Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

141–150 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#141

As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to ba…

> As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling

It is 100% insecure, and been exploited for nearly a decade.

1. Anybody with access to raw SS7 network can basically click a finger, and have you traffic rerouted

2. GSM interception gear is widely available

The person who invented "SMS verification" was a round idiot

Re: Tell HN: SMS-based two-factor authentication is not secure

#142
post #8

Earlier quoted context omitted.

FWIW I wouldn't regard SMS as a good 2nd authentication factor either, for the same reasons as this issue, it's too easy to get a carrier to transfer a number to an attacker. Where it's used as a second factor, this still has an impact which is, if an attacker can get the password (and there's been enough breaches and keystroke logging for that to be common) they can then grab the number to get full control of the ac…

> TOTP or hardware tokens don't generally suffer from the same problem. But how many hardware tokens or TOTP tokens are users willing to deal with? I currently have eight for various clients and systems at work. If each online account required a TOTP token or a custom hardware token it would be a confusing mess of tokens. I don't know if there's a safe and easy way of reusing the same token across sites. Until then S…

It is safe to use the same U2F token for many sites, that's not an issue. Having a backup token is very useful, but apart from that, a single hardware token (not custom - standards are good) can easily be used to secure all your accounts.

Re: Tell HN: SMS-based two-factor authentication is not secure

#143

I lost my Microsoft account years ago. I still get emails from Microsoft stating that there's suspicious activity on the account. I got two just yesterday. Despite that, despite still having access to the email the account is on, I cannot recover the Microsoft account. Despite Microsoft notifying me that the account is still, years later to this day, being abused, cannot use any form of recovery. I cannot access the…

In the same boat. Really annoyed I can longer access it. The process to recovery is a total joke too.

Re: Tell HN: SMS-based two-factor authentication is not secure

#144
Part of the issue here that I don't see people addressing is that SMS as an only-factor recovery tool is often not optional. I hit a case like this just the other day: the service would not allow me to log in at all without adding an SMS number. This is becoming increasingly common.

The irony is that my security is now worse. At least my password was randomly generated.

I'm not sure what there is to do about this, other than educating as broadly as we can and hope that engineers advocate in their own organizations to change this.

Re: Tell HN: SMS-based two-factor authentication is not secure

#145
post #139
post #66

Earlier quoted context omitted.

If they're able to issue a new SIM card without the system requiring them to enter the PIN first, then it's a very terribly designed system.

They have to be able to issue a new SIM card without a pin in the case of a lost phone though. In that case they should probably check government identification, of course, and not be available remotely.

I thought you needed the PIN if you wanted that, too? As in, if you lose your phone and don't have the PIN set up with your carrier, you've lost your number and can't restore it.

Re: Tell HN: SMS-based two-factor authentication is not secure

#148

Earlier quoted context omitted.

1. Somebody loads fakebank.com. 2. It pops up a username/password screen. The user types in their credentials for realbank.com. 3a. The owners of fakebank.com use your creds to log in to realbank.com and are presented with a TOTP page. 3b. fakebank.com loads another page that asks the user for their TOTP. The user enters it, still thinking they are logging in to realbank.com 4. The owners of fakebank.com use the TOTP…

Couldn’t this entire scenario play out exactly the same with SMS codes?

Yes.

The point is the TOTP is precisely as bad as SMS for the common case (phishing) and only safer in a rare case (SIM-swap). This comes with large downsides (losing access).

TOTP is, at best, a very marginal improvement over SMS. This is what makes the online push to complain about services that use SMS 2FA and demand a switch to TOTP very strange.

Re: Tell HN: SMS-based two-factor authentication is not secure

#149

Not only is it not secure, it's not a constant for everyone. I moved countries and I am now locked out of my bank account abroad since they verify logins via OTP over SMS.

For some countries (USA) you can forward your number to a google voice number and retain incoming sms. Call forwarding isn't possible to my knowledge.

Porting my number to Google voice before moving abroad was one of the smartest things I’ve ever done (in hindsight), for this reason.

I sometimes wonder why Google has kept it running for so long, when they’re so keen to kill off boring, under-performing products.

Re: Tell HN: SMS-based two-factor authentication is not secure

#150

The worst part is, Coinbase will not cover your losses. They have absolved themselves of any responsibly for users being hacked, only if they [coinbase] gets hacked.

Worst part, I mean that’s the majority of the risk of crypto. These aren’t government backed accounts, why would there be insurance.
Post reply on HN