Live data from Hacker News

Let's Ban SMS 2FA

lorendb.dev

31–40 of 46 posts

Re: Let's Ban SMS 2FA

#31
The author seems to assume that security is (or should be) the only consideration in implementing 2FA. When in practice, practicality and convenience are part of the equation as well. While imperfect, SMS 2FA significantly improves security while also remaining convenient.

Instead of suggesting that we put in place legislation banning it (?!), perhaps the author should come up with an alternative solution that provides improved security with the same or better convenience for end users and the organizations using it.

Re: Let's Ban SMS 2FA

#32
post #21

Earlier quoted context omitted.

>When the barrier to adoption and inconvenience to the user is so low Is it low though? I'm not sure my parents could figure out how to use an authenticator app.

Then your Patents should not be near any account that should reasonably require 2FA. They are perfect prey for scammers.

[deleted]

Re: Let's Ban SMS 2FA

#33
The author has a few assumptions that I think are incorrect.

Not all accounts need the same level of security or protection. SMS 2FA can be a very reasonable option depending on the accounts. No law can make that kind of a decision in a reasonable way. So the law has to be toothless (if it leaves too much leeway) or it will remove a valid option from people.

The usability and the availability of other 2FA are not on par with SMS. The gap is not trivial as the author makes it sound like. Account recovery problem is a very difficult one to fix cleanly for all types of accounts. SMS is still a useful option.

Sim swap attack is multiple orders of magnitude more difficult than credential stuffing. It's not close to the most important attack vector for majority of people. It certainly is not worth legislating a solution for specifically. There are reasonable practical solutions for people who want protection against SMS as 2fa from sim hijacking - e.g. many cell phone providers support 2fa or pin to protect it from the sim attack in most scenarios. It's a much cheaper solution for the society than banning SMS 2fa.

Re: Let's Ban SMS 2FA

#34
> adding TOTP support is going to be fairly trivial ... This does require the user to install a TOTP app

You just lost 30% of your customers.

> It isn’t that hard to fix

You're highly underestimating the immense difficulty of convincing the entire human population to do something that engineers consider trivial.

Re: Let's Ban SMS 2FA

#35
post #5

Earlier quoted context omitted.

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

>When the barrier to adoption and inconvenience to the user is so low Is it low though? I'm not sure my parents could figure out how to use an authenticator app.

Really though? I get maybe being confused the first time they used it, but you really think they couldn't figure it out?

An authenticator app just has the codes and the sites. SMS has the codes, all the previous codes, all of your other SMSs. Plus the messages come from a 5 digit phone number that has a similar format to the 6-digit code you're supposed to enter. The whole system is byzantine IMO and the authenticator app has a much simpler flow. But, you know, I recognize that not everyone may experience it the same way.

I'm generally curious if people think there's a simplicity to the SMS approach other than just familiarity with something that's awkward.

The real problem IMO is not that it's hard to use an authenticator app, it's that the authenticator app provides an actual secret. There's less of a backdoor, so customers can lock themselves out. The downside of the backdoor is it's a security risk. The upside is that managing private keys is a nightmare and nobody wants to force their customers to actually manage private keys.

Re: Let's Ban SMS 2FA

#36
post #5

So the case against SMS 2FA boils down to “There are two factors, but the second factor is something a determined actor can get around by SIM swapping.” But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people. This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be…

Author here - yes, I agree that SMS 2FA is much better than nothing, but let's be honest, implementing and using actually secure 2FA is a lot easier than installing a vault door on your home. When the barrier to adoption and inconvenience to the user is so low, there's no reason to not adopt better 2FA methods.

> much better than nothing

If you wouldn't advocate banning deadbolt locks just because vault doors are better, why advocate banning SMS 2FA?

Re: Let's Ban SMS 2FA

#37
post #28

My only other experience with 2FA flows other than SMS are the "Auth" apps that generate passkeys like authy or google authenticator. But more than once, I've updated my phone, or had to reset it, or switched phones, and been locked out of a service. In my experience, there's usually no automated flow to recover from those situations, and I've been forced to resort to opening a support ticket to reset my account pass…

This is the most annoying thing about 2FA apps. I once dropped my phone and broke it. It wasn't in a repairable state. Lost access to multiple accounts due to losing 2FA apps. Sometimes, I think security people make them unnecessarily complex just for the sake of it. Not all services need 2FA. And SMS is fine for most of the things.

Re: Let's Ban SMS 2FA

#38
So why is it not easy to go to bank and take someone else's money? What makes phone companies special? This, plus the universal support for spoofing caller-id looks like intentional support of organised crime. How do phone companies get away with it?

Re: Let's Ban SMS 2FA

#39
Honestly?

Let's ban mobile/proprietary devices and related apps, soft-token included. We have smartcards since decades, we have physical OTP tokens, there is no reasons to allow someone else spying on intrinsically insecure platforms for logins.

Re: Let's Ban SMS 2FA

#40
The world needs identity verification as a service. By this, I mean it should be possible to go to an office of ID Check inc, show ID and prove who i am. The id vetting company can then give you a number that you can give to a company to prove you are the person you claim to be and have your password reset.

The current system of having access to a SIM card or knowing your mother’s maiden name is ridiculous.

Post reply on HN