Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

231–240 of 323 posts

Re: Second factor SMS: Worse than its reputation

#231
post #45
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

> So really the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. My understanding of EU regulation is that it effectively requires this by requiring the 2FA to validate not just the identity but also the transaction (such as an amount, or d…

> Unfortunately it means that all banks use SMS

This is not true, I have used multiple financial things where they have different codes for different uses (Raiffeisen, K&H) or apps which have a server sent event and local approval showing the transaction (wise, Fineco)

Re: Second factor SMS: Worse than its reputation

#232

Earlier quoted context omitted.

Huh, can you be more specific? I thought I was using this on Linux with bitwarden. Is a yubikey “junk?”

Software/OS passkeys weren't supported, at least not well enough for Github, on Linux when I last tried. Per web search they still don't. Stuff that I could do without, like a yubikey, is junk in my books.

Bitwarden supports, may be beta. Passkeys are usually controlled by corporate controlled devices—why I haven’t used them yet. See:

https://news.ycombinator.com/item?id=39698502

Keeping the storage separate (or not) from the device may not be important to you but keys are useful to some, for that reason.

Re: Second factor SMS: Worse than its reputation

#233
post #162
post #131

Earlier quoted context omitted.

They are rare but do exist, see ethicalads and Modrinth’s ad program

They are still third-party ad networks that require a browser to cross multiple domains, etc. etc. etc. I am not ideologically opposed to advertisements but I do believe the only safe ads are first party hosted coming from the same domain.

most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site.

things could get a lot better, but this self hosting suggestion in particular will never see wide adoption unless major hosting providers build it and host for their customers. most people don't even bother to self-host/bundle stuff like their fonts and JS libraries unless they have have a JS framework in the loop doing it for them.

Re: Second factor SMS: Worse than its reputation

#234

I’ve recently become pretty disillusion with 2FA in general. Google has recently started enforcing their own “click yes on already authorize mobile device” 2FA, which is very frustrating. I have hardware 2FA keys that I keep in a safe. I deliberately do not keep them on me, and using them to re-auth is mentally an “event”. This is not the case with my cell phone, which my kids play with, gets left on my dresser while…

Google lets you choose which authenticators to use (SMS, push to mobile, TOTP, etc). It sounds like you should disable push to mobile for your accounts.

You cannot disable this anymore. You can add a hardware key, but cannot disable the mobile confirmation thing.

Re: Second factor SMS: Worse than its reputation

#235

Earlier quoted context omitted.

Only if I grant them root, which I'd only do to a very small number of open source apps I instead have to use my desktop web browser, and desktop operating systems have a far worse security model than Android. No special permissions are generally needed to capture the screen, capture/inject keystrokes, or open .mozilla/whatever/cookies.sqlite So my phone is still the significantly more secure environment. The fact th…

> Only if I grant them root But that's exactly the point. The bank doesn't know what you've granted root. It doesn't know if you're a security researcher, or somebody installing pirated apps with spyware. The bank can't enforce that on desktop web browsers, but at least it can on mobile.

Nope, they cannot enforce that on mobile when I have root.

Re: Second factor SMS: Worse than its reputation

#236
post #119
post #21

Earlier quoted context omitted.

So you say, that for Google, Amazon, Facebook, Microsoft, which are among those costumers, it is too hard to negotiate with the various teclos?

It's not their core business, which is why they let SMS aggregators deal with it and merely switch inbetween those.

Yes, and there are multiple levels of aggregators. For example, in a past life, I built SMS APIs and back-ends, including ones used by smaller telecoms to enable their subscribers to send/receive SMS. (We were pretty small, and only accounted for something like 0.5% if US SMS traffic)

We connected to multiple aggregators. It's been a few years, but the big players in the US (Verizon, AT&T, Sprint, T-Mobile) were split between different aggregators. It was a similar situation in Europe.

A big part of working with a new aggregator was a full review of security and privacy, and that became even more important as we began the process of being acquired by an F100 company.

I'm still trying to figure out why messages were stored in S3 buckets to begin with. That's an architecture choice that makes little sense to me, especially since the limited size of SMS makes them pretty space efficient.

Re: Second factor SMS: Worse than its reputation

#237
post #60

Earlier quoted context omitted.

My EU bank uses an app for consumer accounts. It hasn’t used sms for a few years, except when setting the app up on a new phone/sim.

> except when setting the app up on a new phone/sim. So it does when it needs to authenticate you :)

The difference is, it’s a pain, has happened twice in 5 years, and I know what triggered it, and it doesn’t happen with every 3d secure purchase or login.

So much less likely to get phished.

Re: Second factor SMS: Worse than its reputation

#238

Earlier quoted context omitted.

> Only if I grant them root But that's exactly the point. The bank doesn't know what you've granted root. It doesn't know if you're a security researcher, or somebody installing pirated apps with spyware. The bank can't enforce that on desktop web browsers, but at least it can on mobile.

Nope, they cannot enforce that on mobile when I have root.

Then why did the root commenter say:

> because their apps refuse to run on my rooted phone

Re: Second factor SMS: Worse than its reputation

#239
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

> The site was an immaculate knock off ... Then I can picture a great way, locally, to screw these knock off big times. Either the site is a great knock off, visually similar (if not identical) or it won't fool people, right? So what about this: what about the browser saving, locally, screenshots of the login pages you visit. Then, when a new login is made, compare, visually, the page to what's saved and see if any s…

I feel like PassKeys and browser-integrated password managers both solve this problem better already. And yeah they're extra things to do, but so is this.

Re: Second factor SMS: Worse than its reputation

#240
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

Turns out ads aren't just annoying little acts of psychological terrorism that eat up a lot of bandwidth and computing power, they are also the #1 vector for spreading scams and malware on the web. In other words: If you're trying to improve your security posture, installing an ad-blocker is one of the best things you can do. If you have less tech-savvy friends and relatives, I would strongly recommend setting up uBl…

TIP: I sold my senior mom on uBlock Origin because YT ads are so obnoxious. The added benefits are extra security and performance improvements. She was even able to understand that if something doesn't seem to be working right (like a banking site) "turn it off and try again".
Post reply on HN