Earlier quoted context omitted.
Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank
Or skip the website and use their native app.
Second factor SMS: Worse than its reputation
241–250 of 323 posts
Re: Second factor SMS: Worse than its reputation
#242Earlier quoted context omitted.
Kraken is a cryptocurrency exchange that utilizes (at least) two different TOTP codes, one for login and one for money transfers.
For a long time (still?) Kraken also refused to add SMS 2FA as an option due to its weak security. I still don't see how that's worse than no 2FA at all, which was an option, but I appreciated that they were banging the "SMS 2FA isn't very secure" drum.
I find it more secure in some contexts to never give a company my phone number at all if possible, so that it simply can’t be used as any kind of authentication no matter what.
Re: Second factor SMS: Worse than its reputation
#243Earlier quoted context omitted.
I'd like to throw a little blame onto many namebrand websites. Sites like Digital Ocean try to load dozens of third-party trackers for a single page. Their supposedly secure payment processing includes cross-site violations that are blocked by modern browsers. When their credit card management pages fail to work with reasonable browser defaults or sane browser add-ons they immediately advise their users to strip out…
I'd be interested in anybody explaining why a welcome page needs assets from 17 other domains, including paypal and stripe. https://cloud.digitalocean.com/welcome Why are multiple payment processors included on this page that doesn't involve any payment?
Stripe recommends putting stripe.js on every page to help detect fraud better (https://docs.stripe.com/js/including)
Re: Second factor SMS: Worse than its reputation
#244Earlier quoted context omitted.
I don't quite understand that. It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone. Additionally, many seem to want a "real phone number", not a VoIP number like Google Voice. Meanwhile treasurydirect.gov still just uses a verification code via email. If it's good enough for the Treasury, it's probably good enough for a bank.
> It's not like sending an SMS to my phone is any more secure or harder to access than sending an email to my phone. It's not, but much like 'fax' hanging on in the medical environment because it has been labeled "secure" by the regulations, there is a line in some regulation rule somewhere that labels "SMS" as "secure" but does not label "email" as "secure", and because they do the minimum to meet the regulation, th…
'Fax' is 'exempt' not secure. So of course many places will take the relief valve even though the service is both a poor fit / quality and horridly insecure. When it works right the records aren't even in a sealed envelope but just on the output of some printer somewhere for anyone to see!
Re: Second factor SMS: Worse than its reputation
#245Earlier quoted context omitted.
We at MakePlans were affected by this breach as we use Twilio. We are not using Twilio Verify (their 2FA api) but rather handle 2FA SMS ourselves in our app using Twilio as one of our providers. So the CCC definition of this being only 2FA-SMS is incorrect, it was all SMS sent through this Twilio third party gateway that was exposed to a limited set of countries (France, Italy, Burkina Faso, Ivory Coast, and Gambia).…
I think 2FA via texts is better than no 2FA. But only if you do not make the texts world readable. Apart from that, to me it seems justifiable to follow a risk based approach. Booking systems up to a certain value/amount, fine. Online Banking and health related services, thank you, no.
Re: Second factor SMS: Worse than its reputation
#246A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank
Re: Second factor SMS: Worse than its reputation
#247NIST has explicitly said you shouldn't use SMS 2FA for a while now: NIST SP 800-63B §5.1.3.3. https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB
The perspectives and interests of NIST and the things that a service provider has has to worry about with respect to their customer/user experience are not necessarily aligned. Customer: "What do you mean two factor app? I thought the code was supposed to come to my phone?" Support: "It did, but we no longer support SMS two factor authentication." Customer: "But I had no problems when the code came to my phone." Supp…
"Unfortunately, many of our other customers, and customers of other financial institutions were not correctly protected by the code alone.. and were still getting scammed or confused.. and losing _all_ their money."
> Customer: "[...] I'm finding this very frustrating, I need to get into my account."
"That is understandable, but we take the security of your account and your personal information very seriously, and this requires us to make changes to maintain that security in the face of new threats and actors as they evolve."
Re: Second factor SMS: Worse than its reputation
#248Re: Second factor SMS: Worse than its reputation
#249A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
(I know I could have just typed "amazon.com" and gone directly. But browser autocomplete makes it a tiny bit easier to use the omni-url bar and just type "amazon" than "amazon.com")
Re: Second factor SMS: Worse than its reputation
#250Earlier quoted context omitted.
Why isn't there any market fulfillment for "safe, non-intrusive ads", on the part of a vendor? Is it because it's not possible, or not worth the overhead either because of cost or no effect on consumer behavior/blocking? This seems like it ought to be low-hanging fruit. I would have less aversion to clicking on ads if I did not default to it being a security risk.
I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads.
One of the original factors in the rapid uptake of Chrome was believed to be that the ads for it were the first time an ad appeared on google.com.