Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

191–200 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#191
post #35

Earlier quoted context omitted.

> Yeah, and it requires me to use a U2F token, which I can loose, etc. In which case there are much safer recovery mechanisms available. For example, a second U2F token, or handwritten backup codes. > and SMS as a second factor seems like a perfectly reasonable balance. My point is that it isn't. Unfortunately, today, identity is a true privilege - it pretty much requires purchasing multiple U2F tokens, and that's su…

But that is my entire point. SMS as a second factor is purely additive. It cannot reduce security. There is pretty much no form of second factor that users are worse at passing than backup codes. Even if people print them out (few do), they won't find them when the emergency happens. You need some form of trust that can be bootstrapped again from scratch. For most of the world, SMS is it. The Nordic countries have th…

> SMS as a second factor is purely additive. It cannot reduce security.

You are forgetting social engineering. Humans find it reassuring that the security process happened as usual, even if in fact the apparently "usual" process was them being being phished. This can mean they're actually less alert than they would be otherwise.

You get an urgent message from your bank about an unexpected $500 transaction, you follow the link & you need to enter your password as usual of course, and then it tells you that you'll get an SMS and to type in the code so you do so. Phew! Disaster averted! Right? This must have been real, you even got an SMS from the bank.

Alas the SMS was from your bank, and the bad guys didn't have a way to intercept it, but they didn't need one because you typed it into their phishing website. That unexpected $500 transaction wasn't real, but their emptying of your bank account will be.

Re: Tell HN: SMS-based two-factor authentication is not secure

#193
post #177

Earlier quoted context omitted.

Yes. The point is the TOTP is precisely as bad as SMS for the common case (phishing) and only safer in a rare case (SIM-swap). This comes with large downsides (losing access). TOTP is, at best, a very marginal improvement over SMS. This is what makes the online push to complain about services that use SMS 2FA and demand a switch to TOTP very strange.

TOTP is far, far better for travellers who need to swap their SIM cards frequently, or need to work out of places with internet access but no cell reception.

Sure. I'm not opposed to supporting it. It is just weird to me to see people pushing for it with seemingly equal vigor as U2F.

Re: Tell HN: SMS-based two-factor authentication is not secure

#194
post #188

Earlier quoted context omitted.

TOTP is the one that makes the least sense to me. It is also weak to phishing (extremely common) but adds protection against SIM-swapping (comparatively very rare). It also has almost all of the downsides of U2F (a pain in the ass if you lose your device).

> a pain in the ass if you lose your device Every modern TOTP app is cloud-synced, so I'm not sure why people are saying it's "a pain in the ass if you lose your device." Heck, most modern password managers (e.g. 1Password, LastPass, etc.) are also TOTP, and help you fill the TOTP token (usually by putting in on your clipboard) at the same time they autofill the password. > It is also weak to phishing (extremely comm…

> Every modern TOTP app is cloud-synced

I've got a few services that only support Symantec VIP, which does not allow you to extract secrets.

> Sufficient paranoia / user training is enough to protect against phishing.

Considering how easily actual factual professional security engineers fall for phishing, I don't believe you.

Re: Tell HN: SMS-based two-factor authentication is not secure

#195

Earlier quoted context omitted.

It is safe to use the same U2F token for many sites, that's not an issue. Having a backup token is very useful, but apart from that, a single hardware token (not custom - standards are good) can easily be used to secure all your accounts.

Assuming that the sites allow you to change the token manually?

I've never seen a site that didn't have at least this.

Usually you get a UI where you can add new ones and remove old ones, and when you add a new one you name it in their UI so that you can tell it apart from any others.

Re: Tell HN: SMS-based two-factor authentication is not secure

#196
post #188

Earlier quoted context omitted.

> a pain in the ass if you lose your device Every modern TOTP app is cloud-synced, so I'm not sure why people are saying it's "a pain in the ass if you lose your device." Heck, most modern password managers (e.g. 1Password, LastPass, etc.) are also TOTP, and help you fill the TOTP token (usually by putting in on your clipboard) at the same time they autofill the password. > It is also weak to phishing (extremely comm…

> Every modern TOTP app is cloud-synced I've got a few services that only support Symantec VIP, which does not allow you to extract secrets. > Sufficient paranoia / user training is enough to protect against phishing. Considering how easily actual factual professional security engineers fall for phishing, I don't believe you.

> Symantec VIP

See https://www.reddit.com/r/1Password/comments/8yey6y/how_do_i_...

(PITA, I know, but running little auth gateways like this is part-and-parcel of doing security for an org.)

> Considering how easily actual factual professional security engineers fall for phishing, I don't believe you.

It's almost always the service's fault for being designed in such a way that its real async user interactions are indistinguishable from phishing. You can't train a user to distinguish X from X.

• It's hard to train users to not forward TOTP tokens sent to them to someone else, if the real service will text or push-notifies the user their TOTP token "at random" (i.e. because the attacker tried to log in.) But if the service never does that — if you always have to go and fetch the token from your TOTP app — then you can just tell the user that the only time they are to go do that, is right after they've typed their username and password as part of logging in themselves; and that anything else is a phishing attempt.

• It's hard to train users to not type their username+password into phishing login pages, if the services you use constantly send you emails containing deep links. But if the service never does that — if the service always tells you to go your browser and navigate to the site yourself — then it's easy to teach users to never trust a login initiated through an email.

Security, in this case, is less about "good security hygiene", and more about priming/expectations. And because of that, the practice of being an IT admin for such an org, is a practice of picking services, or negotiating with services, to ensure that the service is following secure workflows when dealing with your users, so that your users can be trained.

Re: Tell HN: SMS-based two-factor authentication is not secure

#197

As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to ba…

> As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling

Uh... what does (in)secure mean to you?

Re: Tell HN: SMS-based two-factor authentication is not secure

#198
post #170
post #2

Your problem is not with SMS as a second factor though. (Unless you think the attacker had your password as well). It is with the use of SMS as a single recovery factor. The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene.

SMS is not a good second factor, even as a second factor. I deprecated SMS 10 years ago and the only way I receive SMS codes is via an online interface that is password access. For most people, SMS fails miserably when you need to change your SIM card or fly to another country, or work out of a place with no cell reception but has wired or wi-fi internet access. That's a big part of the reason why I deprecated it in…

How do you direct SMS to the online interface?

Re: Tell HN: SMS-based two-factor authentication is not secure

#199

I lost my Microsoft account years ago. I still get emails from Microsoft stating that there's suspicious activity on the account. I got two just yesterday. Despite that, despite still having access to the email the account is on, I cannot recover the Microsoft account. Despite Microsoft notifying me that the account is still, years later to this day, being abused, cannot use any form of recovery. I cannot access the…

>Despite that, despite still having access to the email the account is on, I cannot recover the Microsoft account. Despite Microsoft notifying me that the account is still, years later to this day, being abused, cannot use any form of recovery. I cannot access the account with help from support or even after visiting a brick-and-mortar store. This happened to me. I was briefly a contractor at MSFT and was able to esc…

> It's likely that your account is completely wiped and no longer exists.

If that's the case then why do I get emails notifying me that unusual sign-in activity is occurring? And, why am I unable to create a new account with the same email?

Re: Tell HN: SMS-based two-factor authentication is not secure

#200
post #86

Earlier quoted context omitted.

> Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe Yeah, and it requires me to use a U2F token, which I can loose, etc. You have to balance security and usability, and SMS as a second factor seems like a perfectly reasonable balance.

I'm glad someone is bringing this up. I witnessed so many people lose access to their accounts because they wiped their phone that had an authenticator app, or they lost their physical 2FA tool.

Password managers such as 1Password and Bitwarden can save and fill in TOTP codes. Maybe not perfect security but a big win for convenience and loss prevention.
Post reply on HN