Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

151–160 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#151

Earlier quoted context omitted.

TOTP is phishable, which is a way way way more common attack than sim swaps.

Sure, no security measure is perfect. Hardware tokens are likely to have better properties than TOTP, which has better properties than SMS, which has better properties than nothing. you can phish SMS exactly the same way you can phish TOTP, I'd say :)

TOTP is marginally safer than SMS.

It also comes with large downsides. Security is an economics game. Marginal improvements in security posture are not always worth the cost.

There are a bunch of people who insist that web services should drop SMS completely and demand that all users use TOTP (at least). I question the value of this change given that TOTP only protects you in comparatively rare cases.

Re: Tell HN: SMS-based two-factor authentication is not secure

#152
post #8

Earlier quoted context omitted.

FWIW I wouldn't regard SMS as a good 2nd authentication factor either, for the same reasons as this issue, it's too easy to get a carrier to transfer a number to an attacker. Where it's used as a second factor, this still has an impact which is, if an attacker can get the password (and there's been enough breaches and keystroke logging for that to be common) they can then grab the number to get full control of the ac…

The problem is with most online services, the only second factor allowed is SMS. If you see it as "don't bother, they can just steal your SMS number" instead of "that's slightly better, at least now they can't get in without stealing my number" then you're not thinking about this reasonably. It's inane to neglect to use SMS where it's the only second factor available. The exception is when a service allows you to use…

Basically every service I've used that requires SMS will use it as the sole authentication factor for resetting your password.. It's brutal

Re: Tell HN: SMS-based two-factor authentication is not secure

#153

Not only is it not secure, it's not a constant for everyone. I moved countries and I am now locked out of my bank account abroad since they verify logins via OTP over SMS.

Why cancel your old phone number in that country when you still have a bank account there? I suggest a bank which doesn't suck, such as bunq.

It can be costly.

I moved from Ireland to the US and kept my Irish number active - the cost was a €5 topup every 6 months.

Going in reverse is much harder - a lot of the budget phone providers in the US don't have any roaming offering. Best I can tell, you really need to have an account with a real provider, and that realistically looks like $20/mo (Google Fi), 20x more expensive than the reverse.

Re: Tell HN: SMS-based two-factor authentication is not secure

#154

I lost my Microsoft account years ago. I still get emails from Microsoft stating that there's suspicious activity on the account. I got two just yesterday. Despite that, despite still having access to the email the account is on, I cannot recover the Microsoft account. Despite Microsoft notifying me that the account is still, years later to this day, being abused, cannot use any form of recovery. I cannot access the…

google does the same thing

Protonmail is the best beacause it does not require backup emmail or SMS, just the username and password and 2fa being optional (but you must have the password), which is how it should be. So many people have gotten hacked through phones and or recovery emails.

Re: Tell HN: SMS-based two-factor authentication is not secure

#155
post #35

Earlier quoted context omitted.

> Yeah, and it requires me to use a U2F token, which I can loose, etc. In which case there are much safer recovery mechanisms available. For example, a second U2F token, or handwritten backup codes. > and SMS as a second factor seems like a perfectly reasonable balance. My point is that it isn't. Unfortunately, today, identity is a true privilege - it pretty much requires purchasing multiple U2F tokens, and that's su…

But that is my entire point. SMS as a second factor is purely additive. It cannot reduce security. There is pretty much no form of second factor that users are worse at passing than backup codes. Even if people print them out (few do), they won't find them when the emergency happens. You need some form of trust that can be bootstrapped again from scratch. For most of the world, SMS is it. The Nordic countries have th…

It can reduce security if password can be reset with SMS

Re: Tell HN: SMS-based two-factor authentication is not secure

#156

Earlier quoted context omitted.

> Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe Yeah, and it requires me to use a U2F token, which I can loose, etc. You have to balance security and usability, and SMS as a second factor seems like a perfectly reasonable balance.

What about an authentication app? Google Authenticator or something similar can be installed on the phone which is necessary for SMS, improves the security more than SMS, and doesn't suffer from the problem of losing it, at least not more than SMS auth does.

When your phone is lost or stolen, you buy a new phone and go to your telco provider to get a new SIM with your number. SMS 2FA continues to work. Your Authenticator secrets are gone with the phone, and you're locked out.

(Unless you use a solution like Authy with multiple devices, which strikes me as the most sensible solution.)

Re: Tell HN: SMS-based two-factor authentication is not secure

#157

Part of the issue here that I don't see people addressing is that SMS as an only-factor recovery tool is often not optional. I hit a case like this just the other day: the service would not allow me to log in at all without adding an SMS number. This is becoming increasingly common. The irony is that my security is now worse. At least my password was randomly generated. I'm not sure what there is to do about this, ot…

that is because google and other companies derive more $ from your number than protecting your privacy/security

Re: Tell HN: SMS-based two-factor authentication is not secure

#158

Earlier quoted context omitted.

> Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe Yeah, and it requires me to use a U2F token, which I can loose, etc. You have to balance security and usability, and SMS as a second factor seems like a perfectly reasonable balance.

And the site has to support U2F. U2F is a great standard but almost none of the businesses I interact with support it. There are maybe 3 banks in the US that support it, but not mine.

I don't understand why banks and businesses don't outsource the whole authentication business to someone that does nothing else, and then does proper 2FA (maybe with a choice of security levels), and supports as many standardised solutions as possible.

Re: Tell HN: SMS-based two-factor authentication is not secure

#159

Earlier quoted context omitted.

Why cancel your old phone number in that country when you still have a bank account there? I suggest a bank which doesn't suck, such as bunq.

It can be costly. I moved from Ireland to the US and kept my Irish number active - the cost was a €5 topup every 6 months. Going in reverse is much harder - a lot of the budget phone providers in the US don't have any roaming offering. Best I can tell, you really need to have an account with a real provider, and that realistically looks like $20/mo (Google Fi), 20x more expensive than the reverse.

Then it sounds like changing bank is a better answer for many.

Re: Tell HN: SMS-based two-factor authentication is not secure

#160

As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to ba…

We have something vaguely similar with "BankID" in Norway. It's a bank issued digital ID that submits a 2FA to your phone (not through SMS, but through some other system that takes over the whole screen - not sure what it is). It's usable for almost all government agencies or official stuff online here, but I haven't seen anyone use it for third party auth as it costs roughly 10 cents per login for the service using…

This has been rolled out and in use in British Columbia, Canada as well. We have a digital ID app for iOS and Android, which you verify your ID with first, then for government sites (e.g., health records), you login through this app instead - there are no emails, usernames, or passwords involved.
Post reply on HN