Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

261–270 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#261
post #246

Earlier quoted context omitted.

Services like Authy address some of the loss of device issue, and always a good idea to have a backup token (e.g., yubikey) physically escrowed somewhere like a safe-deposit box. But it is a whole lot of extra work to set up and maintain long-term, even with the best intentions.

+1 for Authy. Just get a used cheap Android phone for like $30 and use it as the backup device for Authy and never fear about losing your 2FA device again.

Does Authy actually offer 2FA? It sounds like the security boils down to your encryption passcode used to encrypt the 2FA secret, so you aren't actually using 2FA at the end of the day.

For personal use it probably is a good compromise for services which don't implement 2FA properly (that is to say, services that don't allow you to register multiple 2FA devices.) But realistically you might want to just disable 2FA and rely on your password manager.

Re: Tell HN: SMS-based two-factor authentication is not secure

#263
post #2

Your problem is not with SMS as a second factor though. (Unless you think the attacker had your password as well). It is with the use of SMS as a single recovery factor. The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene.

This always bothers me. People say "SMS-based 2FA is bad" and then all the reasons they give have nothing to do with 2FA at all.

Re: Tell HN: SMS-based two-factor authentication is not secure

#264
post #2

Your problem is not with SMS as a second factor though. (Unless you think the attacker had your password as well). It is with the use of SMS as a single recovery factor. The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene.

If the argument is "but you still have a password" it really kind of shows how weak SMS 2FA is. Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe - it is itself just a strong auth mechanism, whereas SMS is adding extremely questionable value between the ability to phish SMS 2FAs or hijack the number. Even in a situation where the attacker would have neede…

Are we comparing it to a token though? Or are we comparing it to nothing?

Re: Tell HN: SMS-based two-factor authentication is not secure

#265
post #78

Earlier quoted context omitted.

I've signed up with voip.ms, which provides me a pay as you go sms number for basically $0/mo. since I only use it for auth.

Many services go out of their way to detect and block the use of VoIP numbers for SMS auth :s

I consistently use voip.ms for auth codes from my bank (TD), Whatsapp, Signal, and more that I'm likely forgetting. Highly recommend them.

Re: Tell HN: SMS-based two-factor authentication is not secure

#267
post #139

Earlier quoted context omitted.

They have to be able to issue a new SIM card without a pin in the case of a lost phone though. In that case they should probably check government identification, of course, and not be available remotely.

I thought you needed the PIN if you wanted that, too? As in, if you lose your phone and don't have the PIN set up with your carrier, you've lost your number and can't restore it.

That would mean eventually there would be no phone numbers left for anyone.

Re: Tell HN: SMS-based two-factor authentication is not secure

#268

In India almost all security mechanism is through 2 factor authentication that too mainly sms, with very few companies offering other forms of 2 factor authentication like authenticator app etc. If this happens in India there will be massive repercussions. Does anybody have any work arounds to this should it start happening to a few people?

Disclaimer: not Indian but living in India and I've not attempted to perform this hack. But if I'm not mistaken a SIM swap procedure is the similar to asking for a new SIM.

For Vodafone India, in addition to traditional info (date of birth, passport number, address), they actually asked me to give the number of someone whom I've called with this SIM, then they called that person and asked them to verify my identity. I found this to be quite secure.

But maybe the procedure is different for foreigners (at least the SIM creation procedure is different).

Re: Tell HN: SMS-based two-factor authentication is not secure

#269

As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to ba…

We have something vaguely similar with "BankID" in Norway. It's a bank issued digital ID that submits a 2FA to your phone (not through SMS, but through some other system that takes over the whole screen - not sure what it is). It's usable for almost all government agencies or official stuff online here, but I haven't seen anyone use it for third party auth as it costs roughly 10 cents per login for the service using…

From a usability standpoint it's not very good though. The experience differs from phone to phone and it kinda feels like a hack from a programmers point of view.

In Norway, Sparebank1 is pushing an app to get one-time codes now. I wonder if we'll see more of these in the future?

I use the Microsoft authenticator to get access to my Microsoft work account.

I bet if everyone starts making their own apps for one-time codes EU will demand a single app to do all of this.

Re: Tell HN: SMS-based two-factor authentication is not secure

#270
post #94

Earlier quoted context omitted.

if you immigrate, like I did, but still have some pension funds or saving accounts in your home country. Why would I want a local phone line?

So your bank can send you the SMS you need to sign in (which in itself indicates their security is poor).

most banks don't support international numbers if that what you meant
Post reply on HN