Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?
US was the last to start using SMS and will apparently be the last to stop. The US was behind the curve because it was one of the few places in the world where local calls were free so people didn't bother with SMS for a long time. As for why it's still here, my guess is that the messaging space is extremely fractured here and it's the only text messaging someone is guaranteed to receive.
It’s time to stop using SMS for security
131–140 of 149 posts
Re: It’s time to stop using SMS for security
#132Later...
"Oh no! The phone company is doing a terrible job of solving our identity issue!"
Re: It’s time to stop using SMS for security
#133So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
I dont think this is a one sided debate. Pro: SMS 2FA is better than just passwords. In practise 2FA is primarily a hedge against credential surfing, with its other security properties more theoretical than practical, and it mostly works good enough for that use case. (Perfect is the enemy of good) Con: there's lots of attacks related to social engineering the telecom into transfering your phone number. Real people h…
That's from the point of view of somebody trying a denial of service attack target at some user, right?
Re: It’s time to stop using SMS for security
#134Earlier quoted context omitted.
That’s a horrendous hack. The security provisions of immediacy and liveness offered by SMS 2FA are rendered moot. That one needs to do this to work around the limitations solidifies in my mind that SMS is a poor 2FA solution and should be discontinued.
I'm surprised to see people here treating SMS "2FA" as anything but some snake oil annoyance to be worked around. I setup mine to go to a VOIP number where texts show up in email. I have plans to write something that looks for these messages and spits the code to a terminal or XMPP. My goal is to get that code into my paste buffer as quickly as possible. If you're using a password manager and have a security model th…
So much this, for Europe as well. Since PSD2, i cannot automatically check my bank account anymore, because of onerous and braindead 2FA requirements. And most banks do not offer a email-on-withdrawal function in any proper fashion, even their apps require regular reauthentication. But, since it is a braindead directive, you can install the 2FA app on the same phone as the bank app and have them talk to each other, thereby killing all the security benefit while still being annoying and non-automatic.
Re: It’s time to stop using SMS for security
#135Did anybody experiment using Twillio (or similar) to receive 2FA SMS? There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-d…
A lot of services reject numbers from known VoIP providers as a way to reject fraud (and I guess prevent people from defeating number-based marketing/advertising tracking by using unique numbers?). You can work around that by using lesser-known providers. In the UK, Andrews & Arnold ( https://www.aa.net.uk ) provide UK mobile numbers which don't seem to be rejected by anything.
Re: It’s time to stop using SMS for security
#136Earlier quoted context omitted.
https://l.sr.ht/XhOm.png If you actually want people to read your content, then don't put it on Medium. Not to mention that it's bloated as hell, requires JavaScript, burns batteries on mobile devices, and is full of loathesome spyware software.
Agree. It's also one of the annoying websites that breaks scrolling with yet more javascript crap. It's a lot of cruft for a text-with-images page that hasn't changed conceptually since 1995.
Re: It’s time to stop using SMS for security
#137Earlier quoted context omitted.
If only there were any perfectly good open standards for 2FA that were implemented by numerous free apps and/or secure hardware tokens...
TOTP is not good enough for banking where you really want to confirm specific transactions, not generate codes that an active attacker intercepting your session could use to do anything.
Kraken (a cryptocurrency exchange) allows you to set up one TOTP token for regular logins, and another, separate one for withdrawals... obviously not as good as individual confirmations but still a heck of a lot better than SMS!
Re: It’s time to stop using SMS for security
#138Earlier quoted context omitted.
So don't allow password reset over SMS. Email is hardly beter than sms, and we do password resets over email.
"Email is hardly better than SMS" is an absurd claim. As has been written SMS is not secure, easily hijacked, and potentially transmitted in the clear. By contrast email can be made arbitrarily secure nowadays via e.g. DANE/STS-MTA, and it's entirely up to an email provider how secure mailbox access is. Saying that "email is hardly better than SMS" when the former can be secured via DNSSEC/DANE and where the mailbox…
Being an on-path attacker against SMTP is not a realistic threat model for most users.
Re: It’s time to stop using SMS for security
#139Earlier quoted context omitted.
I dont think this is a one sided debate. Pro: SMS 2FA is better than just passwords. In practise 2FA is primarily a hedge against credential surfing, with its other security properties more theoretical than practical, and it mostly works good enough for that use case. (Perfect is the enemy of good) Con: there's lots of attacks related to social engineering the telecom into transfering your phone number. Real people h…
> Pro: SMS 2FA is better than just passwords. That's from the point of view of somebody trying a denial of service attack target at some user, right?
Imo, if people used passwords correctly, all common 2fa solutions other than yubikeys would be useless.
Re: It’s time to stop using SMS for security
#140Earlier quoted context omitted.
Why don't you just get a dedicated "virtual" phone number for this purpose? It's not expensive. Skype is an obvious choice, but there are many other providers. Then you have a stable number and can read SMS via app web UI. I switched to the same method a few years ago. It's useful even if you don't travel much, just to not tie 2FA to your phone and for not giving all those services your real number.
I have two virtual (US) numbers - one through Twilio (which I've enable short-code receive support for), and one on Google Voice. Both have failed to receive 2-factor messages from providers over the years. Very occasionally the Google Voice number is blocked explicitly by the provider as a VOIP number. It's just not a reliable 100% replacement for "real" SMS in my experience. Google Voice is close to acceptable as a…
I've heard good things, can you port a cell number in or is it strictly voip? (I haven't done anything phreaking adjacent in ages)