Earlier quoted context omitted.
>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…
Anon SIM cards are still allowed in some EU countries: https://prepaid-data-sim-card.fandom.com/wiki/Registration_P...
SMS 2FA is not just insecure, it's also hostile to mountain people
281–290 of 328 posts
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#282Earlier quoted context omitted.
Ironically, this is only true for prepaid SIMs. As a result, in some EU countries it's easier to get a month-by-month postpaid plan – sometimes there's no KYC at all for these...
When did this change happen? I’ve done local SIM prepaid all over Europe over the past decade, but not so much recently
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#283People who perpetrate SMS 2FA are pure scum.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#284Earlier quoted context omitted.
>>> I really wish that were illegal. A phone number is a phone number. European speaking. For completeness: Financial directive PSD2[1] allows to use an SMS as a 2FA only because there is an KYC already done for that number (anon SIM are no longer allowed in the EU) Also note that the 2FA is not the OTP code you receive. This code is just a proxy for probing "something you have", with the "something" being the phone…
> anon SIM are no longer allowed in the EU Surely Ireland still allows them? If not, they're trivial to source from NI.
I had a SIM from three Ireland that tried to apply this UK policy also on the republic of Ireland customers where this is not required. It was unusable, it blocked pretty much everything it didn't recognise like VPNs, even email servers. Luckily there's many sane providers there too. And no they don't require registration.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#285> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…
> Interesting, I was under the impression that SMS over IMS was implemented transparently to external senders. But given what a hack the entire protocol is, I'm not really surprised. I can probably illuminate some things here. This is almost certainly the SMS API they're using. Your phone, and your network by extension, does not care if the phone is technically online - so those messages get received because they're…
I've been used to unlimited free SMS for so long now (though I remember the days when it was limited), I forgot that commercial customers get charged for these
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#286Earlier quoted context omitted.
I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.
This is probably compliance-related. For me, TOTP isn’t “something I have”, it’s another thing I toss into my password manager and sync to all devices. I really agree with it, but that’s probably their rationale.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#287Something somewhere is always hostile to particular group. That's just facts of life. You do your best to minimize but can never eliminate it. As someone who has dealt with 2FA support, all the methods suck. SMS 2FA is least secure but has broadest support with quickest recovery method. TOTP Applications (Google Auth, Authy, iOS Passwords) is more secure but people switch phones, lose phones and so forth and recovery…
Nah I am good thanks.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#288Something somewhere is always hostile to particular group. That's just facts of life. You do your best to minimize but can never eliminate it. As someone who has dealt with 2FA support, all the methods suck. SMS 2FA is least secure but has broadest support with quickest recovery method. TOTP Applications (Google Auth, Authy, iOS Passwords) is more secure but people switch phones, lose phones and so forth and recovery…
> Yubikey and like have cost problem and you still have recovery problem. Recovery is relatively straightforward if you have more than one key. You enroll all your keys, and if you lose one, you buy a new key and use one of the other keys to enroll it.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#289Earlier quoted context omitted.
1) It's possible they do not have an Internet connection. In fact, it doesn't seem necessary. 2) Bluetooth can ensure that you are in proximity of the locker, otherwise you could accidentally unlock a locker while standing at the wrong rack.
They always had internet access. Of course it is possible that they decided to rip out the internet connection in the new models together with the touch screen, but I heavily doubt that they want to trust the internet connection of a random stranger to do whatever important communication they have to do with their servers. The app only requires internet access because... well, it always needs internet access.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#290I'm not sold yet on non-portable, proprietary passkeys.