Live data from Hacker News

How SMS fraud works and how to guard against it

apuchitnis.substack.com

21–30 of 107 posts

Re: How SMS fraud works and how to guard against it

#21
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone

I use Strongbox to backup TOTP in Keepass databases.

Re: How SMS fraud works and how to guard against it

#22
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to install or use an authenticator app. For this reason, I think most finance companies will steer clear of the Authenticator app and go directly for SMS 2FA or worse, email 2FA.

Re: How SMS fraud works and how to guard against it

#23
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

Have they? It seems the trend is to support Authenticator apps (i.e. one-time scan a QR code to a TOTP URL that I store on my own device). I haven't seen too many products that support TOTP 2FA but require SMS 2FA.

Some companies do require a phone number to setup an account (because it's the best proxy we have for "one per real person" or "expensive for one person to get many of"), but if they're competent then you can remove it as a 2FA option if you replace it with a TOTP code. [0]

If you ask me, it should be illegal to require SMS 2FA without an opt-out to TOTP. Perhaps relatedly, I'm also curious about the percentage of Twilio revenue from 2FA messages.

[0] RANT: Google, in typically creepy fashion, makes it difficult to enable TOTP without first either providing a phone number, or downloading a Google app to "tap to login!" on your phone. But they do allow you to setup a hardware token, so I found a workaround [1] to configure TOTP without providing a phone number, which is (perhaps ironically) to use Chrome DevTools to create a virtualized WebAuthn device and add it as a hardware token 2FA option. Then it's possible to setup TOTP and remove the virtualized device, leaving you with only TOTP 2FA and no com.google apps begging you for entitlements on your phone.

[1] https://superuser.com/a/1759306

Re: How SMS fraud works and how to guard against it

#24
post #22
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

Nobody in my family - parents, kids, spouse - knows what an authenticator app is or would what to do if presented that as an option, although my teen could probably figure it out.

For everyone else, it would be a cascading series of installation and password and app switching and immediacy problems. This would create a great deal of frustration, and ultimately a call to family tech support (me) or the service provider if human tech support is an option which is not the case for many companies such as Google and social media firms.

Re: How SMS fraud works and how to guard against it

#25
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

Because lots of us upgrade phones every couple years, or have dropped a phone and had it break, or get water in it or something.

It's all too easy to realize after the fact you needed to transfer something between the old phone to the new phone to keep the authenticator working. Sometimes that's not available (phone damaged), or don't realize you need it until after you've already sent the phone in for trade in.

So yes, they are user unfriendly.

Re: How SMS fraud works and how to guard against it

#26

Earlier quoted context omitted.

my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone

I use Strongbox to backup TOTP in Keepass databases.

That's good for you, is grandma going to do that?

Re: How SMS fraud works and how to guard against it

#27

Fraud requires that someone make a misrepresentation. Who makes a misrepresentation when SMS fraud is committed? What is the misrepresentation? Is there any chance that this isn’t actually fraud and that companies who send out tons of text messages to any number a person specifies are just paying for their extraordinarily poor design?

It's definitely fraud and it's definitely detectable when a 10000 block prefix of numbers sends 100x more SMS than every other prefix out of the blue.

It's basically a referral marketing campaign where the fraudster does revenue share with local sketchy infrastructure providers.

Re: How SMS fraud works and how to guard against it

#28
post #22
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

I prefer SMS for 2FA because some authenticator apps get tied to a device.

I'm worried about losing my phone and being locked out.

With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.

Re: How SMS fraud works and how to guard against it

#29
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

AIUI, EU regulation requires 2FA in finance now, but the 2FA must also confirm details such as a target account and/or amount.

Authenticator apps (at least those that use TOTP/HOTP) can't do that. SMS can. So can card readers but people hate having to carry them around. So we're stuck with SMS.

Re: How SMS fraud works and how to guard against it

#30
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.

Only downside is the verizon rep giving your sim to someone who deepfaked your voice.
Post reply on HN