Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

141–150 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#141

Sounds like discrimination of a broad group of people. Granted, it's not a designated protected group, like by national origin, but I still think they have a good chance in court.

It's absolutely not discrimination and you're harming people by making such an absurd claim. Unreliable SMS delivery is not discrimination. This is how things end up on Fox News: "Is website security now discrimination?"

> I still think they have a good chance in court

Can you share the law you think was violated?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#142

Earlier quoted context omitted.

The large trucks being loaded with crops for delivery elsewhere should suggest that it contributes to the greater food supply, yes. Further... >I once... My phrasing did not suggest "one time" (the phrase was "I pass", suggesting regularity), and it's not just one single farm, it's a few, and I've passed them many times. I have to agree with someone else[1] about your using vocabulary that others haven't introduced -…

It's rich for you to complain about me "using vocabulary" when your previous comment was trying to put words in my mouth that I did not say...

[deleted]

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#143
post #52

Earlier quoted context omitted.

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?

Chase bank used to not work with Google voice. I would have to use email for code. Sometime in last year? it started working.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#144

Earlier quoted context omitted.

I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?

Execs at those companies probably think "Google = good".

Yet Facebook won’t let me sign into WhatsApp using my GV number alone.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#145
post #52
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

> It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

It never ceases to surprise me how much American banks always seem to lag behind with regards to payment tech. My (european) bank started sending hardware TOTP tokens to whoever requested one like a decade ago. They've since switched to phone app MFA.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#146
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

If you port your cell number to a VOIP carrier, I don’t think senders have any way of telling that it’s not still a regular cell number?

I have such a ported number and have no issues receiving SMS 2FA codes.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#148
post #81

Earlier quoted context omitted.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

This is probably compliance-related. For me, TOTP isn’t “something I have”, it’s another thing I toss into my password manager and sync to all devices. I really agree with it, but that’s probably their rationale.

Banks didn't support TOTP long before we were able to easily sync them across devices. It's likely more along the lines of banks generally have bad IT departments and outdated digital security policies.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#149
post #123
post #5

Google Fi can receive all SMS 2 factor messages on Wi-Fi including short codes. It doesn't even require that your phone is on, you can get them in any web browser on any device even if your phone is destroyed. One of my favorite features. You can get service starting at $20 per month. Fi used to have good service in some mountain areas too, with US Cellular. Not sure what's going on with US Cellular right now though.…

Are you able to use rcs and "messages for web"? The last time I checked if you wanted "cellphone is off" texting/voice (basically the old hangouts), you had to enable "fi syncing" which disabled rcs features. Is that still true? What url do you goto to do texts/voice? (i see hangouts.google.com redirects to google chat).

Yeah no it still disables RCS which is super lame now that iPhones finally support it. I hope Google gets around to fixing it someday. I'm not holding my breath. I'm just happy they didn't kill the feature when hangouts died. The URL changed, it's now https://messages.google.com/web/

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#150

> you have to download an app to do it, it's not just a capability that a phone has by default Luckily this is starting to change. Apple's Passwords app does TOTP out of the box. Though I am mystified why Google Authenticator doesn't come pre-installed in Android.

TIL! Thanks, I had no idea Passwords did this until now.
Post reply on HN