Live data from Hacker News

How SMS fraud works and how to guard against it

apuchitnis.substack.com

31–40 of 107 posts

Re: How SMS fraud works and how to guard against it

#31
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone

Yeah that's the problem - TOTP with a basic app is pretty easy to use, but making sure you're protected from a phone suddenly lost or broken scenario is tougher, and you may not know you need to do it until it's too late. How many people actually store those backup codes properly or go to the trouble to use a third-party app that supports backups and actually do backups?

Re: How SMS fraud works and how to guard against it

#32
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

People lose their phones and then your authenticator app doesn't work anymore, even if you restore from backup. And then the recovery mechanism is often a giant pain.

Yes, that's pretty user unfriendly.

It's a lot more common to lose your phone than lose your phone number.

Re: How SMS fraud works and how to guard against it

#33
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

People lose their phones and then your authenticator app doesn't work anymore, even if you restore from backup. And then the recovery mechanism is often a giant pain. Yes, that's pretty user unfriendly. It's a lot more common to lose your phone than lose your phone number.

There are numerous tools, Google Authenticator and Authy for example, that protect against this by securely storing the keys. In fact, I would venture to say that MOST users of authentication apps are using ones that provide a backup in case the phone is lost.

Re: How SMS fraud works and how to guard against it

#35

Earlier quoted context omitted.

I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.

Only downside is the verizon rep giving your sim to someone who deepfaked your voice.

Or the T-Mobile rep doing the same for someone who asked nicely with whatever voice and knew a couple relatively-easy-to-find details about you

Re: How SMS fraud works and how to guard against it

#36
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.

Obviously custom non-TOTP authenticators are dumb and not much better than SMS 2FA. I was mainly asking why anyone would opt for SMS (or a custom authenticator app) over just a TOTP authenticator.

Re: How SMS fraud works and how to guard against it

#37
post #25
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

Because lots of us upgrade phones every couple years, or have dropped a phone and had it break, or get water in it or something. It's all too easy to realize after the fact you needed to transfer something between the old phone to the new phone to keep the authenticator working. Sometimes that's not available (phone damaged), or don't realize you need it until after you've already sent the phone in for trade in. So y…

> Because lots of us upgrade phones every couple years, or have dropped a phone and had it break, or get water in it or something.

This is just a matter of using one of the many TOTP authenticators which allow backups of the keys.

If people drop or lose their phones, do they lose all their contacts, photos, passwords? I bet not. I am pretty sure this is a solved problem by now.

Moreover, even if you do lose the keys, that's what account recovery processes are for.

Re: How SMS fraud works and how to guard against it

#38
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone

Wouldn't most people just use Google Authenticator and have it automagically back up to google's nigh unlimited storage space?

Obviously not something anyone who respects their privacy would subject themselves to, but it seems to me like the easy path leads to these things being backed up.

Obviously if google has your 2FA keys and you were using 2FA keys to log into your google account then you would need to recover your account, but you would be stuck in the same situation as if you had damaged/lost your SIM (e.g. if you lose your phone).

Re: How SMS fraud works and how to guard against it

#39
I feel like the easiest workaround is to a) not use an email with your name in it for any important login b) don't use those emails for more than one service c) use a separate SIM and device for 2FA (mint mobile etc) / banking apps that aren't up to speed with non SMS 2fa.

It pains me to say this since Bank of America sucks, but their system now supports adding a Yubikey for login, nearly as good as Schwab before they stopped issuing physical TOTP tokens in 2020.

Re: How SMS fraud works and how to guard against it

#40
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone

Just store backup codes, using a 2FA app like authy which can be swapped via SMS defeats the entire point of using 2FA authenticators in lieu of SMS.
Post reply on HN