Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

241–250 of 379 posts

Re: SMS is not 2FA-secure

#241
post #186

Earlier quoted context omitted.

So how SHOULD this problem be solved? How should account recovery work?

Apps like Google authenticator, or more conveniently, a Google voice number. The Google voice solution works well since it can't be Sim swapped, and can be accessed via email (admittedly, a potential downside).

Google voice is a US only service.

Re: SMS is not 2FA-secure

#243
post #131

Earlier quoted context omitted.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

AFAIK, in the EU all banks are required to have "strong authentication" which usually means using 2FA via biometric authentication on your phone. Classic Google Authenticator does not seem much more friction than that.

That is not true. Banks in the EU seem to vary a lot, as the definition of “strong” is not defined (plus many banks have not introduced it yet). Biometric is definitely not required. I use hw tokens but at least one of my banks is trying to move to weaker auth.

Re: SMS is not 2FA-secure

#244
Where were these five providers based? Was it just in the US? I wonder if the controls are more stringent; my suspicion would be that they are in Europe.

Re: SMS is not 2FA-secure

#245
post #236
post #197

Earlier quoted context omitted.

What if you are abroad? My debit card was recently blocked and I had to wait until I went back, walked in the bank and show my face and ID.

Before you go abroad you could notify your bank. Then in period you declared you are abroad they should lower expectation from "in person and ID" to phone call and other means of verification. After that period you are automatically back to normal security. That is for example how my debit card works. If I want to use it abroad I have to turn that feature on for whatever time I am abroad.

In Europe you have a telephone PIN codes, you have number generators on the app. There are lots of ways to authenticate yourself. IN Europe you no longer need to tell them whether you're abroad or not; I guess the ML algo's that monitor for fraud are so much better than before that this isn't needed.

Re: SMS is not 2FA-secure

#246
post #80

Earlier quoted context omitted.

I wish Apple added iMessage as a service to make 2FA more secure.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

My bank does. The iPhone app can generate tokens. I get the feeling that US retail banking is way behind Europe.

Re: SMS is not 2FA-secure

#247
post #229

Earlier quoted context omitted.

What about setting up two mobile phone numbers for recipients of the recovery code: 123 sent to phone #1 and 456 sent to phone #2? (Phone #1 is yours and phone #2 is your elected trusted partner’s) Won’t this work?

Who should single people sign up as #2? Their mom? And what if your SO is currently unavailable? This is a terrible scheme.

Doesn't have to be SO. It can be a trusted friend who knows in advance that you may voice call them in a password recovery scenario (voice calls not via text).

Edit: regarding the "lack of availability" at the point of wanting to reset the password: the urgency of resetting passwords should be considered a lesser inconvenience than the risk of having lost control of your account through insecure 2FA.

(I am simply supporting my original brain storming thought through ... I am not married to this idea in any way or form. Just a thought.)

Re: SMS is not 2FA-secure

#248
post #118

I want my things protected by a human with a process to unlock/reset/.. given some kind of proof of identity. Because with 99.99% certainty the person that needs to unlock the account is me, and not an attacker. Even with a dozen backup yubikeys and spare codes written down I’d still be much more likely to lock myself out than be attacked. If it’s one thing I have learned the hard way it’s that the most dangerous per…

That's how https://jmp.chat/ works, and you can make your phone number as arbitrarily secure as you want with JMP. Any port-out requests are handled manually - you are contacted by a human to ensure that you made the request. You can ask them to put a verification code on file for you to confirm when this happens if you're concerned about the security of your XMPP account (which itself could use whatever kind of auth…

Good luck trying to use VOIP numbers with US banks these days

Re: SMS is not 2FA-secure

#249
post #131

Earlier quoted context omitted.

I wish banks and suchlike would get with the program and use Google Authenticator or equivalent. Even if iMessage could be a more secure 1.5FA, it would still be 1.5FA and not true 2FA.

After using TOTP like Google Authenticator since around 2013, I now think the friction needed is just too great. Especially for banks which log you out after 15 minutes or so of idleness. Google doesn't do that. Not to mention Google Authenticator deliberately prevents these stored tokens to be backed up and transferred to a different device, which makes upgrading devices troublesome. I wish everyone would start usin…

People recommend Authy. As far as I can tell they rely on cloud sync/backup like any other app in that space.

Isn’t google authenticator not using this on purpose? Central account and sync is googles thing and yet they deem it too insecure. Completely understandable

So how can using a central service that adds yet another attack vector be of value?

What I would love to have is a paper export. Every time you add a new account to google authenticator you can print it as QR code for later reimport.

Yes many services already provide this for you via recovery codes but having it on a per service basis directly from authenticator is probably much easier to use and not less secure

Any reason this wouldn’t work?

Re: SMS is not 2FA-secure

#250
post #188

Earlier quoted context omitted.

So how SHOULD this problem be solved? How should account recovery work?

Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.

what store for online-only services?
Post reply on HN