Earlier quoted context omitted.
So how SHOULD this problem be solved? How should account recovery work?
Apps like Google authenticator, or more conveniently, a Google voice number. The Google voice solution works well since it can't be Sim swapped, and can be accessed via email (admittedly, a potential downside).
SMS is not 2FA-secure
241–250 of 379 posts
Re: SMS is not 2FA-secure
#242Re: SMS is not 2FA-secure
#243Earlier quoted context omitted.
After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…
AFAIK, in the EU all banks are required to have "strong authentication" which usually means using 2FA via biometric authentication on your phone. Classic Google Authenticator does not seem much more friction than that.
Re: SMS is not 2FA-secure
#244Re: SMS is not 2FA-secure
#245Earlier quoted context omitted.
What if you are abroad? My debit card was recently blocked and I had to wait until I went back, walked in the bank and show my face and ID.
Before you go abroad you could notify your bank. Then in period you declared you are abroad they should lower expectation from "in person and ID" to phone call and other means of verification. After that period you are automatically back to normal security. That is for example how my debit card works. If I want to use it abroad I have to turn that feature on for whatever time I am abroad.
Re: SMS is not 2FA-secure
#246Earlier quoted context omitted.
I wish Apple added iMessage as a service to make 2FA more secure.
I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.
Re: SMS is not 2FA-secure
#247Earlier quoted context omitted.
What about setting up two mobile phone numbers for recipients of the recovery code: 123 sent to phone #1 and 456 sent to phone #2? (Phone #1 is yours and phone #2 is your elected trusted partner’s) Won’t this work?
Who should single people sign up as #2? Their mom? And what if your SO is currently unavailable? This is a terrible scheme.
Edit: regarding the "lack of availability" at the point of wanting to reset the password: the urgency of resetting passwords should be considered a lesser inconvenience than the risk of having lost control of your account through insecure 2FA.
(I am simply supporting my original brain storming thought through ... I am not married to this idea in any way or form. Just a thought.)
Re: SMS is not 2FA-secure
#248I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…
That's how https://jmp.chat/ works, and you can make your phone number as arbitrarily secure as you want with JMP. Any port-out requests are handled manually - you are contacted by a human to ensure that you made the request. You can ask them to put a verification code on file for you to confirm when this happens if you're concerned about the security of your XMPP account (which itself could use whatever kind of auth…
Re: SMS is not 2FA-secure
#249Earlier quoted context omitted.
I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.
After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…
Isn’t google authenticator not using this on purpose? Central account and sync is googles thing and yet they deem it too insecure. Completely understandable
So how can using a central service that adds yet another attack vector be of value?
What I would love to have is a paper export. Every time you add a new account to google authenticator you can print it as QR code for later reimport.
Yes many services already provide this for you via recovery codes but having it on a per service basis directly from authenticator is probably much easier to use and not less secure
Any reason this wouldn’t work?
Re: SMS is not 2FA-secure
#250Earlier quoted context omitted.
So how SHOULD this problem be solved? How should account recovery work?
Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.