Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

181–190 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#181
post #59
post #2

Your problem is not with SMS as a second factor though. (Unless you think the attacker had your password as well). It is with the use of SMS as a single recovery factor. The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene.

The option for a delay of is great. The option of adding a custom security question/password etc. is even better. The option of completely turning off recovery is also great. The ability to have your solution on multiple devices without a need for a mobile phone number based recovery is great as well. I hate it that Twitter forces you to enter a mobile phone number even when you set up an authenticator code generator…

On Twitter you can remove your phone number after the fact tho. In fact most sites that req a phone number to sign up etc allow you to remove the phone number later if you choose.

Re: Tell HN: SMS-based two-factor authentication is not secure

#182
post #119

Got an email from Heroku last night saying they're discontinuing SMS as a 2FA scheme... yay Heroku!

Not sure if the yay is sarcasm. Heroku will remove existing SMS as second factor from all accounts, effectively making those accounts less secure. Yay Heroku! (Sarcasm intended)

No sarcasm intended at all on my part -- I think this is a very good move.

SMS is very bad as a 2FA, in that someone can fairly easily social-engineer your phone company to send them a new SIM card for your account, and once it's in their phone, all your SMS messages go to them. They now have control of your "protected" account (and yeah, they have to get your password as well, but if you're a big enough target, it's worth it).

This is why getting rid of SMS entirely as a 2FA is seen as an improvement in security.

Re: Tell HN: SMS-based two-factor authentication is not secure

#183
post #119

Earlier quoted context omitted.

Not sure if the yay is sarcasm. Heroku will remove existing SMS as second factor from all accounts, effectively making those accounts less secure. Yay Heroku! (Sarcasm intended)

No sarcasm intended at all on my part -- I think this is a very good move. SMS is very bad as a 2FA, in that someone can fairly easily social-engineer your phone company to send them a new SIM card for your account, and once it's in their phone, all your SMS messages go to them. They now have control of your "protected" account (and yeah, they have to get your password as well, but if you're a big enough target, it's…

Removing 2FA from existing accounts is never an improvement in security. As other replies on this post have noted, having SMS as 2FA is always better than not having 2FA. Heroku is actively harming their user's security by removing 2FA from user's accounts. Some users will not set up a new 2FA method on their account, leaving their account vulnerable to password attacks.

Re: Tell HN: SMS-based two-factor authentication is not secure

#184
post #156

Earlier quoted context omitted.

What about an authentication app? Google Authenticator or something similar can be installed on the phone which is necessary for SMS, improves the security more than SMS, and doesn't suffer from the problem of losing it, at least not more than SMS auth does.

When your phone is lost or stolen, you buy a new phone and go to your telco provider to get a new SIM with your number. SMS 2FA continues to work. Your Authenticator secrets are gone with the phone, and you're locked out. (Unless you use a solution like Authy with multiple devices, which strikes me as the most sensible solution.)

It blows my mind that Google Authenticator still doesn't have a multi-device sync feature (or even a "recover from backup" feature on iOS for that app, because I think they added it recently to Android; just "recover from backup" alone would have been sufficient to convince me not to switch).

All of that made me switch to Microsoft Authenticator, as they do have both multi-device sync and "recover from backup" feature as well, so now I don't need to be stressed about my phone getting lost. Kind of sad, given that I've been a user of Google Authenticator for quite many years until that point.

Re: Tell HN: SMS-based two-factor authentication is not secure

#185
post #116

What really grinds my gears is the seemingly unstoppable global transition towards SMS to a mobile phone number as means of identifying an individual, conflated with "security" through 2FA/account recovery, with this as the only option. This is especially popular within Fintech. Wise (formerly Transferwise) recently started requiring 2FA for signing in - SMS is the one and only option. Revolut requires it for acknowl…

Wise supports 2FA through their app (similar to what Google does, with a prompt).

Re: Tell HN: SMS-based two-factor authentication is not secure

#186

Earlier quoted context omitted.

SMS is better than nothing, but you have a bunch of other better fallback alternatives before you should rely on it. You can support the enrollment of multiple hardware tokens (i.e., you keep one at home, and one on your person). You can have online push login approvals. You can have a TOTP code generator.

> You can support the enrollment of multiple hardware tokens (i.e., you keep one at home, and one on your person). How many services do that today? And since so few people have fallbacks what is their recovery process like? Because the hackers will find the weaknesses.

WebAuthn explicitly tells Relying Parties (ie web sites) to all do this. All the services I use which offer WebAuthn or its predecessor U2F support multiple named hardware tokens and I enroll at least my Yubico branded device and one more at such sites. For those I use from a phone, the phone itself is enrolled.

AWS is the counter-example which will be (indeed already has been in this HN comment tree) cited as proof sites don't all do this, I've tried asking if there are literally any others, and never received any ideas. I don't currently have an employer and I don't use AWS for personal projects.

It's pretty common for sites that actually care about authenticating you (so, Google but not your Bank, GitHub but not your mortgage lender) to provide you with single use bypass codes which they tell you to write down and keep somewhere safe.

Re: Tell HN: SMS-based two-factor authentication is not secure

#187
post #116

What really grinds my gears is the seemingly unstoppable global transition towards SMS to a mobile phone number as means of identifying an individual, conflated with "security" through 2FA/account recovery, with this as the only option. This is especially popular within Fintech. Wise (formerly Transferwise) recently started requiring 2FA for signing in - SMS is the one and only option. Revolut requires it for acknowl…

Well, the European PSD2 has forbidden the use of SMS TANs last year for banking applications while requiring much more stringent 2FA use (for account balances more than 30 days in the past for instance).

So, I would say quite the opposite to unstoppable.

Re: Tell HN: SMS-based two-factor authentication is not secure

#188

Earlier quoted context omitted.

SMS is better than nothing, but you have a bunch of other better fallback alternatives before you should rely on it. You can support the enrollment of multiple hardware tokens (i.e., you keep one at home, and one on your person). You can have online push login approvals. You can have a TOTP code generator.

TOTP is the one that makes the least sense to me. It is also weak to phishing (extremely common) but adds protection against SIM-swapping (comparatively very rare). It also has almost all of the downsides of U2F (a pain in the ass if you lose your device).

> a pain in the ass if you lose your device

Every modern TOTP app is cloud-synced, so I'm not sure why people are saying it's "a pain in the ass if you lose your device."

Heck, most modern password managers (e.g. 1Password, LastPass, etc.) are also TOTP, and help you fill the TOTP token (usually by putting in on your clipboard) at the same time they autofill the password.

> It is also weak to phishing (extremely common) but adds protection against SIM-swapping (comparatively very rare).

Sufficient paranoia / user training is enough to protect against phishing. (Especially for services where the only "users" are the extremely-paranoid IT admins themselves.) But nothing can really protect you from SIM-swapping, save for not allowing services that use single-factor SMS recovery to ever know your phone number in the first place.

Re: Tell HN: SMS-based two-factor authentication is not secure

#189

Earlier quoted context omitted.

SMS is better than nothing, but you have a bunch of other better fallback alternatives before you should rely on it. You can support the enrollment of multiple hardware tokens (i.e., you keep one at home, and one on your person). You can have online push login approvals. You can have a TOTP code generator.

TOTP is the one that makes the least sense to me. It is also weak to phishing (extremely common) but adds protection against SIM-swapping (comparatively very rare). It also has almost all of the downsides of U2F (a pain in the ass if you lose your device).

TOTP is an improvement over SMS in that identity is not tied to a phone number, which has been proven over and over again to be a terrible indicator of identity.

Re: Tell HN: SMS-based two-factor authentication is not secure

#190

Question: Have people used Google Voice SMS accounts or Twilio SMS accounts for 2FA? Would that be more secure?

I have heard that this is actually better and more secure. Google voice I think isn't susceptible to social engineering attacks like typical phone carriers. Also it's a smarter move to have a separate phone number that isn't related to what a hacker might be able to find out about you just doing basic search engine queries.
Post reply on HN