Earlier quoted context omitted.
It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.
I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.
SMS 2FA is not just insecure, it's also hostile to mountain people
211–220 of 328 posts
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#212Earlier quoted context omitted.
By brokerage suports TOTP but not my bank. My bank does support Yubikey-type devices though.
Vanguard supports Yubikeys. I'm yet to use a bank (~8 of them so far) that supports anything other than SMS.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#213Earlier quoted context omitted.
It just saddens me that you can be so devoid of empathy.
This kind of performative "empathy" people talk about in online forums is not true empathy. It's frequently the case that prioritizing this fake "empathy" results in bad outcomes. It saddens me when people use "empathy" to justify policy with strongly negative overall consequences. It's how you end up with, for example, the disaster zone that large chunks of San Francisco were before Lurie started cleaning up a few m…
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#214Can we just go back to having passwords please. I hate this state of authentication on the web.
We have known for decades how to do better than that. The fact that at least twice a month (often much more) I read an HN comment saying passwords are great is like discovering most of your friends don't know about germ theory still. I feel so fucking tired.
With a Shared Secret system the person authenticating you can give away the fucking secret and we already know we live in a society where they will blame you and act as though there's nothing they should have done better - that's what "Identity theft" is - blaming other people for the fact you didn't do your job properly.
When you use Human Memorable secrets the humans try to remember them, which means they're usually very low quality, dog's name, favourite band, that sort of thing. Worse, since humans can't remember many things they usually choose only a few and re-use them, so now they're not only a Shared Secret they're also Reused which is even worse.
So then we end up with a whole pile of kludges to try to use "passwords" which aren't really memorable, losing most of the benefits yet still retaining most of the disadvantages. This is an awful situation to be in, it's taken a considerable amount of laziness and incompetence to achieve it.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#215Earlier quoted context omitted.
I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.
Fwiw, Symantec VIP is TOTP under the hood, and you can extract the seed with some hackery. There is at least one financial institution in the US that uses that.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#216Earlier quoted context omitted.
They do not have to receive GPS, but it causes issues for e911 service if they do not. It has no impact on anything else, at least not the T-Mobile version.
The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#217> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#218> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…
>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…
No, no, no, no, NO. No it's not. And you have zero proof of this. Its done this way because its the lowest effort to give security theater.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#219> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…
...
"... unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons ..."
Correct.
This is, in fact, a terrible idea because even if you do find a VOIP provider that can receive SMS from "short codes" (the weird little numbers your bank sends codes from) that is a temporary oversight and will get "fixed" eventually.
Remember:
None of this is for your security or to help you. All of these measures are just sand in the gears to slow down the relentless onslaught of scam/spam traffic.
Your bona fide mobile phone number is a "proof of work" that these providers are relying on in absence of any real solution to this problem.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#220Earlier quoted context omitted.
This kind of performative "empathy" people talk about in online forums is not true empathy. It's frequently the case that prioritizing this fake "empathy" results in bad outcomes. It saddens me when people use "empathy" to justify policy with strongly negative overall consequences. It's how you end up with, for example, the disaster zone that large chunks of San Francisco were before Lurie started cleaning up a few m…
You're bringing in all sorts of unrelated things here. The simple reality is that expecting a 70-year old to leave their entire life behind and move to the city just because of a relatively simple issue like this, is deeply and profoundly unemphatic. As is the general principle of not accepting that some people may want to choose a slightly different life from what you might choose for yourself. No one is asking the…