Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

211–220 of 323 posts

Re: Second factor SMS: Worse than its reputation

#211
post #145

Can someone explain to me how SIM swapping actually works? All the articles and videos I found are like: 1. Attacker calls phone companies support hotline or alternatively his confidante there 2. ** MAGIC ** 3. Atacker has access to SMS messages sent to victims number I understand that some might be deliberately vague but I don't want a step by step instructions, just a high level technical overview. And to give anot…

If you have a never registered, not expired SIM for a carrier, the carrier can register it to an account given the IMSI. You can also do this with eSIM without needing a physical SIM. So, step 1, convince the carrier representative. Step 2, give the the IMSI. Step 3, put the sim in your phone and receive SMS. If you do step 1 in a physical store, the representative will probably give you a new sim from their stack ev…

Thanks, this is the hint I needed.

Re: Second factor SMS: Worse than its reputation

#212
post #100
post #86

Earlier quoted context omitted.

Or they were using 2FA by email until an auditor told them "that's not 2FA" at which point they realized that their middleware to send notifications supports SMS as well as email.

I don't quite understand that. It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone. Additionally, many seem to want a "real phone number", not a VoIP number like Google Voice. Meanwhile treasurydirect.gov still just uses a verification code via email. If it's good enough for the Treasury, it's probably good enough for a bank.

> It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone.

It's not, but much like 'fax' hanging on in the medical environment because it has been labeled "secure" by the regulations, there is a line in some regulation rule somewhere that labels "SMS" as "secure" but does not label "email" as "secure", and because they do the minimum to meet the regulation, they go with "SMS" and go on about their day.

Re: Second factor SMS: Worse than its reputation

#213

Earlier quoted context omitted.

> Let’s not make an inferior solution mandatory when we already have a superior solution. With a slight caveat that it doesn't work. At least not on Linux without some proprietary junk dongles or their emulators.

Huh, can you be more specific? I thought I was using this on Linux with bitwarden. Is a yubikey “junk?”

Software/OS passkeys weren't supported, at least not well enough for Github, on Linux when I last tried. Per web search they still don't.

Stuff that I could do without, like a yubikey, is junk in my books.

Re: Second factor SMS: Worse than its reputation

#214

NIST has explicitly said you shouldn't use SMS 2FA for a while now: NIST SP 800-63B §5.1.3.3. https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB

The perspectives and interests of NIST and the things that a service provider has has to worry about with respect to their customer/user experience are not necessarily aligned. Customer: "What do you mean two factor app? I thought the code was supposed to come to my phone?" Support: "It did, but we no longer support SMS two factor authentication." Customer: "But I had no problems when the code came to my phone." Supp…

It’s all a gradual improvement over time though, as both companies are able to adopt better practices and customers become accustomed to it. Many, many more people are using TOPT than a decade ago.

Re: Second factor SMS: Worse than its reputation

#215
In Singapore, the banks have moved away from SMS entirely, even for notifications. Now they have to come through the app.

But for login you basically register a single phone, download a certificate to it and that becomes your second factor. If you login via web or another phone, you need to approve the login from that phone.

Of course if you lose the phone (or it's damaged) you need to go to the bank to fix it, but that seems like a reasonable approach.

Re: Second factor SMS: Worse than its reputation

#216
post #63

I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…

> I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. A password manager is, in essentially every respect except interoperability, inferior to WebAuthn. Let’s not make an inferior solution mandatory when we already have a superior solution.

[deleted]

Re: Second factor SMS: Worse than its reputation

#217

Earlier quoted context omitted.

Well, TIL

It's really incomprehensible, whatever minuscule revenue Apple is getting from running this protection racket, I mean ad network, must be minuscule compared to the potential damage they cause to their users and brand. But I guess that's next quarter's problem.

Their ad business is generally booming but the brand rap can’t be worth letting these in. OTOH maybe it’s either all in or don’t bother. There’s no way to staff reviews at the scale you need an ads business to work.

Re: Second factor SMS: Worse than its reputation

#218
post #65

Earlier quoted context omitted.

> an attacker who paid for Google Ads for a search term like "BANKNAME login" I tried out buy Google ads once out of curiosity cause they gave me a free credit. It was crazy how many ridiculous stipulations and guidelines I had to work around before they'd accept my ad. How are they that strict for me, but seemingly they'll sell to a phishing page that's impersonating a bank and targeting it to people searching for t…

Because the impersonator is probably a lot more sophisticated at this than you or I, and it's likely that 999 impersonators were rejected and this is just the 1/1000 who found a way around it. The system probably produces a lot of false positives AND negatives.

And even at those failure rates (no matter how anecdotal), economies of scale creep in so a couple billion failures/day still would result in nearly a billion successes per year. The machine never rests and is fueled by creative people from all walks of life from every possible place on earth.

Re: Second factor SMS: Worse than its reputation

#219
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

I wish we could break people of the habit of searching for websites that they visit all the time and using search results to navigate to them.

Maybe a secure browser profile that blocks search engine usage and can only visit sited in bookmarks or a whitelist so if you get a new bank and its not on the common whitelist have to explicitly add it to bookmarks.

Use your Chrome secure profile tm for banking and refuse to auto complete payment info on the insecure side.

Re: Second factor SMS: Worse than its reputation

#220

Earlier quoted context omitted.

In the past I've heard people say the opposite - that if less computer savvy people are using google instead of URLs, it's a good thing. The reasoning was it protects them against typosquatters and whitehouse.com situations. I guess when people were giving out that advice, google wasn't the way it is now.

Yeah -- this was good logic back in the day. Now one has to scroll down -- sometimes several links -- before finding a link that isn't an ad. Maybe this is where encouraging people to use the "I'm Feeling Lucky" button would help, because it should still go to the top non-ad-link?

There was a time wherein the top result for facebook was a blog which faced a deluge of comments complaining that they couldn't log onto their facebook.
Post reply on HN