Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

161–170 of 379 posts

Re: SMS is not 2FA-secure

#161
post #49

Earlier quoted context omitted.

What about Authenticator? Maintaining a small fleet of yubikeys costs as much as a whole phone. https://play.google.com/store/apps/details?id=com.google.and...

Know that if your single phone dies with all your totp credentials, you're sunk.

True, and this is the reason I instead direct friends to options such as Authy or Aegis which allow the use of more than one device.

Unfortunately my bank (ANZ) and my government's online platform (myGov) in AU both have dedicated OTP apps which only allow single-device installations. When I lived overseas, my bank in Germany also had their own dedicated OTP app but they allowed installation on a backup device as well. Much better.

Re: SMS is not 2FA-secure

#162

My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…

Yep, the security problems with the mobile system are ghastly.

- Stingrays...

- Operator app pushes to SIM cards...

- Secret GSM processors and software internals

- Voice / text / data "ciphering"

- Protocol-level "emergency" tracking features

- Silent SMS (sounds like its from a bad cop show but its actually a real thing it turns out.) "They do not show up on a display, nor trigger any acoustical signal when received. Their primary purpose was to deliver special services of the network operator to any cell phone." -- sounds like it has a completely legit use...

The list goes on. It's enough to make anyone want to get the tin foil out. But at least in this case there's a simple and clear recommendation: --not to use 2-factor auth by SIM--.

Re: SMS is not 2FA-secure

#163
The title is mangled, because someone misparsed the question.

The question is "Is SMS 2FA secure?", not "Is SMS 2FA-secure?" There is no such property as 2FA-secure.

Title should read: "SMS 2FA is not secure".

Re: SMS is not 2FA-secure

#165

Earlier quoted context omitted.

Isn't iMessage just as vulnerable to SIM swapping and number portability fraud as SMS? Once you have control over a phone number, you can register iMessage as that number on a device you control.

It depends. If your iMessage account is tied to an Apple ID used on multiple devices with 2FA enabled then the code is sent to one of those other devices to validate the login on the new device. So if you are fully in the Apple ecosystem and have 2FA enabled then I believe it would be secure. I know I get alerts on my other devices any time I have had to re-add my phone number to an Apple ID. It tells me my phone num…

When you get the prompt to input the code, just choose "Did not get a verification code" and it will fall back to SMS.

See: https://blog.elcomsoft.com/wp-content/uploads/2016/03/apple_...

Re: SMS is not 2FA-secure

#166

Earlier quoted context omitted.

In a previous company, one of the employees enabled 2FA for their staff account (it was mandatory), stored the backup codes on his phone (presumably as a photo) and it fall in the ocean the next day. With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.

Yes, that is exactly what I want. Life should be much more difficult without the TOTP and backup codes, so much that it takes a great deal of resources to get around it, if at all possible. Maybe even providing heavy documentation such as a Facetime call with various proof so that fraudulent actors are sufficiently deterred.

In a previous job I implemented a recovery page with a long random key (also posted as a QR code) that you could print out and use as an emergency password reset if ever required. You'd scan the QR code and it would take you to a page where you could set a new password directly.

This, coupled with a "I know what I'm doing, never let support reset my password" option that disabled changing the user's password for anyone without direct write access to the production database was pretty good for security, I feel.

Re: SMS is not 2FA-secure

#167
post #97
post #37

Earlier quoted context omitted.

Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…

They (and similar corporate 2FA solutions like PingID and similar systems used by banks) basically assume uninterrupted access to the internet which is generally a poor assumption. It often breaks down when you're traveling either due to network or roaming issues just when you desperately need access. In all these situations, I've found companies which offer a back up SMS option very valuable since it usually gets de…

I'm pretty sure the Microsoft authenticator has a backup TOTP token you can have it display if you have issues receiving the notification. It is quite a user friendly auth scheme, at least I've never had to resort to any kind of SMS backed auth.

Re: SMS is not 2FA-secure

#168
post #80
post #21

This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…

I wish Apple added iMessage as a service to make 2FA more secure.

Why the downvoting? iMessage is a hundred times more secure than SMS. It’s got E2E encryption and a published security paper.

https://techcrunch.com/2014/02/27/apple-explains-exactly-how...

Re: SMS is not 2FA-secure

#169
post #131

Earlier quoted context omitted.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

Don’t put them in google authenticator. https://support.1password.com/one-time-passwords/

Wow that’s awesome! I had no idea 1Password had this functionality so thanks for sharing. I just had a rough time after upgrading my phone dealing with Google Authenticator since I hadn’t realized my Auth info would not migrate along with the rest of my data...

Re: SMS is not 2FA-secure

#170

Earlier quoted context omitted.

In a previous company, one of the employees enabled 2FA for their staff account (it was mandatory), stored the backup codes on his phone (presumably as a photo) and it fall in the ocean the next day. With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.

Yes, that is exactly what I want. Life should be much more difficult without the TOTP and backup codes, so much that it takes a great deal of resources to get around it, if at all possible. Maybe even providing heavy documentation such as a Facetime call with various proof so that fraudulent actors are sufficiently deterred.

Dude. If somebody wants into your account specifically, they’ll get into it. 2FA, specifically SMS based 2FA, is really about the provider getting mass compromised because people recycle their password across all their sites.

It great for keeping people using scripted attacks against a huge list of accounts. It isn’t really to keep people specifically after your account out.

If somebody wants your shit and specifically your shit.... they’ll get it...

Post reply on HN