Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

211–220 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#211
post #52

Earlier quoted context omitted.

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

Fwiw, Symantec VIP is TOTP under the hood, and you can extract the seed with some hackery. There is at least one financial institution in the US that uses that.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#212

Earlier quoted context omitted.

By brokerage suports TOTP but not my bank. My bank does support Yubikey-type devices though.

Vanguard supports Yubikeys. I'm yet to use a bank (~8 of them so far) that supports anything other than SMS.

There is at least one major US bank that supports Yubikeys and a different major that one supports (with some convincing) phone notification-based second factor.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#213
post #168

Earlier quoted context omitted.

It just saddens me that you can be so devoid of empathy.

This kind of performative "empathy" people talk about in online forums is not true empathy. It's frequently the case that prioritizing this fake "empathy" results in bad outcomes. It saddens me when people use "empathy" to justify policy with strongly negative overall consequences. It's how you end up with, for example, the disaster zone that large chunks of San Francisco were before Lurie started cleaning up a few m…

You're bringing in all sorts of unrelated things here. The simple reality is that expecting a 70-year old to leave their entire life behind and move to the city just because of a relatively simple issue like this, is deeply and profoundly unemphatic. As is the general principle of not accepting that some people may want to choose a slightly different life from what you might choose for yourself. No one is asking the world here. These are small accommodations at best.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#214

Can we just go back to having passwords please. I hate this state of authentication on the web.

Passwords are terrible. They're Human Memorable Shared Secrets, it's "What if somebody who doesn't know the first thing about cryptography tried to invent secure authentication?" and should have died out last century yet here we are.

We have known for decades how to do better than that. The fact that at least twice a month (often much more) I read an HN comment saying passwords are great is like discovering most of your friends don't know about germ theory still. I feel so fucking tired.

With a Shared Secret system the person authenticating you can give away the fucking secret and we already know we live in a society where they will blame you and act as though there's nothing they should have done better - that's what "Identity theft" is - blaming other people for the fact you didn't do your job properly.

When you use Human Memorable secrets the humans try to remember them, which means they're usually very low quality, dog's name, favourite band, that sort of thing. Worse, since humans can't remember many things they usually choose only a few and re-use them, so now they're not only a Shared Secret they're also Reused which is even worse.

So then we end up with a whole pile of kludges to try to use "passwords" which aren't really memorable, losing most of the benefits yet still retaining most of the disadvantages. This is an awful situation to be in, it's taken a considerable amount of laziness and incompetence to achieve it.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#215

Earlier quoted context omitted.

I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.

Fwiw, Symantec VIP is TOTP under the hood, and you can extract the seed with some hackery. There is at least one financial institution in the US that uses that.

USAA. Better than nothing, but since it doesn't do push notifications it's a needlessly proprietary piece. It's probably a combination of legal and a slow IT infrastructure.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#216
post #204

Earlier quoted context omitted.

They do not have to receive GPS, but it causes issues for e911 service if they do not. It has no impact on anything else, at least not the T-Mobile version.

The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal.

Similar experience here a few years ago w/ a Verizon microcell device. It wouldn't service clients w/o a GPS fix.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#217
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

The problem isn't discrimination of SMS number types, it's SMS itself should be illegal, period.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#218
post #190
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…

> SMS is the only 2FA method that can be easily deployed at scale

No, no, no, no, NO. No it's not. And you have zero proof of this. Its done this way because its the lowest effort to give security theater.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#219
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

"port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi"

...

"... unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons ..."

Correct.

This is, in fact, a terrible idea because even if you do find a VOIP provider that can receive SMS from "short codes" (the weird little numbers your bank sends codes from) that is a temporary oversight and will get "fixed" eventually.

Remember:

None of this is for your security or to help you. All of these measures are just sand in the gears to slow down the relentless onslaught of scam/spam traffic.

Your bona fide mobile phone number is a "proof of work" that these providers are relying on in absence of any real solution to this problem.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#220
post #213

Earlier quoted context omitted.

This kind of performative "empathy" people talk about in online forums is not true empathy. It's frequently the case that prioritizing this fake "empathy" results in bad outcomes. It saddens me when people use "empathy" to justify policy with strongly negative overall consequences. It's how you end up with, for example, the disaster zone that large chunks of San Francisco were before Lurie started cleaning up a few m…

You're bringing in all sorts of unrelated things here. The simple reality is that expecting a 70-year old to leave their entire life behind and move to the city just because of a relatively simple issue like this, is deeply and profoundly unemphatic. As is the general principle of not accepting that some people may want to choose a slightly different life from what you might choose for yourself. No one is asking the…

Nobody's asking them to leave their life behind! Talk about bringing in unrelated things! I'm saying we should recognize that lifestyle choices have consequences and that's OK. Not every consequence needs mitigation by third parties. Having to use a TOTP app and/or make a 20 minute trip into town to use some web services is not an unacceptable price to pay for the lifestyle choice of living in a remote area, and we shouldn't be vilifying people or branding them "devoid of empathy" for not prioritizing support for that use case over other, higher impact things they could do to improve their products.
Post reply on HN