Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

251–260 of 323 posts

Re: Second factor SMS: Worse than its reputation

#251
post #162

Earlier quoted context omitted.

They are still third-party ad networks that require a browser to cross multiple domains, etc. etc. etc. I am not ideologically opposed to advertisements but I do believe the only safe ads are first party hosted coming from the same domain.

most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site. things could get a lot better, but this self hosting suggestion in particular will never see wide adoption unless major hosting providers build it and host for their customers. most people don't even bother to self-host/bundle stuff like their fonts and JS libraries unless they…

> most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site.

That's sort of beside the point, though. The site owner's commitment to running ads is useless unless there are people to view them, and, as long as unsafe ads are ubiquitous, the only safe advice to give to people is that they should run ad blockers everywhere. It doesn't matter that that isn't what the site owner wants to happen.

Re: Second factor SMS: Worse than its reputation

#252
post #162

Earlier quoted context omitted.

They are still third-party ad networks that require a browser to cross multiple domains, etc. etc. etc. I am not ideologically opposed to advertisements but I do believe the only safe ads are first party hosted coming from the same domain.

most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site. things could get a lot better, but this self hosting suggestion in particular will never see wide adoption unless major hosting providers build it and host for their customers. most people don't even bother to self-host/bundle stuff like their fonts and JS libraries unless they…

Pack before the web most places doing ads had them al, in house, salesmen (mostly male) design and so on., large byers (mcdonalds) might hire an agency to talk to all the little newspapers, but even the little ones did this in house.

Re: Second factor SMS: Worse than its reputation

#253
post #175

Earlier quoted context omitted.

Intrusive ads are more profitable for the ad company, while the costs are largely born by other parties. A strategy to privatize the gains and socialize the costs is common in a lot of sleazy industries.

There is zero reason for ad companies or ad networks to be covered by any safe harbor provisions of the law. They should have 100% criminal liability for every mal-advertisement they send to a user.

Ads are a paid transaction and Ad Companies absolutely need to be held liable for the money that they take because of who they take it from voluntarily. Google should be ashamed at all the money they are making from scammers and criminals and other evils. They should have a terrible score at every agency remotely like the Better Business Bureau. They should be tarred and feathered in public opinion. The brand name should already be tarnished by all this Evil across too many years of negligence. Same goes for Meta/Facebook, though they do have some of the tarnish already, more than Google has managed to get to stick. (I think too many people still want to believe the "Do No Evil" lie and its lasting brand propaganda.) Other companies should be wary of working with Google because of that bad reputation. ("No, we won't be using GCP because Google does too much business with criminals.")

Yes, it is hard to scale Terms of Service enforcement. Yes it is a hard problem to solve finding bad actors at scale. That shouldn't be a free pass to just not do it at all. Especially when money is changing hands. If someone is paying you to be a bad actor they are either paying you to look the other way (called a "bribe" in most jurisdictions, and illegal in some of them) or you aren't doing due diligence before accepting bad money (called things like "laundering" and "embezzlement" at scale). "It's hard to scale" doesn't sound like a good excuse to do financial crimes, last I checked with banking regulators and is in fact the opposite (a larger crime); why should Google or Meta get a free pass in advertising because they don't want to put the work in and take the revenue hit?

Re: Second factor SMS: Worse than its reputation

#254
Certain financial institutions in some regions mandate telephone-network based 2FA for their customers accounts, and in the event of an account compromise attempt to pin the onus of liability on the customer. Maddening they wont give customers better options if they want to secure themselves.

Re: Second factor SMS: Worse than its reputation

#255

Earlier quoted context omitted.

I'm paranoid enough at this point that I check that the Cert authority for my bank is the one I know it to have before I log in on the website.

What's your process? Where do you save the cert? I'd be interested in automating that.

Oh nah, I just check the lock icon in firefox, and it's a pretty unusual (and not publically accessible) cert authority so I'd notice if it's a different one

Re: Second factor SMS: Worse than its reputation

#256
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

Passkeys or FIDO hardware tokens are the solution, as written up by Google ages ago, because they only enter the TOTP code when the URL matches the right site, it wouldn't enter the code for the phishing URL

Re: Second factor SMS: Worse than its reputation

#257

Earlier quoted context omitted.

There is zero reason for ad companies or ad networks to be covered by any safe harbor provisions of the law. They should have 100% criminal liability for every mal-advertisement they send to a user.

Ads are a paid transaction and Ad Companies absolutely need to be held liable for the money that they take because of who they take it from voluntarily . Google should be ashamed at all the money they are making from scammers and criminals and other evils. They should have a terrible score at every agency remotely like the Better Business Bureau. They should be tarred and feathered in public opinion. The brand name s…

> Yes, it is hard to scale Terms of Service enforcement. Yes it is a hard problem to solve finding bad actors at scale. That shouldn't be a free pass to just not do it at all.

What evidence do you have that they are "not doing it at all"?

Re: Second factor SMS: Worse than its reputation

#258

Earlier quoted context omitted.

The perspectives and interests of NIST and the things that a service provider has has to worry about with respect to their customer/user experience are not necessarily aligned. Customer: "What do you mean two factor app? I thought the code was supposed to come to my phone?" Support: "It did, but we no longer support SMS two factor authentication." Customer: "But I had no problems when the code came to my phone." Supp…

> Customer: "But I had no problems when the code came to my phone." "Unfortunately, many of our other customers, and customers of other financial institutions were not correctly protected by the code alone.. and were still getting scammed or confused.. and losing _all_ their money." > Customer: "[...] I'm finding this very frustrating, I need to get into my account." "That is understandable, but we take the security…

Stop threatening me. And what does Hollywood have to do with me logging in?

Re: Second factor SMS: Worse than its reputation

#259

Earlier quoted context omitted.

In the past I've heard people say the opposite - that if less computer savvy people are using google instead of URLs, it's a good thing. The reasoning was it protects them against typosquatters and whitehouse.com situations. I guess when people were giving out that advice, google wasn't the way it is now.

Yeah -- this was good logic back in the day. Now one has to scroll down -- sometimes several links -- before finding a link that isn't an ad. Maybe this is where encouraging people to use the "I'm Feeling Lucky" button would help, because it should still go to the top non-ad-link?

"Always use a bookmark" has always been the best advice. I'm fairly sure getting a bunch of typosquatting domains is standard practice now for major (particularly financial) sites so typing in the site from a reliable printed source for the first access is fine (particularly since you can be extra careful if you only do it once). For using shared computers, I'd still personally recommend typing from a reliable printed source.

For logins, a major advantage of having browsers save login info is to recognize legit sites becuase the login can be filled out (though it should be set to require a click on the login form and not just appear). Occasionally sites change in a way that breaks this but usually just once to use a subdomain and can be investigated more closely when it happens.

I think browsers should add a "site bookmark" feature that uses a well known mechanism to allow all associated sites to be annotated in a way that shows up similar to how EV certificates used to work (but is entered by users). That would make it possible to recognize legitimate links into a site (as long as you annotate the correct site the first time) and there could be an option to be notified when leaving the annotiated set of domains for particularly sensitive sites. Currently the closest is bookmarking the home page, editing the URL to remove everything after the domain, checking that the edited url is bookmarked (this is fragile since sites change the redirection quite a bit), and then hold the back button and go back to to the linked page, although this might not work for additional domains (e.g. support sites are often on a subdomain). Ideally, the site bookmarks would also annotate search results before they are clicked. While "remember to check if the site is legit" is not ideal it is a far better situation than "no way to tell if the site is legit". This could also be used to add a standard OTP entry mechanism that binds to a site and gives a warning if it is from a site you haven't given an OTP to before or stored login info (and shows the site name when you enter the OTP).

Re: Second factor SMS: Worse than its reputation

#260
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

Instead, the 2fa app should show you the action you are authenticating, just like the SMS version.

But actually, we have put way too much stuff on the (inherently transient) web. What solves your problem is permanent client-side storage. Your friend shouldn't reach the bank through a google search.

Post reply on HN