Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

261–270 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#261
post #198
post #191

Earlier quoted context omitted.

>>> she turned on wifi calling on her phone. now she could receive SMS messages from friends and family, but 2FA codes still weren't coming through. Completely different beasts. One is P2P, the other is A2P

I was under the impression WiFi Calling was just regular phone service through WiFi. It seems to work that way for me, 2FA codes and all.

VoWiFi (as Wi-Fi calling is called in the 3GPP specs) is similar to VoLTE, but not all SMS go over VoLTE: Unlike for calls, where there's mandatory VoIP in 4G/LTE and beyond (there is no more circuit switching), there's still a fallback path for SMS that uses legacy signalling instead of IMS (which powers VoWiFi and VoLTE/VoNR).

Maybe there are some SMS gateways that are somehow incompatible with some IMS message gateways? (Theoretically, the IM-SM-GW should be transparent to external networks, I believe, but practically I wouldn't be surprised if some weird things lurked in there, requiring a fallback to the signalling path, which is not available on VoWiFi.)

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#262

Earlier quoted context omitted.

>I could not use my Google Voice number (that I've had since Grand Central) for most companies that only do SMS 2FA until it became my Google Fi number. Then I guess some flag got set in the database they check against. I was wondering about that, because I can't get google voice because I have google fi, so clearly it's using the same bank of numbers, but maybe once they are fi, they are ported to T-mobile instead o…

They removed that restriction. You can have Fi and Voice on the same account now.

Yeah, I think that restriction was due to that extremely strange way of using Hangouts (remember that?) as a possible backend for both Google Voice and Google Fi text messages.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#264
post #121

Sounds like discrimination of a broad group of people. Granted, it's not a designated protected group, like by national origin, but I still think they have a good chance in court.

> but I still think they have a good chance in court. On what grounds?

Discrimination by making banking harder for a specific group of people (living in mountains).

They could accept other 2FA methods, like passkeys and OTP apps, which are more secure than SMS.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#265
post #108

Earlier quoted context omitted.

> Apple's satellite messaging service is the only solution I know of that can somehow hook into carriers' SMS home router Are you sure it actually does this? I thought it was a pseudo-carrier that could speak MAP / Diameter, and just pretended you were roaming with them when you used satellite connectivity, perhaps with the original carrier's knowledge and consent. As far as I understand, that's how this kind of serv…

I assumed that that's how it works because I couldn't think of any other way to achieve the observed behavior, but pseudo roaming sounds plausible too, and presumably requires much less work on the carriers' side! Would that approach also allow the extra functionality they seem to be offering, such as only recently messaged numbers and emergency contacts being able to send messages to satellite users, though? I suppo…

> Do you have any other examples for solutions like this

I have a vague recollection that Pebble had something like this to get texts on the Pebble watch.

> Would that approach also allow the extra functionality they seem to be offering, such as only recently messaged numbers and emergency contacts being able to send messages to satellite users, though?

Hmm, you could definitely do this with a "Stripe-like" approach, where the actual traffic goes over the usual protocols to ease implementation, but the carriers provide Apple an API to query messaging history in some way (which they probably already offer in their apps, and so have good integrations for anyway).

Stripe uses this pattern for fraud detection. Their card transactions still go over the antiquated ISO protocols from the 80's, because that's just what everybody integrates with and agrees on, but they can also speak a custom API directly with participating banks, mostly for better fraud detection and fraud-related information sharing.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#266
post #237

Earlier quoted context omitted.

> SMS is the only 2FA method that can be easily deployed at scale No, no, no, no, NO. No it's not. And you have zero proof of this. Its done this way because its the lowest effort to give security theater.

What's the theater with sms 2fa? That is more secure than not having it enabled no?

Possibly less secure, considering the existence of sim-cloning crime rings. SMS 2-factor potentially gives a hostile actor a way to 'prove' that they're you.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#267

Earlier quoted context omitted.

It's absolutely not discrimination and you're harming people by making such an absurd claim. Unreliable SMS delivery is not discrimination. This is how things end up on Fox News: "Is website security now discrimination?" > I still think they have a good chance in court Can you share the law you think was violated?

People love to eagerly advise litigation while remaining ignorant that a five-figure retainer is required to even get started on such a process. And in the end, it's still a gamble that you may lose your case.

Yep, but in this case lawyer might try to make it a class-action lawsuit and work for a percentage. Up to the attorney, of course, if they are will to risk their time on that.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#268

Sounds like discrimination of a broad group of people. Granted, it's not a designated protected group, like by national origin, but I still think they have a good chance in court.

It's absolutely not discrimination and you're harming people by making such an absurd claim. Unreliable SMS delivery is not discrimination. This is how things end up on Fox News: "Is website security now discrimination?" > I still think they have a good chance in court Can you share the law you think was violated?

I'm not sure where "absolutely" comes from. I'm not an attorney to make assured statements, I can only guess.

I'm not talking about unreliable SMS delivery, I'm talking about banks not accepting other options like passkeys, software/hardware OTP keys which are more secure than SMS, thereby discriminating a whole class of people "living in the mountains".

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#269

She just needs a microcell/femtocell. Talk to your provider, explain to them you get poor service at your home or place of work, and they'll send you a free Internet-in cellular-out radio AP. She doesn't need a tower-based booster if she's got fiber/cable/DSL, those only serve to amplify weak signals and she's too many miles and too many mountain ridges away from the nearest tower, she wants something with RJ-45 inpu…

I have a 4G LTE Network Extender provided free by Verizon. My only issue is calls drop as I leave my property.

I called 911 in January and gave my address before the call dropped as I moved my car from my driveway to the street. The 911 operator called me back once I was back in range.

A few months later Verizon asked me to edit the location data with my address. Hopefully, I won't need to test anytime soon.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#270
post #221

Something somewhere is always hostile to particular group. That's just facts of life. You do your best to minimize but can never eliminate it. As someone who has dealt with 2FA support, all the methods suck. SMS 2FA is least secure but has broadest support with quickest recovery method. TOTP Applications (Google Auth, Authy, iOS Passwords) is more secure but people switch phones, lose phones and so forth and recovery…

> Privacy Advocates would lose their minds Privacy of authentication may be a valid concern (e.g. during voting), but I don't see how it applies here. If what I want is to confirm to the bank that I am who I am, with all the details about me that I have told the bank already anyway, I very clearly and openly forfeit my privacy. I explicitly ask to be precisely identified.

For banks an other cases that (1) need to know you true identity, and (2) provide no expectation of privacy regarding sharing the existence of accounts with the government, a government run authentication would be fine from a privacy point of view.

The issue is that every site has moved to using 2FA, and most of them have no legitimate need to know your true identity. So using a government ID based solution would unnecessarily conflate authentication and identification and would be a real privacy concern.

Post reply on HN