Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

241–250 of 323 posts

Re: Second factor SMS: Worse than its reputation

#241
post #43

Earlier quoted context omitted.

Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank

Or skip the website and use their native app.

then you can't block anything

Re: Second factor SMS: Worse than its reputation

#242
post #210
post #109

Earlier quoted context omitted.

Kraken is a cryptocurrency exchange that utilizes (at least) two different TOTP codes, one for login and one for money transfers.

For a long time (still?) Kraken also refused to add SMS 2FA as an option due to its weak security. I still don't see how that's worse than no 2FA at all, which was an option, but I appreciated that they were banging the "SMS 2FA isn't very secure" drum.

It’s worse in a lot of implementations because often SMS is often used as part of a recovery flow in cases where you lose the first factor.

I find it more secure in some contexts to never give a company my phone number at all if possible, so that it simply can’t be used as any kind of authentication no matter what.

Re: Second factor SMS: Worse than its reputation

#243

Earlier quoted context omitted.

I'd like to throw a little blame onto many namebrand websites. Sites like Digital Ocean try to load dozens of third-party trackers for a single page. Their supposedly secure payment processing includes cross-site violations that are blocked by modern browsers. When their credit card management pages fail to work with reasonable browser defaults or sane browser add-ons they immediately advise their users to strip out…

I'd be interested in anybody explaining why a welcome page needs assets from 17 other domains, including paypal and stripe. https://cloud.digitalocean.com/welcome Why are multiple payment processors included on this page that doesn't involve any payment?

pptm.js is paypal's tag manager, for "Marketing Solutions". Gives the vendor shopper insights (clickthru, etc).

Stripe recommends putting stripe.js on every page to help detect fraud better (https://docs.stripe.com/js/including)

Re: Second factor SMS: Worse than its reputation

#244
post #212
post #100

Earlier quoted context omitted.

I don't quite understand that. It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone. Additionally, many seem to want a "real phone number", not a VoIP number like Google Voice. Meanwhile treasurydirect.gov still just uses a verification code via email. If it's good enough for the Treasury, it's probably good enough for a bank.

> It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone. It's not, but much like 'fax' hanging on in the medical environment because it has been labeled "secure" by the regulations, there is a line in some regulation rule somewhere that labels "SMS" as "secure" but does not label "email" as "secure", and because they do the minimum to meet the regulation, th…

Important distinction.

'Fax' is 'exempt' not secure. So of course many places will take the relief valve even though the service is both a poor fit / quality and horridly insecure. When it works right the records aren't even in a sealed envelope but just on the output of some printer somewhere for anyone to see!

Re: Second factor SMS: Worse than its reputation

#245

Earlier quoted context omitted.

We at MakePlans were affected by this breach as we use Twilio. We are not using Twilio Verify (their 2FA api) but rather handle 2FA SMS ourselves in our app using Twilio as one of our providers. So the CCC definition of this being only 2FA-SMS is incorrect, it was all SMS sent through this Twilio third party gateway that was exposed to a limited set of countries (France, Italy, Burkina Faso, Ivory Coast, and Gambia).…

I think 2FA via texts is better than no 2FA. But only if you do not make the texts world readable. Apart from that, to me it seems justifiable to follow a risk based approach. Booking systems up to a certain value/amount, fine. Online Banking and health related services, thank you, no.

It's not really 2FA even. More like a magic link (which is what we use for verification via email). The customer has no password, just verifies using a code via sms/email.

Re: Second factor SMS: Worse than its reputation

#246
post #43
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank

If Google ad words even allows a scammer to create an ad for a bank login page then we have a more fundamental problem.

Re: Second factor SMS: Worse than its reputation

#247

NIST has explicitly said you shouldn't use SMS 2FA for a while now: NIST SP 800-63B §5.1.3.3. https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB

The perspectives and interests of NIST and the things that a service provider has has to worry about with respect to their customer/user experience are not necessarily aligned. Customer: "What do you mean two factor app? I thought the code was supposed to come to my phone?" Support: "It did, but we no longer support SMS two factor authentication." Customer: "But I had no problems when the code came to my phone." Supp…

> Customer: "But I had no problems when the code came to my phone."

"Unfortunately, many of our other customers, and customers of other financial institutions were not correctly protected by the code alone.. and were still getting scammed or confused.. and losing _all_ their money."

> Customer: "[...] I'm finding this very frustrating, I need to get into my account."

"That is understandable, but we take the security of your account and your personal information very seriously, and this requires us to make changes to maintain that security in the face of new threats and actors as they evolve."

Re: Second factor SMS: Worse than its reputation

#248
I like that IdentifyMobile's website[0] isn't even protected with a valid HTTPS cert. Falls back to HTTP. Oh and it's WordPress. And last updated 2015. Guess that's all telling. Nice that so many important companies used this crappy provider for such things.

[0] http://www.identifymobile.com/

Re: Second factor SMS: Worse than its reputation

#249
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

just this week, I clicked on the 1st search result ad for "amazon" in google search. It led me to a windows-themed "Virus detected" amazon clone. I'm not using Windows. I was able to close the tab, but it left a bad taste in my mouth for google search results.

(I know I could have just typed "amazon.com" and gone directly. But browser autocomplete makes it a tiny bit easier to use the omni-url bar and just type "amazon" than "amazon.com")

Re: Second factor SMS: Worse than its reputation

#250

Earlier quoted context omitted.

Why isn't there any market fulfillment for "safe, non-intrusive ads", on the part of a vendor? Is it because it's not possible, or not worth the overhead either because of cost or no effect on consumer behavior/blocking? This seems like it ought to be low-hanging fruit. I would have less aversion to clicking on ads if I did not default to it being a security risk.

I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads.

> I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads.

One of the original factors in the rapid uptake of Chrome was believed to be that the ads for it were the first time an ad appeared on google.com.

Post reply on HN