Live data from Hacker News

Tell HN: SMS-based two-factor authentication is not secure

news.ycombinator.com

281–290 of 291 posts

Re: Tell HN: SMS-based two-factor authentication is not secure

#281

As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to ba…

We have something vaguely similar with "BankID" in Norway. It's a bank issued digital ID that submits a 2FA to your phone (not through SMS, but through some other system that takes over the whole screen - not sure what it is). It's usable for almost all government agencies or official stuff online here, but I haven't seen anyone use it for third party auth as it costs roughly 10 cents per login for the service using…

>not through SMS, but through some other system that takes over the whole screen - not sure what it is

This sounds like it might be a so-called “flash” SMS. https://en.wikipedia.org/wiki/SMS#Flash_SMS

Re: Tell HN: SMS-based two-factor authentication is not secure

#283
post #278

Earlier quoted context omitted.

I have received advice from way to many people to not use your password manager as a 2nd factor be ause 1) It's actually become the only point if failure (your pw getting hacked). 2) Both factors protected and saved on the same spot

Mostly fear-mongering. 1Password in particular encrypts your vault with your master password and importantly an additional 128 bit secret key that is meant to be kept somewhere physically (e.g. in your safe). This key is needed the first time your vault is decrypted (e.g. a new device) An attacker would need to have access to all of the following: a) your encrypted vault b) your master password c) an 128-bit secret k…

Since your own computer will typically have the vault unlocked, you don't need a+b+c. You can suffice with a circa 2000s Sony Music cd. Or any driveby malware, or malvertisement, etc.

Using the 2nd factor on another device as the first means attackers need to either compromise 2 devices, or compromise a single point higher up in the hierarchy (e.g., your google account).

Re: Tell HN: SMS-based two-factor authentication is not secure

#284
post #231

Earlier quoted context omitted.

> As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling Uh... what does (in)secure mean to you?

exactly. "its not that the lock is insecure, its just that sometimes thieves figure out how to make keys."

What I mean is that if thieves can defeat the lock on my door, it doesn’t mean my door lock is worthless. I still lock my door but I don’t rely on it exclusively for protection.

Re: Tell HN: SMS-based two-factor authentication is not secure

#285
post #283
post #278

Earlier quoted context omitted.

Mostly fear-mongering. 1Password in particular encrypts your vault with your master password and importantly an additional 128 bit secret key that is meant to be kept somewhere physically (e.g. in your safe). This key is needed the first time your vault is decrypted (e.g. a new device) An attacker would need to have access to all of the following: a) your encrypted vault b) your master password c) an 128-bit secret k…

Since your own computer will typically have the vault unlocked, you don't need a+b+c. You can suffice with a circa 2000s Sony Music cd. Or any driveby malware, or malvertisement, etc. Using the 2nd factor on another device as the first means attackers need to either compromise 2 devices, or compromise a single point higher up in the hierarchy (e.g., your google account).

Now we’re talking extremes!

If there’s malware on your PC that has complete access to your system memory you are screwed in every single way possible. I’m perfectly comfortable with having my OTP coupled with my passwords given this is the only real attack vector and requires an actively unlocked vault to expose secrets.

If this is the case, what’s stopping the malware from adding a key logger and MITMing your input to your bank’s website, Gmail or Coinbase?

Re: Tell HN: SMS-based two-factor authentication is not secure

#287
post #99

Earlier quoted context omitted.

I'd start with VOIP numbers being so easy to spoof... and move onto the entire telephone network being insanely insecure and unverified, despite decades of efforts to link people to telnos -- until they implement actual caller-recipient full verification, they've effectively got nothing.

> until they implement actual caller-recipient full verification Is it even possible to do this at this point? I'd expect something like this to fundamentally change the way telephone networks work.

Not sure how fundamental it is, e.g., is it fundamental to bar ad-hoc caller-ID functions and require displaying the actual number & name of the account (maybe allowing additional info also)? Telcos already pass on this info - how big a deal is it to transmit accurate data?

But even if it is fundamental, such fundamental change is needed.

Re: Tell HN: SMS-based two-factor authentication is not secure

#288
post #287

Earlier quoted context omitted.

> until they implement actual caller-recipient full verification Is it even possible to do this at this point? I'd expect something like this to fundamentally change the way telephone networks work.

Not sure how fundamental it is, e.g., is it fundamental to bar ad-hoc caller-ID functions and require displaying the actual number & name of the account (maybe allowing additional info also)? Telcos already pass on this info - how big a deal is it to transmit accurate data? But even if it is fundamental, such fundamental change is needed.

Part of the problem I believe is a great many people (even the telcos) view voice calls as a dead technology on it’s last legs. Almost no one wants to invest in it, and even fewer technical people want to build a career on figuring these issues out.

If regulators and the industry saw a future in figuring this out (as compared to dealing with another hassle from a unsexy legacy technology mostly used by old folks), it would have been solved a long time ago.

Re: Tell HN: SMS-based two-factor authentication is not secure

#289
post #246

Earlier quoted context omitted.

+1 for Authy. Just get a used cheap Android phone for like $30 and use it as the backup device for Authy and never fear about losing your 2FA device again.

Does Authy actually offer 2FA? It sounds like the security boils down to your encryption passcode used to encrypt the 2FA secret, so you aren't actually using 2FA at the end of the day. For personal use it probably is a good compromise for services which don't implement 2FA properly (that is to say, services that don't allow you to register multiple 2FA devices.) But realistically you might want to just disable 2FA a…

> Does Authy actually offer 2FA

I'm not sure what you meant by this, Authy certainly provides TOTP, and the encryption password is only used when you need to sync the 2FA secret to other devices, which by the way also requires confirmation using SMS to your phone number as well.

Re: Tell HN: SMS-based two-factor authentication is not secure

#290
post #289

Earlier quoted context omitted.

Does Authy actually offer 2FA? It sounds like the security boils down to your encryption passcode used to encrypt the 2FA secret, so you aren't actually using 2FA at the end of the day. For personal use it probably is a good compromise for services which don't implement 2FA properly (that is to say, services that don't allow you to register multiple 2FA devices.) But realistically you might want to just disable 2FA a…

> Does Authy actually offer 2FA I'm not sure what you meant by this, Authy certainly provides TOTP, and the encryption password is only used when you need to sync the 2FA secret to other devices, which by the way also requires confirmation using SMS to your phone number as well.

I usually take 2FA to mean that you have to use two of (something you have, something you know, or something you are.) If the "2FA secret" (TOTP secret?) is stored on multiple devices it doesn't actually prove ownership of "something you have" it's effectively no different from a password stored within a password manager which is considered simply "something you know." So basically the TOTP secret is a second password with some obfuscation that protects the password. But software running on one of your devices could easily steal the secret.

It does seem like this is somewhat more secure, in some sense, but it weakens the security that TOTP is intended to provide.

Post reply on HN