Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

271–280 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#271
post #190

Earlier quoted context omitted.

>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…

> SMS is the only 2FA method that can be easily deployed at scale No, no, no, no, NO. No it's not. And you have zero proof of this. Its done this way because its the lowest effort to give security theater.

What's the actual method that can be easily deployed at scale then?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#272

Earlier quoted context omitted.

> Carriers would probably hate this and might not be willing to sign roaming agreements with such a company. This is THE problem with your idea. Congress would have to pass a law forcing them to do it, or they won't. You'd probably have more luck physically keeping someone's SIM card, keeping it installed in a phone, and watching for new texts. Perhaps you could make a box that simulates 10 phones at once.

> congress would have to pass a law forcing them to do it Well, I'm not so sure about that. SS7 redirection attacks exist, so clearly shenanigans like these are very hard to stop for carriers. The question here is whether such "attacks" are legal if performed with the consent of the customer, but against the wishes of their carrier. One could also do some "legal optimization" here, and ally themselves with a major ca…

"SS7 redirection attacks" means, more concretely, "hacking into some phone company that's connected to the one you want to redirect, and using that system to send false data to the one you want to redirect".

It's BGP hijacking but for the phone system. If Comcast is connected to Verizon, and I want to hack your connection to Google, and you're on Verizon, one of my options is to hack Comcast and have Comcast tell Verizon that Comcast has a really fast connection to Google. It might let me intercept your traffic if circumstances are good; it's also fraudulent and illegal through and through. If caught, I will go straight to federal prison.

(Of course the analogy isn't 100%. The set of things you can do by hacking one side of a SS7 link is not identical to the set of things you can do by hacking one side of a BGP link - in particular, there's no BGP roaming. But it's a similar principle.)

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#273

Earlier quoted context omitted.

A lot of US carriers charge per SMS when roaming (as if it were 2006).

Sure but with 2FA you only recieve SMS so so what?

Some plans in the US charge the recipient of an SMS.

That is unheard of in Europe, so makes no sense to you - hence the confusion.

It's also often the case that prepaid plans or smaller carriers in the USA don't offer international roaming.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#274

Can we just go back to having passwords please. I hate this state of authentication on the web.

Passwords are terrible. They're Human Memorable Shared Secrets, it's "What if somebody who doesn't know the first thing about cryptography tried to invent secure authentication?" and should have died out last century yet here we are. We have known for decades how to do better than that. The fact that at least twice a month (often much more) I read an HN comment saying passwords are great is like discovering most of y…

Oh and passwords don't require you to link your identity to every single service you use online

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#275
This is a niche article, where it reads as though the SMS 2FA messages started coming through right as the lady purchased a cell service. Well the lady would have needed to have activated 2FA first and walked away from the house to even enable it.

Then goes on to say that TOPT is also too difficult, firstly because you have to download an app to do it, yet she supposedly knows how to use her phone.

There will always be edge cases where something doesn't work perfectly the way it does for everyone else. The solution here seems to be help her choose a TOPT app, print out those backup codes and be done with it.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#276
post #231
post #195

Earlier quoted context omitted.

> anon SIM are no longer allowed in the EU Ah. That explains why they asked for my life history when I tried to buy a local SIM in Italy.

Ironically, this is only true for prepaid SIMs. As a result, in some EU countries it's easier to get a month-by-month postpaid plan – sometimes there's no KYC at all for these...

When did this change happen? I’ve done local SIM prepaid all over Europe over the past decade, but not so much recently

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#277
post #270
post #221

Earlier quoted context omitted.

> Privacy Advocates would lose their minds Privacy of authentication may be a valid concern (e.g. during voting), but I don't see how it applies here. If what I want is to confirm to the bank that I am who I am, with all the details about me that I have told the bank already anyway, I very clearly and openly forfeit my privacy. I explicitly ask to be precisely identified.

For banks an other cases that (1) need to know you true identity, and (2) provide no expectation of privacy regarding sharing the existence of accounts with the government, a government run authentication would be fine from a privacy point of view. The issue is that every site has moved to using 2FA, and most of them have no legitimate need to know your true identity. So using a government ID based solution would unn…

Can you offer an example of a situation when the second factor authentifies without identification?

Assume a service S wants a confirmation that user U is indeed legitimate. The centralized auth service A could receive from S a bunch of data S knows about U, like name, address, phone, SSN, whatever S needs to know about U. Then A should respond whether the fields match the data which A knows about U, without revealing to S any additional data that A may know about U.

The problem if a centralized service is that it's a SPOF, and the juiciest target for compromising.

I still think that TOTP and personal crypto tokens like yubikey are the most resilient, and technically the easiest, solution to that.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#278

Earlier quoted context omitted.

Passwords are terrible. They're Human Memorable Shared Secrets, it's "What if somebody who doesn't know the first thing about cryptography tried to invent secure authentication?" and should have died out last century yet here we are. We have known for decades how to do better than that. The fact that at least twice a month (often much more) I read an HN comment saying passwords are great is like discovering most of y…

Oh and passwords don't require you to link your identity to every single service you use online

"This terrible idea could actually be worse" is about the level I've come to expect. Congratulations, passwords haven't managed to be worse in every way than every possible alternative, mostly, yet.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#279
post #5

Google Fi can receive all SMS 2 factor messages on Wi-Fi including short codes. It doesn't even require that your phone is on, you can get them in any web browser on any device even if your phone is destroyed. One of my favorite features. You can get service starting at $20 per month. Fi used to have good service in some mountain areas too, with US Cellular. Not sure what's going on with US Cellular right now though.…

Google Fi charges $10 PER 1GB of data. US Mobile is cheaper and offers the top 3 providers in the US.
Post reply on HN