Can someone explain to me how SIM swapping actually works? All the articles and videos I found are like: 1. Attacker calls phone companies support hotline or alternatively his confidante there 2. ** MAGIC ** 3. Atacker has access to SMS messages sent to victims number I understand that some might be deliberately vague but I don't want a step by step instructions, just a high level technical overview. And to give anot…
If you have a never registered, not expired SIM for a carrier, the carrier can register it to an account given the IMSI. You can also do this with eSIM without needing a physical SIM. So, step 1, convince the carrier representative. Step 2, give the the IMSI. Step 3, put the sim in your phone and receive SMS. If you do step 1 in a physical store, the representative will probably give you a new sim from their stack ev…
Second factor SMS: Worse than its reputation
211–220 of 323 posts
Re: Second factor SMS: Worse than its reputation
#212Earlier quoted context omitted.
Or they were using 2FA by email until an auditor told them "that's not 2FA" at which point they realized that their middleware to send notifications supports SMS as well as email.
I don't quite understand that. It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone. Additionally, many seem to want a "real phone number", not a VoIP number like Google Voice. Meanwhile treasurydirect.gov still just uses a verification code via email. If it's good enough for the Treasury, it's probably good enough for a bank.
It's not, but much like 'fax' hanging on in the medical environment because it has been labeled "secure" by the regulations, there is a line in some regulation rule somewhere that labels "SMS" as "secure" but does not label "email" as "secure", and because they do the minimum to meet the regulation, they go with "SMS" and go on about their day.
Re: Second factor SMS: Worse than its reputation
#213Earlier quoted context omitted.
> Let’s not make an inferior solution mandatory when we already have a superior solution. With a slight caveat that it doesn't work. At least not on Linux without some proprietary junk dongles or their emulators.
Huh, can you be more specific? I thought I was using this on Linux with bitwarden. Is a yubikey “junk?”
Stuff that I could do without, like a yubikey, is junk in my books.
Re: Second factor SMS: Worse than its reputation
#214NIST has explicitly said you shouldn't use SMS 2FA for a while now: NIST SP 800-63B §5.1.3.3. https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB
The perspectives and interests of NIST and the things that a service provider has has to worry about with respect to their customer/user experience are not necessarily aligned. Customer: "What do you mean two factor app? I thought the code was supposed to come to my phone?" Support: "It did, but we no longer support SMS two factor authentication." Customer: "But I had no problems when the code came to my phone." Supp…
Re: Second factor SMS: Worse than its reputation
#215But for login you basically register a single phone, download a certificate to it and that becomes your second factor. If you login via web or another phone, you need to approve the login from that phone.
Of course if you lose the phone (or it's damaged) you need to go to the bank to fix it, but that seems like a reasonable approach.
Re: Second factor SMS: Worse than its reputation
#216I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…
> I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. A password manager is, in essentially every respect except interoperability, inferior to WebAuthn. Let’s not make an inferior solution mandatory when we already have a superior solution.
Re: Second factor SMS: Worse than its reputation
#217Earlier quoted context omitted.
Well, TIL
It's really incomprehensible, whatever minuscule revenue Apple is getting from running this protection racket, I mean ad network, must be minuscule compared to the potential damage they cause to their users and brand. But I guess that's next quarter's problem.
Re: Second factor SMS: Worse than its reputation
#218Earlier quoted context omitted.
> an attacker who paid for Google Ads for a search term like "BANKNAME login" I tried out buy Google ads once out of curiosity cause they gave me a free credit. It was crazy how many ridiculous stipulations and guidelines I had to work around before they'd accept my ad. How are they that strict for me, but seemingly they'll sell to a phishing page that's impersonating a bank and targeting it to people searching for t…
Because the impersonator is probably a lot more sophisticated at this than you or I, and it's likely that 999 impersonators were rejected and this is just the 1/1000 who found a way around it. The system probably produces a lot of false positives AND negatives.
Re: Second factor SMS: Worse than its reputation
#219A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
Maybe a secure browser profile that blocks search engine usage and can only visit sited in bookmarks or a whitelist so if you get a new bank and its not on the common whitelist have to explicitly add it to bookmarks.
Use your Chrome secure profile tm for banking and refuse to auto complete payment info on the insecure side.
Re: Second factor SMS: Worse than its reputation
#220Earlier quoted context omitted.
In the past I've heard people say the opposite - that if less computer savvy people are using google instead of URLs, it's a good thing. The reasoning was it protects them against typosquatters and whitehouse.com situations. I guess when people were giving out that advice, google wasn't the way it is now.
Yeah -- this was good logic back in the day. Now one has to scroll down -- sometimes several links -- before finding a link that isn't an ad. Maybe this is where encouraging people to use the "I'm Feeling Lucky" button would help, because it should still go to the top non-ad-link?