Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

221–230 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#221
post #187
post #116

What really grinds my gears is the seemingly unstoppable global transition towards SMS to a mobile phone number as means of identifying an individual, conflated with "security" through 2FA/account recovery, with this as the only option. This is especially popular within Fintech. Wise (formerly Transferwise) recently started requiring 2FA for signing in - SMS is the one and only option. Revolut requires it for acknowl…

Well, the European PSD2 has forbidden the use of SMS TANs last year for banking applications while requiring much more stringent 2FA use (for account balances more than 30 days in the past for instance). So, I would say quite the opposite to unstoppable.

And because it has not required some open standard as a replacement, I now have hundreds of MB of different bloatware bank apps on my phone, each of which I have to use in a slightly different way when logging into my bank accounts, usually with scanning barcodes or remembering yet another PIN. Migrating to a new phone is a nightmare.

For extra convenience, PSD2 also mandated a logout after 5 minutes of inactivity.

Some of the ideas behind PSD2 are great, but the outcome is about as good as the cookie directive.

Re: Tell HN: SMS-based two-factor authentication is not secure

#222
post #211

Earlier quoted context omitted.

Twilio, Kraken, Paypal, Gusto, Bittrex, Coinbase, ...

But none of these support U2F or WebAuthn at all. The problem isn't that they need to support "multiple" tokens except in the sense that they don't support any at all.

They all support TOTP and some (such as Kraken) support U2F.

Point is whether it's U2F or Web'n'Auth or TOTP they need to support multiple keys.

Re: Tell HN: SMS-based two-factor authentication is not secure

#223
post #207
post #35

Earlier quoted context omitted.

But that is my entire point. SMS as a second factor is purely additive. It cannot reduce security. There is pretty much no form of second factor that users are worse at passing than backup codes. Even if people print them out (few do), they won't find them when the emergency happens. You need some form of trust that can be bootstrapped again from scratch. For most of the world, SMS is it. The Nordic countries have th…

> But that is my entire point. SMS as a second factor is purely additive. It cannot reduce security. It most certainly can reduce security, that's the point. If I don't have a phone number on my account (which I almost universally don't) then no amount of SMS hijacking will ever matter. If some provider forces me to put a phone number in, now I may be vulnerable to a weakness I didn't want to be vulnerable to. Maaybe…

They specifically said "SMS as a second factor." What you're discussing here is a completely different different use of SMS that nobody is arguing in favor of.

Re: Tell HN: SMS-based two-factor authentication is not secure

#224

Earlier quoted context omitted.

that is because google and other companies derive more $ from your number than protecting your privacy/security

Google doesn't require SMS. They often ask me when I log in, but I can always hit 'skip', which I do because I'm scared of this exact case.

This is not universally true. If Google decides that your account looks suspicious, either at creation or a later date, you are unable to access it until you provide a phone number.

You also used to be unable to set up a U2F/FIDO 2FA without first setting up SMS 2FA (but you could delete the phone number from the account later). Not sure if that's still the case.

Re: Tell HN: SMS-based two-factor authentication is not secure

#225
post #9

I think crypto companies should block withdraws for a period of time after a password recovery. (OP, you are calculating your losses, but didn't specify what those losses were. Did the theif get your crypto?)

Coinbase has extensive access to mobile provider data. They can see when number ported and what phone the thief uses, but it's really hard to make decisions.

I understand that it's hard in the edge cases, but a port followed by account recovery within a short period of time should be enough of a red flag to immediately lock the account.

Re: Tell HN: SMS-based two-factor authentication is not secure

#226
Happened to me as well. I found out who the actual people who hijacked it due to their poor operational security awareness. Found out they did this to someone every 2 weeks. Nobody cared as they successfully stole $0. I've watched the news to see if they were ever caught; I assume they are still doing it to this day.

Re: Tell HN: SMS-based two-factor authentication is not secure

#227

The worst part is, Coinbase will not cover your losses. They have absolved themselves of any responsibly for users being hacked, only if they [coinbase] gets hacked.

Since I wasn't sure if this is just what their ToS claim or how it's handled in practice, I googled a bit, and found this case:

https://finance.yahoo.com/news/coinbase-hacked-accounts-get-...

So this indeed seems to be how Coinbase handles it.

Re: Tell HN: SMS-based two-factor authentication is not secure

#229

Earlier quoted context omitted.

Coinbase has extensive access to mobile provider data. They can see when number ported and what phone the thief uses, but it's really hard to make decisions.

I understand that it's hard in the edge cases, but a port followed by account recovery within a short period of time should be enough of a red flag to immediately lock the account.

> A port followed by account recovery within a short period of time should be enough of a red flag to immediately lock the account

What happens if a legitimate customer's phone gets lost and they quickly transfer the number and reset their accounts?

I think they should do a video call verification.

Re: Tell HN: SMS-based two-factor authentication is not secure

#230
It's a major issue in South Africa too with bank accounts being raided.

Bank says not my problem if your password got compromised. Cellphone provider says not my problem - SMS was never advertised/intended as secure.

So the user just has to deal with bank account being drained

Post reply on HN