Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

131–140 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#131
Along the same lines, am I the only one who thinks it's weird that when logging in on a desktop PC the average bank requires a:

- username

- password

- one time generated 16 digit number

- SMS confirmation

- email confirmation

- phone call with an associate

- retinal scan

- DNA sample

Whereas to log in on mobile all you potentially need is a 4 digit pin which a passerby could easily observe, then yank the phone from your hand?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#132
post #81

Earlier quoted context omitted.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

This is probably compliance-related. For me, TOTP isn’t “something I have”, it’s another thing I toss into my password manager and sync to all devices. I really agree with it, but that’s probably their rationale.

The real problem is not having a (trusted) way of seeing what you are consenting to by entering a TOTP (which can be phished).

SMS-OTP, with all its downsides, allows attaching a message of who you're paying how much to the actual code.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#134

TOTP are okay for some things but often regulation means each code/challenge needs to be tied to a specific action. TOTP codes typically last for 30s and mulitple actions can happen within 30s, so it's not possible to use TOTP in many cases. PUSH approval could be used instead but then you need to download an app for every service you use, which isn't very convenient. PASSKEYS offer a solution which will work on both…

I have some rural Duo customers and we always end up having to dial up the timeouts because it can take longer than a minute to receive a push notification in some areas. One of them has told me that duo is the only 'notification thingy' that works because the other implementations won't wait long enough.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#135
post #27

Earlier quoted context omitted.

I don't understand how this post stacks up against the myriad of communications apps that not only require phone verification when creating a new profile (and maybe SMS2FA), but put great effort into blocking as many VoIP/burner/prepaid numbers as possible. "Most"? maybe "a troubling few"? Phone verification is absolutely a widely exploited data mining opportunity, I don't see how it's a red herring at all. It's one…

To single out Meta properties, I'd point to both Instagram and WhatsApp. It was an official policy early on that you could only create a WhatsApp account if it was connected to a "real" cellular number, I think the same has been true about Instagram for a while in that every time I tried to create an account without a cellular number it didn't work. Put in a cellular number and it worked just fine.

Last time I tried to create a throwaway account for facebook it didn't actually ask for my mobile number. Just automatically banned me for being suspicious and then demanded a video of my head with no assurance that would actually help. I generally avoid meta but it seems like most craiglist sales have moved to facebook marketplace.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#136
post #55

Earlier quoted context omitted.

>Food doesn't come from remote mountainous areas. I must be imagining the farms that I pass in the mountains in the middle of nowhere when I go backpacking. Surely your argument isn't, "My farm was here, so it's impossible for other farms to be in different locales"?

Surely you aren't arguing "I once saw a farm in the mountains, therefore small remote mountain farms are critical to our food supply"?

The large trucks being loaded with crops for delivery elsewhere should suggest that it contributes to the greater food supply, yes. Further...

>I once...

My phrasing did not suggest "one time" (the phrase was "I pass", suggesting regularity), and it's not just one single farm, it's a few, and I've passed them many times. I have to agree with someone else[1] about your using vocabulary that others haven't introduced - I question whether or not a good faith discussion can be had because of that. Have a good one!

[1]https://news.ycombinator.com/item?id=43985331

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#137
This is a problem with her carrier or her specific account provisioning. SMS over WiFi calling works just fine, including from short codes.

I'm often traveling outside of the US, and my AT&T prepaid line most definitely does not roam outside of CAN/US/MEX. I spend the bulk of my time in WiFi calling mode. I have never had any issues receiving or sending SMS over WiFi, including to short codes.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#138

Earlier quoted context omitted.

Surely you aren't arguing "I once saw a farm in the mountains, therefore small remote mountain farms are critical to our food supply"?

The large trucks being loaded with crops for delivery elsewhere should suggest that it contributes to the greater food supply, yes. Further... >I once... My phrasing did not suggest "one time" (the phrase was "I pass", suggesting regularity), and it's not just one single farm, it's a few, and I've passed them many times. I have to agree with someone else[1] about your using vocabulary that others haven't introduced -…

It's rich for you to complain about me "using vocabulary" when your previous comment was trying to put words in my mouth that I did not say...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#139

This is a really good point, "cell service will always be available" is a classic incorrect assumption that needs to be shattered. I do kinda wonder what the correct way forward is, I think it's silly that ISPs don't support this type of SMS over wifi but I have no clue why. Meanwhile TOTP apps are rightly pointed out to be too numerous with unclear trade offs, I'm surprised ios and android don't have native TOTP app…

I'm pretty sure they both do have TOTP but it's not well documented that it even exists, and it's difficult for regular users to use. In iOS it in the Passwords app (née Keychain) and in Android I think it's buried in the settings app of all places. People don't know it exists and don't know how to use it, and even if they did, unless you're already using it for password management, it's difficult to know how to find…

Many of the big companies seem to really want you to use their app so there's this big game of smoke and mirrors to avoid saying it is TOTP or what they're actually doing. And of course they make it as big of a pain to export your codes as they can get away with. Then they hide behind it being complicated and that is why they have to do this to help grandma, but much of complexity is due to their obfuscation.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#140
> you have to download an app to do it, it's not just a capability that a phone has by default

Luckily this is starting to change. Apple's Passwords app does TOTP out of the box.

Though I am mystified why Google Authenticator doesn't come pre-installed in Android.

Post reply on HN