Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

201–210 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#201
post #7

I wonder what the companies requiring 2FA think about uncompleted 2FA bounces. Deterred fraudster? Short attention span? SMS sucks?

I implemented 2FA at a previous job and I was responsible for the production implementation working as expected. My thoughts were that uncompleted 2FA attempts are common for a number of reasons: typos, someone gets distracted, didn't have access to phone at the time, SMS sucks (either our sending side or the receiving side), etc. I didn't put much thought into it beyond that. (Should I?)

I implemented rate limiting/lockouts for too many 2FA failures. I added the ability to clear the failed attempt count in our customer support portal. If we had any problems after those were implemented, I never heard about them.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#202
post #97

Earlier quoted context omitted.

It seems t-Mobile no longer offers such hardware: https://www.t-mobile.com/support/coverage/4g-lte-cellspot-se...

Maybe T-Mobile doesn't need to. I've used their WiFi calling for, what, going on ten years probably. Works a treat, including getting short code SMS. Ergo, I don't know the use case for femtocell for T-Mobile. That's why I was surprised to learn via TFA that WiFi isn't the solution in all cases.

We moved to a T-Mobile femtocell precisely because their wifi calling was absolute shit in our experience. Dropped calls, no group SMS, no SMS/RCS images, frequently no calling service at all. The femtocell fixed all of that for us, and it has remained fixed.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#203

Earlier quoted context omitted.

Eh, assuming it's 4G LTE (or above), it's literally the same thing as Wi-Fi calling. This is technically called IMS (IP Multimedia Subsystem, https://en.wikipedia.org/wiki/IP_Multimedia_Subsystem ), and is powered by "magic" DNS (no kidding, everything points to 3gppnetwork.org) and literal IP + IPSEC. Even when your phone is connected to Wi-Fi, it enters a special mode called IWLAN which powers your Wi-Fi calling, S…

No, in this case the consumer femtocells on the market (AT&T Cell Booster, Verizon LTE Network Extender) are actual eNodeBs inside the carrier’s RAN. They will IPSEC tunnel back to a security gateway (SeGW), grab provisioning information, and then come up on the carrier’s commercial license as just another (fancy low powered) LTE radio on the network. AT&T did try to add some additional tamper switches and protection…

Thanks for injecting some hard facts into this. Too many folks don't understand the difference.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#204
post #197

Earlier quoted context omitted.

> She just needs a microcell/femtocell. Those come with their own set of problems. In particular, they have to be able to receive a GPS signal, which is often not possible in mountainous terrain. I had a microcell for years and it was nightmarishly unreliable. Not only would it regularly (but randomly) just stop working, it would give absolutely no indication of why it was not working.

They do not have to receive GPS, but it causes issues for e911 service if they do not. It has no impact on anything else, at least not the T-Mobile version.

The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#205
post #190
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…

> anon SIM are no longer allowed in the EU

Surely Ireland still allows them? If not, they're trivial to source from NI.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#206
post #190
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…

Anon SIM cards are still allowed in some EU countries: https://prepaid-data-sim-card.fandom.com/wiki/Registration_P...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#207
post #72

At this point it's pretty clear 2FA SMS is just a ploy to get PII customer data under the guise of security

The ONLY accounts I have that require SMS and offer no other 2FA are financial institutions. They already have more information on their customers than most other businesses I can think of. Heck, I WANT my bank to have my phone number so they can call me if there's ever a problem. I just want insecure SMS to stop being the only minor hurdle between a fraudster and my life savings. Companies do SMS because their VP of…

This has been my experience as well.

I implemented 2FA for my previous employer and we would have gladly skipped SMS 2FA if we could get away with it. It's more expensive for the company and the customer. And it sucks to implement because you have to integrate with a phone service. The whole phone system is unreliable or has unexpected problems (e.g. using specific words in a message can get your texts blocked). Problems with the SMS 2FA is a pain for customer service too.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#209
Isn't SMS 2FA immune to SIM swapping attacks when the SIM is an unregistered PAYG one?

i.e. there is no way to contact the carrier and get the number reassigned to a new SIM unless one first registers the SIM, and hence binds the number to a known identity.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#210
Something somewhere is always hostile to particular group. That's just facts of life. You do your best to minimize but can never eliminate it.

As someone who has dealt with 2FA support, all the methods suck.

SMS 2FA is least secure but has broadest support with quickest recovery method.

TOTP Applications (Google Auth, Authy, iOS Passwords) is more secure but people switch phones, lose phones and so forth and recovery is always a nightmare.

Yubikey and like have cost problem and you still have recovery problem.

A clear solution in my mind is having the Federal Government run some form of centralized hardware based system where hardware could be replaced by government office after verifying identity. Government does this already for DoD CaC cards. However, in the United States, Privacy Advocates would lose their minds, and funding would constantly be under attack.

So yea, I get SMS 2FA is hostile to mountain people but 2FA is hostile to login services and executive yachts.

Post reply on HN