Live data from Hacker News

Let's Ban SMS 2FA

lorendb.dev

21–30 of 46 posts

Re: Let's Ban SMS 2FA

#21
post #5

Earlier quoted context omitted.

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

>When the barrier to adoption and inconvenience to the user is so low Is it low though? I'm not sure my parents could figure out how to use an authenticator app.

Then your Patents should not be near any account that should reasonably require 2FA. They are perfect prey for scammers.

Re: Let's Ban SMS 2FA

#22
No mention of why SMS 2FA is so popular: it's way easier for everyday users and customer support people to handle than the other options.

If you want to advance this argument, explore how customer service would evolve with a different method, or how user experience could be improved with passkeys. It's not a technology problem.

Re: Let's Ban SMS 2FA

#23
post #5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

Out of curiosity - do you think that difficulty of installation is what keeps people from installing a vault door on their home?

I imagine even if it were easier, you would see low adoption, because “I’ve never been robbed but I have locked myself out, does this mean I can’t call a locksmith anymore?” Would be top of people’s minds.

Re: Let's Ban SMS 2FA

#24
Has there ever been a confirmed case of snooping on cellphone traffic for the SMS with the one time password? I hear this argument a lot but the barrier here seems sufficiently high enough to make all but the most motivated bad actors seek other options. Even if this person is able to orchestrate the SMS capture, they ultimately are obtaining a code that expires in 10 minutes and therefore must be used very quickly before it becomes absolutely useless.

Re: Let's Ban SMS 2FA

#27
post #16
post #6

Sure, SMS 2FA isn't great. It may even be bad. But calling for government legislation to make that decision for other people is definitely bad. This is something you ban internally at your company or chose not to use yourself. Calling for government use of force against people who use SMS 2FA is really nasty. That said, maybe I'm missing come implicit context here and he's only taking about banning it for incorporate…

I'm talking about banning implementation of SMS 2FA server side. Individual users wouldn't be banned from using it, but it would be illegal to provide it as a company (or at least for important sectors like banks).

I am not talking about individual users using corporate services. Individual human people run services on the internet too. Non-incorporated businesses owned by humans should not be subject to this kind of thing. Nor should non-incorporated persons running services that are not businesses.

Only businesses that trade away their human rights for limited liability by incorporating should be covered by such legislation, if anyone.

Re: Let's Ban SMS 2FA

#28
My only other experience with 2FA flows other than SMS are the "Auth" apps that generate passkeys like authy or google authenticator. But more than once, I've updated my phone, or had to reset it, or switched phones, and been locked out of a service. In my experience, there's usually no automated flow to recover from those situations, and I've been forced to resort to opening a support ticket to reset my account password in a way that's usually far more insecure and could be hacked by simple social engineering, and it usually takes a few days to a few weeks to resolve.

Re: Let's Ban SMS 2FA

#29
SMS 2F seems better than most of the alternatives. Auth apps generally suck. Maybe they're more secure in theory but in practice, it's just another vector for me to leak my login.

Re: Let's Ban SMS 2FA

#30

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

SMS disaster recovery becomes 1FA.

If im giving my phone number and a second factor to verify me, I don’t want it repurposed as a single factor backdoor. Too often companies dont advertise that it’s a backdoor into the account, or the feature gets added after they collect the info.

Post reply on HN