

> Subscribe to mightytext.net so you can get SMS on your computer. I don't know if this works if your cell phone can't get signal It can't – how would it? The only entity that can forward texts is the carrier, and I doubt that that service is integrated with all US carriers to somehow get them forwarded (which is technically quite difficult for various legacy protocol reasons). Apple's satellite messaging service is…

> Apple's satellite messaging service is the only solution I know of that can somehow hook into carriers' SMS home router Are you sure it actually does this? I thought it was a pseudo-carrier that could speak MAP / Diameter, and just pretended you were roaming with them when you used satellite connectivity, perhaps with the original carrier's knowledge and consent. As far as I understand, that's how this kind of serv…

I assumed that that's how it works because I couldn't think of any other way to achieve the observed behavior, but pseudo roaming sounds plausible too, and presumably requires much less work on the carriers' side!

Would that approach also allow the extra functionality they seem to be offering, such as only recently messaged numbers and emergency contacts being able to send messages to satellite users, though? I suppose they could just reject all MT-Forward-SM with sender numbers they don't like?

> As far as I understand, that's how this kind of service usually gets implemented.

Do you have any other examples for solutions like this? Are you thinking of (pre-VoWifi) carrier apps or services that could receive texts, sometimes on multiple devices?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#109
post #52

Earlier quoted context omitted.

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?

Mine has worked as well but it used to be a landline when I first acquired it many moons ago.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#110
post #7

I wonder what the companies requiring 2FA think about uncompleted 2FA bounces. Deterred fraudster? Short attention span? SMS sucks?

I assume it shows up as a hAcKErS sToPpEd figure in a quarterly report where they pat themselves on the back for it along with CAPTCHA hassling, blocking browsers that are too secure, network address bans, popups about "passkeys", forced password changes practically every login, etc. If they had any sense they wouldn't be pushing this nonconsensual trash to begin with.
Post reply on HN