Live data from Hacker News

Security Analysis of SMS as a Second Factor of Authentication

queue.acm.org

31–35 of 35 posts

Re: Security Analysis of SMS as a Second Factor of Authentication

#31
post #18

Earlier quoted context omitted.

>2. in unionized environments what is meant by "unionized" here? It doesn't seem to be related to labor unions.

Specifically, in unionized environments introducing new technologies and methods no matter how seemingly trivial creates an obligation for formal job training. Setting up an hour of training for 5k+ people on how to install and use Auth0 is way more expensive than just sending someone an SMS. There is no implicit responsibility to adapt to change. If an employer wants employees in a bargaining unit to use their own m…

That's too broad a generalization. I am aware of unionized environments where the employer uses MFA and expects the employee to bring their own device, and the user is expected to read the online KB documentation in lieu of formal training.

tl;dr -- unions aren't all alike, and don't all bargain over the same issues.

Re: Security Analysis of SMS as a Second Factor of Authentication

#32
The worst thing about SMS authentication in terms of UX is what happens when you're outside your country. I moved countries recently, but I still need to do things like retrieve tax statements etc. Some companies only support SMS as a second tier authentication method (some at least allow you to use email as an alternative), some won't allow you to change to a foreign number, some will not be able to send you a text if you're in roaming mode abroad (I keep my old SIM active just for that).

Re: Security Analysis of SMS as a Second Factor of Authentication

#33

SMS 2FA is weak, but it does two things: it shifts the attack from a passive opportunistic one to a targeted one, and, 2. in unionized environments you can add a second compliance factor without distributing new devices, "training" people to use TOTP apps, or "forcing" people to install an app on their personal devices. That is the big cultural reason why SMS 2FA is going to be with us for a while. Sure, use TOTP and…

> it shifts the attack from a passive opportunistic one to a targeted one

This isn't true. You can bulk phish SMS, TOTP and the push confirmation stuff. Software to do this isn't theoretical you can just download it ready to use, because in each case you only need to fool a human into believing this is really their bank/ web mail/ government/ etc.

If you want to get rid of the opportunistic stuff you need technology like WebAuthn that makes it simply not work.

Re: Security Analysis of SMS as a Second Factor of Authentication

#34

I think the worst is when companies force you to leave SMS on as a fallback. On stripe, I use a security key. Someone has to either steal my keyring, or steal my backup key. But I'm force to leave SMS on as a fallback, so really, the weakest link is there, and a potential cracker only needs to break this extremely fragile insecure system, and completely bypass the security key.

Even worse is when companies force you to use SMS as the first and sufficient authentication factor. EDF (the biggest European electricity provider) does that in France.

Re: Security Analysis of SMS as a Second Factor of Authentication

#35
post #18

Earlier quoted context omitted.

>2. in unionized environments what is meant by "unionized" here? It doesn't seem to be related to labor unions.

Specifically, in unionized environments introducing new technologies and methods no matter how seemingly trivial creates an obligation for formal job training. Setting up an hour of training for 5k+ people on how to install and use Auth0 is way more expensive than just sending someone an SMS. There is no implicit responsibility to adapt to change. If an employer wants employees in a bargaining unit to use their own m…

I am not sure which countries you relate to, but requiring pepole in France to use their private phone for work is simply impossible.
Post reply on HN