Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

161–170 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#161
post #13

Much agreement with the others that there's too much expectation. I rented a lime scooter for the first time last year. But, I messed up my VPN settings so I had no Internet. There was no way to tell the scooter I'm done. Even though it was stopped, no button to end the ride. They refunded me the extra time (which was maybe 5 of the 10 minutes) because they could see it was just stopped at a bike rack on gps. Idk wha…

Reminds me of DHL parcel lockers in Germany. The new ones don't have a screen anymore, so you are forced to use their app to use the locker, which somehow requires both a working bluetooth connection to communicate with the locker, AND you need a working internet connection on your phone. What's the point of that?! The parcel locker evidently already has a working internet connection, that should be enough.

Reminds me of a cashless hotel laundromat that I had to use that didnt accept coins, tokens or had a credit card reader. So to wash my clothes I had to find a charger to charge my phone, download an app, being able to receive SMS 2FA while roaming which is a hit or miss depending on roaming agreements, having working internet connection, enabling Bluetooth and Bluetooth Nearby Devices, and then top it up with a foreign credit card. It took about 30 minutes to set it up.

I guess this would be easier in a beighbourhood laundromat with local clients, but in a hotel with many foreigners it becomes a pain with so many dependencies needed to use the washer and dryer.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#162

> you have to download an app to do it, it's not just a capability that a phone has by default Luckily this is starting to change. Apple's Passwords app does TOTP out of the box. Though I am mystified why Google Authenticator doesn't come pre-installed in Android.

Doesn't this kind of defeat the purpose of MFA in that you now have both factors within the same application?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#163
post #159

Some of the comments pointed out that this is hostile behaviour for people roaming as well, and I completely agree. Here is my solution for this : When I am roaming internationally, I leave my SIM card in a spare android at home plugged into a charger. Android has an app that forwards SMS to API : https://f-droid.org/packages/tech.bogomolov.incomingsmsgatew... . Every time I receive a SMS I forward it to this API. Th…

Looks like this might stop working soon unless this process works without logging into the phone: https://mashable.com/article/android-smartphones-automatical...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#165
I remember running in to this problem in university too where one of the basement lab rooms didn't have cell service, but we had to log in to the school computers with our university accounts that had mandatory 2fa

also was surprised to learn from the article that some carriers don’t support the 2fa 5 digit numbers over wifi calling/sms. when I travelled abroad recently that was such a life saver since my carrier supports it

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#166
post #89

She just needs a microcell/femtocell. Talk to your provider, explain to them you get poor service at your home or place of work, and they'll send you a free Internet-in cellular-out radio AP. She doesn't need a tower-based booster if she's got fiber/cable/DSL, those only serve to amplify weak signals and she's too many miles and too many mountain ridges away from the nearest tower, she wants something with RJ-45 inpu…

I'm surprised the major cell providers are cool with letting randos operate cell towers that back into an unknown untrusted ISP and their customers will automatically switch to when in range. It's unbelievably chill for companies that are usually so concerned about their image and controlling the whole experience end to end.

Femtocells are remotely controlled by the carrier, they require GPS location (and maybe spectrum sensing), and I assume the backhaul is over VPN. Obviously they can't guarantee any QoS but it's better than having no signal.

(Fun trivia: Our office paid $XX,000 for AT&T MicroCells which wouldn't activate because they couldn't get GPS signal.)

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#167
post #5

Google Fi can receive all SMS 2 factor messages on Wi-Fi including short codes. It doesn't even require that your phone is on, you can get them in any web browser on any device even if your phone is destroyed. One of my favorite features. You can get service starting at $20 per month. Fi used to have good service in some mountain areas too, with US Cellular. Not sure what's going on with US Cellular right now though.…

I have been living outside the United States for twelve years. I always had problems with SMS until I got Google Fi. And that's a problem because, as the article here says, many banks insist on SMS these days. There are various services that give you a virtual number. But they always suffer from one of two problems: (1) VOIP numbers are 'blacklisted' by some banks for security reasons: they want a real cell phone num…

>Google shuts off the data on Fi after you've been outside the USA for a month. No problem, I'm happy to pay $25 a month for a 'dataless' connection that gives me SMS and voice.

To be somewhat more specific: while I travel extensively and am in the US often, I am often outside of it for more than a month at a time, and it appears that Google will shut off data outside the US if you use data outside the US for too long. If you are using a different SIM for the primary data connection, it appears that they won't even if you have it enabled as a backup.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#168
post #12

Earlier quoted context omitted.

> When you choose an eccentric lifestyle Many "eccentric" lifestyles are not chosen. For instance not owning a smartphone or not having access to power easily is not necessarily limited to well-off tech-savv hipsters who want to make a statement, homeless people, older people in less connected areas or people in developing countries can also be in that situation. When you make your services depend on specific access,…

Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.

It just saddens me that you can be so devoid of empathy.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#169
post #89

She just needs a microcell/femtocell. Talk to your provider, explain to them you get poor service at your home or place of work, and they'll send you a free Internet-in cellular-out radio AP. She doesn't need a tower-based booster if she's got fiber/cable/DSL, those only serve to amplify weak signals and she's too many miles and too many mountain ridges away from the nearest tower, she wants something with RJ-45 inpu…

I'm surprised the major cell providers are cool with letting randos operate cell towers that back into an unknown untrusted ISP and their customers will automatically switch to when in range. It's unbelievably chill for companies that are usually so concerned about their image and controlling the whole experience end to end.

If the device is remotely managed and all IPSEC back to the carrier, who cares what network it's on? At worst you'd just get poor connectivity, I don't think there's any additional exposure here.
Post reply on HN