Earlier quoted context omitted.
Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.
>When the barrier to adoption and inconvenience to the user is so low Is it low though? I'm not sure my parents could figure out how to use an authenticator app.
Let's Ban SMS 2FA
21–30 of 46 posts
Re: Let's Ban SMS 2FA
#22If you want to advance this argument, explore how customer service would evolve with a different method, or how user experience could be improved with passkeys. It's not a technology problem.
Re: Let's Ban SMS 2FA
#23So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…
Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.
I imagine even if it were easier, you would see low adoption, because “I’ve never been robbed but I have locked myself out, does this mean I can’t call a locksmith anymore?” Would be top of people’s minds.
Re: Let's Ban SMS 2FA
#24Re: Let's Ban SMS 2FA
#25Re: Let's Ban SMS 2FA
#26Re: Let's Ban SMS 2FA
#27Sure, SMS 2FA isn't great. It may even be bad. But calling for government legislation to make that decision for other people is definitely bad. This is something you ban internally at your company or chose not to use yourself. Calling for government use of force against people who use SMS 2FA is really nasty. That said, maybe I'm missing come implicit context here and he's only taking about banning it for incorporate…
I'm talking about banning implementation of SMS 2FA server side. Individual users wouldn't be banned from using it, but it would be illegal to provide it as a company (or at least for important sectors like banks).
Only businesses that trade away their human rights for limited liability by incorporating should be covered by such legislation, if anyone.
Re: Let's Ban SMS 2FA
#28Re: Let's Ban SMS 2FA
#29Re: Let's Ban SMS 2FA
#30So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…
If im giving my phone number and a second factor to verify me, I don’t want it repurposed as a single factor backdoor. Too often companies dont advertise that it’s a backdoor into the account, or the feature gets added after they collect the info.