Earlier quoted context omitted.
> But that is my entire point. SMS as a second factor is purely additive. It cannot reduce security. It most certainly can reduce security, that's the point. If I don't have a phone number on my account (which I almost universally don't) then no amount of SMS hijacking will ever matter. If some provider forces me to put a phone number in, now I may be vulnerable to a weakness I didn't want to be vulnerable to. Maaybe…
They specifically said "SMS as a second factor." What you're discussing here is a completely different different use of SMS that nobody is arguing in favor of.
Tell HN: SMS-based two-factor authentication is not secure
241–250 of 291 posts
Re: Tell HN: SMS-based two-factor authentication is not secure
#242Earlier quoted context omitted.
And because it has not required some open standard as a replacement, I now have hundreds of MB of different bloatware bank apps on my phone, each of which I have to use in a slightly different way when logging into my bank accounts, usually with scanning barcodes or remembering yet another PIN. Migrating to a new phone is a nightmare. For extra convenience, PSD2 also mandated a logout after 5 minutes of inactivity. S…
Absolutely agreed. I expect consolidation to happen in the next couple of years on this. Banks who do it well, will win customers.
One of my apps where I spend money on a regular basis (always similar small amounts, always from the same phone, usually from the same IP) constantly triggers 2FA via my banking app. Even as an informed customer, I have no idea whether to blame that app, their payment gateway, Visa/Mastercard, or my bank (that issued the credit card) for that bullshit.
The previous situation (banks absorb the fraud) seemed much better for me as the customer, and banks stuck with it. PSD2 made it so that customers can't pick their bank based on which is more convenient, by making them all at least roughly equally inconvenient. Few people will bother to change banks over this, and even fewer banks will feel enough pressure to actually improve.
Re: Tell HN: SMS-based two-factor authentication is not secure
#243Earlier quoted context omitted.
I understand that it's hard in the edge cases, but a port followed by account recovery within a short period of time should be enough of a red flag to immediately lock the account.
> A port followed by account recovery within a short period of time should be enough of a red flag to immediately lock the account What happens if a legitimate customer's phone gets lost and they quickly transfer the number and reset their accounts? I think they should do a video call verification.
Video verification sounds reasonable, as would some wait time. What's not reasonable in that situation is a self-service fully automated account recovery via SMS and e-mail verification followed by allowing withdrawals.
Re: Tell HN: SMS-based two-factor authentication is not secure
#244Earlier quoted context omitted.
But none of these support U2F or WebAuthn at all. The problem isn't that they need to support "multiple" tokens except in the sense that they don't support any at all.
They all support TOTP and some (such as Kraken) support U2F. Point is whether it's U2F or Web'n'Auth or TOTP they need to support multiple keys.
https://support.kraken.com/hc/en-us/articles/360001363963-Yu...
It doesn't make sense to try to "support multiple keys" for TOTP. You can copy-paste TOTP seeds if that's what you want and feel comfortable with, if the site tries to allow you to use any of N seeds they not only increase their system complexity they also reduce their security by a factor of N which makes no sense.
Edited to add: OK, Coinbase does now have U2F and they clearly state you can use "a maximum of 5 keys" which feels like that's enough.
Re: Tell HN: SMS-based two-factor authentication is not secure
#245Earlier quoted context omitted.
If someone can exploit your SMS, it's possible they can use that to social engineer their way into a password resets with services. (I forgot may password but I still have my phone.) So I would say a bad second factor can be strictly worse than no second factor.
You're describing single factor, not two factor. If you can change the password with SMS alone, it's not multi-factor. I plainly stated that exception two comments ago.
You can check if they appear to allow it today. Not perfectly, as they may have multiple variants and depending on other factors you might get presented with one or the other.
But you have no way to predict if next month a PM there decides their current password reset was too cumbersome and they change it to SMS-only. If you had a phone# on file, you're now suddenly vulnerable.
Re: Tell HN: SMS-based two-factor authentication is not secure
#246Earlier quoted context omitted.
I'm glad someone is bringing this up. I witnessed so many people lose access to their accounts because they wiped their phone that had an authenticator app, or they lost their physical 2FA tool.
Services like Authy address some of the loss of device issue, and always a good idea to have a backup token (e.g., yubikey) physically escrowed somewhere like a safe-deposit box. But it is a whole lot of extra work to set up and maintain long-term, even with the best intentions.
Re: Tell HN: SMS-based two-factor authentication is not secure
#247Your problem is not with SMS as a second factor though. (Unless you think the attacker had your password as well). It is with the use of SMS as a single recovery factor. The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene.
If the argument is "but you still have a password" it really kind of shows how weak SMS 2FA is. Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe - it is itself just a strong auth mechanism, whereas SMS is adding extremely questionable value between the ability to phish SMS 2FAs or hijack the number. Even in a situation where the attacker would have neede…
U2F and 2FA came to life just because people are bad at making passwords and remembering them.
Making non technical people to use password manager with generating passwords for each page is still hard.
Making non technical people use SMS as a second factor is easy.
Making non technical people use tokens is still hard.
There is a lot of value in having SMS 2FA still, yes you can phish it or you can hijack the number. But that is argument like: "there is no point in having any security at all because if you install malware on your computer you will get hacked".
Yes SMS alone is not going to save you, but people have phones and understand that they type code that comes via SMS to the phone number they provided when registering. Barrier to entry for it is so trivial that I think it still has value.
Barrier to entry to take over someones phone is not high but random kid on the street is not going to do that just like random kid that can find your email + de-hashed password from database dumps.
If you have someone who is motivated to get you then probably given enough time they will get you anyway.
So take into account what that SMS 2FA prevents and what issues it is solving. Don't just throw it away.
Re: Tell HN: SMS-based two-factor authentication is not secure
#248Earlier quoted context omitted.
> Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe Yeah, and it requires me to use a U2F token, which I can loose, etc. You have to balance security and usability, and SMS as a second factor seems like a perfectly reasonable balance.
I'm glad someone is bringing this up. I witnessed so many people lose access to their accounts because they wiped their phone that had an authenticator app, or they lost their physical 2FA tool.
Re: Tell HN: SMS-based two-factor authentication is not secure
#249That isn't 2FA. That is a single factor recovery process. SIM-swapping only defeats SMS-based 2FA if the attacker also has your password, which is difficult to accomplish if you are using good passwords that are unique.
I had to remove this detail from my original post as it was too long: Boost mobile is negligent and not following industry standards. Their whole security model is based on a 4-digit pin. At first I thought somebody had a script working its way up through all the combinations at the login screen, but I no longer feel that is the case. The fact that at least nine of us had this same issue within days makes me think th…
It might be confusing but that was account recovery attack.
For account recovery there is no "password" as thieves just made their own password while having your phone number.
So phone number as a password recovery option is not secure without any additional checks. Not 2FA because with this attack there was no second factor.
Re: Tell HN: SMS-based two-factor authentication is not secure
#250Earlier quoted context omitted.
If the argument is "but you still have a password" it really kind of shows how weak SMS 2FA is. Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe - it is itself just a strong auth mechanism, whereas SMS is adding extremely questionable value between the ability to phish SMS 2FAs or hijack the number. Even in a situation where the attacker would have neede…
If you have strong generated passwords that are different for each system and you use password manager then you would not need 2FA at all. Well maybe if it is for system that stores your password in plain text but who would be stupid to keep user password in plain text and slap 2FA on top of it. U2F and 2FA came to life just because people are bad at making passwords and remembering them. Making non technical people…
It might be confusing but that was account recovery attack.
For account recovery there is no "password" as thieves just made their own password while having victim phone number.
So phone number as a password recovery option is not secure without any additional checks. Not 2FA because with this attack there was no second factor.