Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

151–160 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#151
post #72

At this point it's pretty clear 2FA SMS is just a ploy to get PII customer data under the guise of security

The ONLY accounts I have that require SMS and offer no other 2FA are financial institutions. They already have more information on their customers than most other businesses I can think of. Heck, I WANT my bank to have my phone number so they can call me if there's ever a problem. I just want insecure SMS to stop being the only minor hurdle between a fraudster and my life savings. Companies do SMS because their VP of…

No, I think he's mostly right but it is a little more complicated. Most services demand a cell number verification on account creation for user tracking and identification under the guise of security for you. The SMS 2FA setup flow just helps push the user into coughing it up and helps sell the security cover story. Theoretically this helps prevent abuse, but there's no reason they have to abuse the data themselves after getting it for that. Its just that they will. They'll even lie to your face that they only use the number for security purposes and then use it for advertising anyway.

https://www.eff.org/deeplinks/2019/10/twitter-uninentionally...

https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#153

> you have to download an app to do it, it's not just a capability that a phone has by default Luckily this is starting to change. Apple's Passwords app does TOTP out of the box. Though I am mystified why Google Authenticator doesn't come pre-installed in Android.

For the longest time Authenticator was almost abandoned by Google, so it's not surprising the team responsible for the bundled Android apps swerved it.

It didn't need bells and whistles and constant security updates, but it took 13 years for it to get cloud-sync support so you could backup your codes.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#154

Earlier quoted context omitted.

Execs at those companies probably think "Google = good".

Yet Facebook won’t let me sign into WhatsApp using my GV number alone.

There must be something unique about my GV number. It's even allowed on WhatsApp (knock on wood).

I registered it about 13 years ago. I didn't transfer it from a landline/cell phone, it was picked from a list of Google Voice numbers available in my area code. I've never had Fi.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#155
post #7

I wonder what the companies requiring 2FA think about uncompleted 2FA bounces. Deterred fraudster? Short attention span? SMS sucks?

I do not know but I am given a code via SMS for each operation, and each SMS costs more than what a regular SMS costs like, so the bank often deducts quite a lot of money from me for "SMS fee".

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#156
post #81

Earlier quoted context omitted.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

This is probably compliance-related. For me, TOTP isn’t “something I have”, it’s another thing I toss into my password manager and sync to all devices. I really agree with it, but that’s probably their rationale.

That same rationale wouldn't support SMS as "something I have." iMessage and other solutions easily spread SMS into cloud and PC lands (ones that are more easily accessible than password managers.) More likely it's because of legacy and "good enough" reasons.

Personally I don't put TOTP tokens into my password manager and keep a dedicated app for it, just in case my password manager is pwned.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#157

Earlier quoted context omitted.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

By brokerage suports TOTP but not my bank. My bank does support Yubikey-type devices though.

Vanguard supports Yubikeys. I'm yet to use a bank (~8 of them so far) that supports anything other than SMS.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#158

This made me wonder whether it would be possible to build a Wi-Fi-only, roaming-only carrier for computers. Your carrier is already capable of redirecting your SMS messages to other carriers, that's what they do when you're abroad and roaming with a foreign operator. You could make a fake carrier that speaks the right protocols on the roaming side, but communicates with the customer over the internet (using an API or…

> This made me wonder whether it would be possible to build a Wi-Fi-only, roaming-only carrier for computers.

This has been essentially been tried multiple times, e.g. by FreedomPop and Republic Wireless.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#159
Some of the comments pointed out that this is hostile behaviour for people roaming as well, and I completely agree. Here is my solution for this : When I am roaming internationally, I leave my SIM card in a spare android at home plugged into a charger. Android has an app that forwards SMS to API : https://f-droid.org/packages/tech.bogomolov.incomingsmsgatew.... Every time I receive a SMS I forward it to this API. The API in turn emails me the whole message.

I have been using this setup for a few years now without any issues. Even when I am not roaming, I still have this setup on my primary phone. So when I am on my computer and need a SMS OTP I don't need to go find my phone, I receive it in email :-).

(Note : This doesn't work with MMS but I don't need them anyway)

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#160

Along the same lines, am I the only one who thinks it's weird that when logging in on a desktop PC the average bank requires a: - username - password - one time generated 16 digit number - SMS confirmation - email confirmation - phone call with an associate - retinal scan - DNA sample Whereas to log in on mobile all you potentially need is a 4 digit pin which a passerby could easily observe, then yank the phone from…

And keep in mind you have everything stored on your phone, too.
Post reply on HN