Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

291–300 of 323 posts

Re: Second factor SMS: Worse than its reputation

#291
post #283
post #134

Earlier quoted context omitted.

Was this in the US or elsewhere, what was the amount and how long did it take to notice? Just curious. In the US the bar to pull money out of an account is pretty low. Most banks would allow reasonably-sized transfers out with just routing and account numbers. I was stunned by this, but this is the reason utilities and stores can pull your money without you even talking to your bank. Just give them the info. And that…

> Was this in the US or elsewhere, what was the amount and how long did it take to notice? Just curious. It was in Australia, amount was thousands of dollars, she noticed when she was asked to enter yet another code and all of a sudden it made her snap out of her "autopilot" and take notice and look at the URL and other details. So as soon as she realised that something was fishy, she logged into the correct site, th…

I understand the attack (I heard some high visibility telegram channels were recently compromised by a similar technique).

My point was that most bank transactions are actually reversible for a while after the money supposedly left the account.

Re: Second factor SMS: Worse than its reputation

#292

Earlier quoted context omitted.

It is very much software-world-thinking to believe that dismissive Kafkaesque responses that just shut down the conversation without addressing the fundamental issues around usability and customer satisfaction will ameliorate the situation. For a lot of service based businesses they see their customers face to face and it is imperative that the customers have a seamless experience. Imagine having a business where cus…

"We face this. It's about 5% of users. Our margins are large enough we don't worry about this segment. They need our service more than we need them." - Any Large Bank Anywhere

Most large banks already largely offer non-SMS 2FA through their companion mobile apps. This is about pretty much every other service you have that does not have a dedicated mobile app and doesn't want to teach their users how to manage your 2FA codes.

Re: Second factor SMS: Worse than its reputation

#293
post #162

Earlier quoted context omitted.

They are still third-party ad networks that require a browser to cross multiple domains, etc. etc. etc. I am not ideologically opposed to advertisements but I do believe the only safe ads are first party hosted coming from the same domain.

most people publishing a website either cannot or do not care to host the ad server on the same domain, they just want to monetize the site. things could get a lot better, but this self hosting suggestion in particular will never see wide adoption unless major hosting providers build it and host for their customers. most people don't even bother to self-host/bundle stuff like their fonts and JS libraries unless they…

Who said anything about an ad server ?

An ad is a particularly sized JPEG that you place in your images directories… and then point to with an HTML tag.

Everything we tried to build for you was lost once you deviated from that level of complexity.

Re: Second factor SMS: Worse than its reputation

#294

Earlier quoted context omitted.

There were ads on google.com since at least 2000[1]. Chrome wasn't announced until 2008. Disclosure: I work at Google but not on ads or Chrome. [1] https://googlepress.blogspot.com/2000/10/google-launches-sel...

I believe they meant on https://google.com (the home page)

Oh, I didn't think of that. But I don't think that's really true either. There seem to be ads on the homepage before Chrome:

Google News: https://web.archive.org/web/20021001073516/http://www.google...

Google Calendar: https://web.archive.org/web/20060831050142/http://www.google...

For comparison, Chrome: https://web.archive.org/web/20080904192205/http://www.google...

Now admittedly the Chrome one is a bit flashier. Although I haven't exhaustively gone through every homepage variant before Chrome, so it's possible there was something as flashy before Chrome as well.

Re: Second factor SMS: Worse than its reputation

#295

In the UK it seems that almost all online banking transactions are now verified by SMS. As far as I can tell this is required by law, and replaced the previous, bank card + card reader + pin verification system, which was not only more secure but also did not depend on having a working mobile phone with signal. I hope that this will in due course be recognised as a terrible mistake and rectified. Unfortunately my hop…

First line is not true at all. SMS is an option, but many support app based 2fa

Agree about the card reader being useful for offline. But I never remembered the thing and was often stuck when travelling

Re: Second factor SMS: Worse than its reputation

#296

I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…

The tools aren't the hard part. The hard parts are adoption and recovery. SMS has an extraordinary advantage in that the vast majority of people transparently have access to it. No need to download another app. No need to install anything. No need to buy a special usb device. It also has a recovery mechanism built in, as the carriers will all let you move your phone number to a new device. This, of course, comes with…

How I would loath to rely on Goole or Apple to be able to make payments or confirm other actions. Sure as hell they would call home about what actions I am performing, and associate that data with some Google account or Apple Id or so, that they will force me to have.

No thank you.

Re: Second factor SMS: Worse than its reputation

#297
post #66
post #43

Earlier quoted context omitted.

Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank

This might not be sufficient anymore. Many online payments are rendered either on the shop's pages or on a third party payment provider, including 3DSecure implementations. These don't redirect to any sensible bank URLs. Both of my banks use a payment flow which uses a hardware authenticator. But only one bank seems secure: it prompts for an amount and a reference and generates an OTP based on that. This is distinct…

[deleted]

Re: Second factor SMS: Worse than its reputation

#299

Earlier quoted context omitted.

The tools aren't the hard part. The hard parts are adoption and recovery. SMS has an extraordinary advantage in that the vast majority of people transparently have access to it. No need to download another app. No need to install anything. No need to buy a special usb device. It also has a recovery mechanism built in, as the carriers will all let you move your phone number to a new device. This, of course, comes with…

How I would loath to rely on Goole or Apple to be able to make payments or confirm other actions. Sure as hell they would call home about what actions I am performing, and associate that data with some Google account or Apple Id or so, that they will force me to have. No thank you.

That's fine. I don't think any individual is foolish for preferring to keep these companies out of the process.

But it is just undeniable at this point that any authentication system other than raw passwords must come from any already ubiquitous ecosystem that doesn't require people to download, install, or buy anything new. Hoping that yubikeys take off is fantasy.

Re: Second factor SMS: Worse than its reputation

#300
post #66
post #43

Earlier quoted context omitted.

Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank

This might not be sufficient anymore. Many online payments are rendered either on the shop's pages or on a third party payment provider, including 3DSecure implementations. These don't redirect to any sensible bank URLs. Both of my banks use a payment flow which uses a hardware authenticator. But only one bank seems secure: it prompts for an amount and a reference and generates an OTP based on that. This is distinct…

I ran into this. I'm trying to set up an account on wise.com. The way they want me to set up my bank for direct deposit is to type my banks password into their site! I asked support if there was any other way to do this (for example the regular institution, branch, account numbers) and they said no. But they reassured me that despite me typing the password into their site that they don't have access to it! (Ok, it was actually a Plaid iframe, but still not my bank. Clickjacking would also be very easy to implement and there is no way for the average user to understand this.)

Then banks wonder why their customers get phished.

Post reply on HN