Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

261–270 of 323 posts

Re: Second factor SMS: Worse than its reputation

#261
post #151

Earlier quoted context omitted.

I still don’t understand why banks just don’t use FIDO2/WebAuthn yet. I’d much prefer to use a Yubikey over all other options at this point.

Because banks are financial institutions and every decision they make is based in that. If the cost of insurance is less than the cost to actually secure the system, they will choose that every time. Banks and payment processors have some of the worst technical debt. For example, a lot of transactions are processed using the ISO8583 standard, a binary bitmap-based protocol from the 80s. The way cryptography was bolte…

I don't work at a bank, but I do work in fintech, and this strikes me as excessively cynical. The reason banks are slow about this stuff is not necessarily because "it's cheaper" (though maybe it is), but because the complexity of any change is simply off the charts: money-related logic must work correctly, to a far higher standard than almost any tech company. It makes you conservative, in the same way that demanding 99.999% uptime is exponentially harder than demanding 99%, and makes moving quickly essentially impossible.

(Also, of course, they're probably working on COBOL stacks that were written in 1978.)

For a bank, pile on top of that mountains of (often conflicting) regulatory review, such that just about any change sounds the alarm for armies of nearby lawyers to swarm upon you and bury you in paper. All it takes 0.1% of annoyed users filing complaints that they can't access their accounts, and you might well be looking at a steep fine, a class-action lawsuit, or worse.

Re: Second factor SMS: Worse than its reputation

#262
post #250

Earlier quoted context omitted.

I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads.

> I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads. One of the original factors in the rapid uptake of Chrome was believed to be that the ads for it were the first time an ad appeared on google.com.

There were ads on google.com since at least 2000[1]. Chrome wasn't announced until 2008. Disclosure: I work at Google but not on ads or Chrome.

[1] https://googlepress.blogspot.com/2000/10/google-launches-sel...

Re: Second factor SMS: Worse than its reputation

#263
post #251

Earlier quoted context omitted.

most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site. things could get a lot better, but this self hosting suggestion in particular will never see wide adoption unless major hosting providers build it and host for their customers. most people don't even bother to self-host/bundle stuff like their fonts and JS libraries unless they…

> most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site. That's sort of beside the point, though. The site owner's commitment to running ads is useless unless there are people to view them, and, as long as unsafe ads are ubiquitous, the only safe advice to give to people is that they should run ad blockers everywhere. It doesn't mat…

there are plenty of site owners that would voluntarily choose a more ethical ad hosting network if it was a good and easy option.

adding a pain-in-the-ass hurdle like "has to be hosted on the same domain" that 99.99% of people won't see the value of or understand is only going to hurt adoption of the better solutions.

Re: Second factor SMS: Worse than its reputation

#264

Out of curiosity, I just tried with ChatGPT 4o... Screenshot of a legit banking website and asking it to describe it to me, to give me the exact URL in the screenshot and to tell me if it's legit or not. It described me the whole page, explaining it was a login page to log in to bank X in country Y. He compared the URL with the bank's name, etc. Then I modified one letter in the URL, changing " https://online.banking…

dumbass

Re: Second factor SMS: Worse than its reputation

#265
post #175

Earlier quoted context omitted.

Intrusive ads are more profitable for the ad company, while the costs are largely born by other parties. A strategy to privatize the gains and socialize the costs is common in a lot of sleazy industries.

There is zero reason for ad companies or ad networks to be covered by any safe harbor provisions of the law. They should have 100% criminal liability for every mal-advertisement they send to a user.

They don't. DMCA safe-harbor covers copyright violations. All it takes is a prosecutor willing to use the CFAA to hold business as accountable as people.

Re: Second factor SMS: Worse than its reputation

#266

Earlier quoted context omitted.

I don't see why SMS would need to write to a store, public or not. One can implement SMS-2FA using TOTP for example, it's just that the TOTP secret is not shared with the recipient.

Yes, it is not a technical necessity to store these messages. But there is the option to do it (and some people are evidently doing it). The point is that for one-time-passwords, it's not even an option, not matter how hard you try. You simply cannot make this class of mistake. Unless you try really really hard to fuck up and, say, for some very weird reason, exfiltrate the one-time passwords generated on the user's…

How does the bank verify the OTP generated on the user's device?

Re: Second factor SMS: Worse than its reputation

#267
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

I was saved from a phishing attack by using a password manager that refused to auto-fill my password since the hostname didn't match.

Re: Second factor SMS: Worse than its reputation

#268

Earlier quoted context omitted.

I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads.

The doubleclick acquisition was the end of that.

Isn't that when the business majors took over?

Re: Second factor SMS: Worse than its reputation

#269
post #250

Earlier quoted context omitted.

> I feel like this was one of the original selling points of Google's ads. They were pretty simple, unobtrusive, mostly text, ads. One of the original factors in the rapid uptake of Chrome was believed to be that the ads for it were the first time an ad appeared on google.com.

There were ads on google.com since at least 2000[1]. Chrome wasn't announced until 2008. Disclosure: I work at Google but not on ads or Chrome. [1] https://googlepress.blogspot.com/2000/10/google-launches-sel...

I believe they meant on https://google.com (the home page)

Re: Second factor SMS: Worse than its reputation

#270

Earlier quoted context omitted.

Turns out ads aren't just annoying little acts of psychological terrorism that eat up a lot of bandwidth and computing power, they are also the #1 vector for spreading scams and malware on the web. In other words: If you're trying to improve your security posture, installing an ad-blocker is one of the best things you can do. If you have less tech-savvy friends and relatives, I would strongly recommend setting up uBl…

Why isn't there any market fulfillment for "safe, non-intrusive ads", on the part of a vendor? Is it because it's not possible, or not worth the overhead either because of cost or no effect on consumer behavior/blocking? This seems like it ought to be low-hanging fruit. I would have less aversion to clicking on ads if I did not default to it being a security risk.

It doesn't seem to be profitable, in part because the internet now consists of mega-sites and if your network doesn't serve ads on the mega-sites, no one is interested in your network.

Project Wonderful was a fantastic webcomic-focused ad network. From my perspective as a reader, being shown ads for other webcomics while I'm reading a webcomic was... a positive, really. A lot of webcomic artists ran Project Wonderful ads and nothing else. They shut down in part because of the rise of facebook.

Post reply on HN