Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

321–323 of 323 posts

Re: Second factor SMS: Worse than its reputation

#321
post #318

Earlier quoted context omitted.

Most large banks already largely offer non-SMS 2FA through their companion mobile apps. This is about pretty much every other service you have that does not have a dedicated mobile app and doesn't want to teach their users how to manage your 2FA codes.

The problem with the above statement is that merely “offering” a better option doesn’t solve the issue. The mere presence of SMS as one option gives the same risk as if it were SMS- only. An attacker can choose the sms option (after slipping $100 or even just a fake ID to the teen at the phone store to sim-swap you) even if you never would use it. It needs to be at minimum able to be permanently disabled on demand.

Offering it as an option does not necessarily mean allowing both sms and non sms options simultaneously.

Re: Second factor SMS: Worse than its reputation

#322
post #318

Earlier quoted context omitted.

The problem with the above statement is that merely “offering” a better option doesn’t solve the issue. The mere presence of SMS as one option gives the same risk as if it were SMS- only. An attacker can choose the sms option (after slipping $100 or even just a fake ID to the teen at the phone store to sim-swap you) even if you never would use it. It needs to be at minimum able to be permanently disabled on demand.

Offering it as an option does not necessarily mean allowing both sms and non sms options simultaneously.

I suppose, but in practice nearly all systems I’ve seen allow the attacker to opt for SMS, on demand, unless you’ve been allowed to not put in a phone number on file. Which is not always the case.

Re: Second factor SMS: Worse than its reputation

#323
post #320
post #224

Earlier quoted context omitted.

I preferred the blinky bars; the reader for them is tiny, not locked to an account, battery lasts what feels like forever, and they're cheap enough that you can trivially eat a loss (from forgetting where it is or leaving it in a place where it disappears before you get a chance to collect it). Maybe just stick an airtag to the back?

The blinky bars were great! Already forgot about those. If I remember correctly, a problem with those were people with displays that had funky refresh rates? I think that in the current era that would be much less of a concern. Conceptually it's great to have an actual physical, airgapped device under your full control as your signing device.

You can just press on "slower" to fix that issue. Though really you should probably figure out how to get a decent refresh rate from your screen.

Also, it's not like they're gone, they're still going strong.

Post reply on HN