Earlier quoted context omitted.
I'm currently developing firmware that supports both Bluetooth and cellular connection for a hardware device. With proper cryptography, you don't have to trust the random stranger (e.g. using TLS). In fact, you can get away with no connection at all. For example, when someone locks the locker, it sets a "password" via Bluetooth and when you open it, your phone simply transmits the "password" via Bluetooth.
I'm not just thinking of trust in terms of whether the device will tamper with the data, but also stuff like: What happens if you just put the parcel in the locker and in that exact moment the internet connection cuts out? Normally the parcel locker would send some data to DHL servers (as made evident by the fact that the lockers can send a confirmation mail), how do you get that information out now? Of course you co…
SMS 2FA is not just insecure, it's also hostile to mountain people
301–310 of 328 posts
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#302Earlier quoted context omitted.
I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?
GV still works on BOA to an extent: general balance queries through their app or the web will go through but anything involving identity and real transactions via wire or zelle will ask for your real mobile number. Even if you do happen to visit one of their branches they will ask for confirmation through your real mobile number (landlines will obviously not work).
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#303Earlier quoted context omitted.
Sure but with 2FA you only recieve SMS so so what?
Some plans in the US charge the recipient of an SMS. That is unheard of in Europe, so makes no sense to you - hence the confusion. It's also often the case that prepaid plans or smaller carriers in the USA don't offer international roaming.
So if I buy 10.000 SMS for cheap on Messagebird I can "denial of service" your phone bill?
What, lol?
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#304Earlier quoted context omitted.
>>> she turned on wifi calling on her phone. now she could receive SMS messages from friends and family, but 2FA codes still weren't coming through. Completely different beasts. One is P2P, the other is A2P
I was under the impression WiFi Calling was just regular phone service through WiFi. It seems to work that way for me, 2FA codes and all.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#305Earlier quoted context omitted.
Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.
> Homeless people get free smartphones and free service in the US Recently former homeless person here. The Republicans in Congress refused to renew the Lifeline program in 2023 and the replacement is objectively worse in every single way. > Not all choices need to be subsidized. Ah yes, being homeless, a choice. I hope it never happens to you.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#306Some of the comments pointed out that this is hostile behaviour for people roaming as well, and I completely agree. Here is my solution for this : When I am roaming internationally, I leave my SIM card in a spare android at home plugged into a charger. Android has an app that forwards SMS to API : https://f-droid.org/packages/tech.bogomolov.incomingsmsgatew... . Every time I receive a SMS I forward it to this API. Th…
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#307Earlier quoted context omitted.
For banks an other cases that (1) need to know you true identity, and (2) provide no expectation of privacy regarding sharing the existence of accounts with the government, a government run authentication would be fine from a privacy point of view. The issue is that every site has moved to using 2FA, and most of them have no legitimate need to know your true identity. So using a government ID based solution would unn…
Can you offer an example of a situation when the second factor authentifies without identification? Assume a service S wants a confirmation that user U is indeed legitimate. The centralized auth service A could receive from S a bunch of data S knows about U, like name, address, phone, SSN, whatever S needs to know about U. Then A should respond whether the fields match the data which A knows about U, without revealin…
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#308Something somewhere is always hostile to particular group. That's just facts of life. You do your best to minimize but can never eliminate it. As someone who has dealt with 2FA support, all the methods suck. SMS 2FA is least secure but has broadest support with quickest recovery method. TOTP Applications (Google Auth, Authy, iOS Passwords) is more secure but people switch phones, lose phones and so forth and recovery…
If you mean the government just replaces hardware and re-establishing access is up to me, that’s no different from Yubikey.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#309Earlier quoted context omitted.
It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.
I absolutely cannot stand that no bank I have (US) supports generic TOTP, which is more secure and easier to recover from backup if my phone is broken or stolen. It's inexcusable.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#310Earlier quoted context omitted.
It's absolutely not discrimination and you're harming people by making such an absurd claim. Unreliable SMS delivery is not discrimination. This is how things end up on Fox News: "Is website security now discrimination?" > I still think they have a good chance in court Can you share the law you think was violated?
I'm not sure where "absolutely" comes from. I'm not an attorney to make assured statements, I can only guess. I'm not talking about unreliable SMS delivery, I'm talking about banks not accepting other options like passkeys, software/hardware OTP keys which are more secure than SMS, thereby discriminating a whole class of people "living in the mountains".
> I'm not talking about unreliable SMS delivery
Why? That's what this is about. Everyone, including hill people, have the same problems with the same technology. Ergo, not discrimination.
> I'm talking about banks not accepting other options like passkeys, software/hardware OTP keys which are more secure than SMS
I'm going to sue Apple for not adding satellite to my iPhone. It's discrimination that when I go into the mountains, I don't have reliable coverage.
See how silly that is?
> I'm not an attorney
Then why are you confident about the outcome of court cases?