Earlier quoted context omitted.
It depends. If your iMessage account is tied to an Apple ID used on multiple devices with 2FA enabled then the code is sent to one of those other devices to validate the login on the new device. So if you are fully in the Apple ecosystem and have 2FA enabled then I believe it would be secure. I know I get alerts on my other devices any time I have had to re-add my phone number to an Apple ID. It tells me my phone num…
When you get the prompt to input the code, just choose "Did not get a verification code" and it will fall back to SMS. See: https://blog.elcomsoft.com/wp-content/uploads/2016/03/apple_...
SMS is not 2FA-secure
181–190 of 379 posts
Re: SMS is not 2FA-secure
#182This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…
So how SHOULD this problem be solved? How should account recovery work?
Re: SMS is not 2FA-secure
#183Earlier quoted context omitted.
I wish Apple added iMessage as a service to make 2FA more secure.
I could see Apple offering 2FA as a core feature, at least on iOS. In fact, Apple should redesign Keychain into a user friendly, 1Password-lite product with 2FA built-in (1Password offers this too) or as a separate app that works with Keychain.
Re: SMS is not 2FA-secure
#184Re: SMS is not 2FA-secure
#185Earlier quoted context omitted.
Consider if you're kidnapped and extracted DNA in unwilling manner
I've built something around it. It's not 100% but gets you to 99%. Dontport.com
Re: SMS is not 2FA-secure
#186This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…
So how SHOULD this problem be solved? How should account recovery work?
Re: SMS is not 2FA-secure
#187I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…
Anytime you have a human in the loop you have the risk of human failings. I.e., that human forgets to follow critical step X in the protocol. Or that human falls for the attackers emotional sob story and takes pity on the attacker and lets the attacker unlock your account. Or that particular human is amenable to bribery to obtain the outcome the attacker wants.
In fact, many sim swaps have been reported to have occurred because of "human at cell phone store did not follow protocol" or "human at cell phone store was taking bribes".
So having a human in the loop is not an absolute solution to solving the problem.
Re: SMS is not 2FA-secure
#188This is great; it's a Princeton research project from Arvind Narayanan's (@random_walker) group, in which their team made 10 attempts to SIM-swap each of 5 different carriers, including T-Mobile, AT&T, and Verizon (all three of which were, weirdly, less secure in some ways than the 2 MVNOs they tested). Most notably: AT&T and Verizon both use call logs to authenticate SIM swaps from people who don't know the account…
So how SHOULD this problem be solved? How should account recovery work?
Re: SMS is not 2FA-secure
#189Ran Bar-Zik, from Israel, created a technique to hack most voice 2FA by using a weak voicemail password. It was largely used in 2019 to hack Brazilian politicians, including state ministers. The hacked telegram messages were passed to Glenn Greenwald, linked to Assange.
Do you have any sources on that (the specific technique that was used)? Google returned nothing. AFAIK, they were hacked using plain simple SIM swap/cloning.
Re: SMS is not 2FA-secure
#190Earlier quoted context omitted.
So how SHOULD this problem be solved? How should account recovery work?
Apps like Google authenticator, or more conveniently, a Google voice number. The Google voice solution works well since it can't be Sim swapped, and can be accessed via email (admittedly, a potential downside).