Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

231–240 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#231
post #195
post #190

Earlier quoted context omitted.

>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…

> anon SIM are no longer allowed in the EU Ah. That explains why they asked for my life history when I tried to buy a local SIM in Italy.

Ironically, this is only true for prepaid SIMs. As a result, in some EU countries it's easier to get a month-by-month postpaid plan – sometimes there's no KYC at all for these...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#232
post #81

Earlier quoted context omitted.

This is probably compliance-related. For me, TOTP isn’t “something I have”, it’s another thing I toss into my password manager and sync to all devices. I really agree with it, but that’s probably their rationale.

That same rationale wouldn't support SMS as "something I have." iMessage and other solutions easily spread SMS into cloud and PC lands (ones that are more easily accessible than password managers.) More likely it's because of legacy and "good enough" reasons. Personally I don't put TOTP tokens into my password manager and keep a dedicated app for it, just in case my password manager is pwned.

I'm not really defending it, I'm explaining the mentality. iMessage is probably closer to "something I have" but yeah, often not true for many American users.

I'd probably keep a TOTP app if I actually brought my cell with my everywhere but I really don't feel like it; if I'm heading to a cafe to work for a bit I might need to access something and can't be bothered to bring two devices.

Plus, people increasingly access stuff from cell phones, so it's not a guarantee of "something you have" anymore. And no shot we're convincing everyone to start carrying some kind of hardware token.

You have to remember that cybersecurity is driven by what is secure so much as what is compliant, and increasingly so.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#233
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

The problem isn't discrimination of SMS number types, it's SMS itself should be illegal, period.

SMS itself is just fine, the problem is companies making me use it in ways I don't care for.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#234

Can we just go back to having passwords please. I hate this state of authentication on the web.

I also hate this state of authentication on the web, but passwords have problems as mentioned in the other comment. API keys are also just another kind of passwords, so they aren't very good either. I think X.509 client authentication would be better, especially for connections that insist on using TLS.

(However, for some uses, signed messages which can be verified by anyone would be better, in case the message is intended to be public anyways; this is independent of the protocol.)

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#235
post #204

Earlier quoted context omitted.

They do not have to receive GPS, but it causes issues for e911 service if they do not. It has no impact on anything else, at least not the T-Mobile version.

The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal.

The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal.

Strange, because my AT&T Microcell didn't require a GPS signal. I kept it in the cabinet under the sink deep inside a large apartment building where there's no way it could get a GPS signal.

I haven't used since I moved a few years ago. Perhaps it's changed.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#236
post #89

Earlier quoted context omitted.

I'm surprised the major cell providers are cool with letting randos operate cell towers that back into an unknown untrusted ISP and their customers will automatically switch to when in range. It's unbelievably chill for companies that are usually so concerned about their image and controlling the whole experience end to end.

>I'm surprised the major cell providers are cool with letting randos operate cell towers that back into an unknown untrusted ISP and their customers will automatically switch to when in range. A lot of office buildings have these in them. I think the personal ones are how they get around some of the issues with government requiring them to build networks to certain coverage. They just don't build it out and when some…

A lot of office buildings have these in them. I think the personal ones are how they get around some of the issues with government requiring them to build networks to certain coverage. They just don't build it out and when someone complains they offer them one of these.

Also because a lot of office and residential towers have people high above street level, and the buildings have radiation-minimizing windows so that no cell signal can penetrate. The cell companies put their sites 30 feet above the street, not 600+ feet up.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#237
post #190

Earlier quoted context omitted.

>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…

> SMS is the only 2FA method that can be easily deployed at scale No, no, no, no, NO. No it's not. And you have zero proof of this. Its done this way because its the lowest effort to give security theater.

What's the theater with sms 2fa? That is more secure than not having it enabled no?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#238

Sounds like discrimination of a broad group of people. Granted, it's not a designated protected group, like by national origin, but I still think they have a good chance in court.

It's absolutely not discrimination and you're harming people by making such an absurd claim. Unreliable SMS delivery is not discrimination. This is how things end up on Fox News: "Is website security now discrimination?" > I still think they have a good chance in court Can you share the law you think was violated?

People love to eagerly advise litigation while remaining ignorant that a five-figure retainer is required to even get started on such a process.

And in the end, it's still a gamble that you may lose your case.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#240
post #204

Earlier quoted context omitted.

The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal.

The one I had, an AT&T Microcell, which was the only model offered by my cell provider, refused to work without a GPS signal. Strange, because my AT&T Microcell didn't require a GPS signal. I kept it in the cabinet under the sink deep inside a large apartment building where there's no way it could get a GPS signal. I haven't used since I moved a few years ago. Perhaps it's changed.

See:

https://paulstamatiou.com/review-att-3g-microcell

"After giving the MicroCell some power and ethernet, it will start blinking the 3G and GPS LEDs. Wait, what.. GPS? Yep. To limit the MicroCell from working outside of test markets (or out of the country too), it must get a GPS lock on your location. AT&T suggests this should take no longer than 90 minutes. It took me about 5 hours."

And this was the fundamental problem: there was absolutely no way to know if progress was being made or if it was going to run forever. It was literally a real-world Halting Problem.

Post reply on HN