Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

321–328 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#321

Earlier quoted context omitted.

Doesn't this kind of defeat the purpose of MFA in that you now have both factors within the same application?

You don't actually need MFA. This whole thing came about because people reuse passwords between websites and websites have their databases hacked all the time so the same password can be used to log in on other sites. 2FA codes solve that because you can't reuse them between websites so one website getting hacked doesn't expose all of them.

You can easily reuse TOTP between websites, but not many websites let you set your own TOTP secret. They could easily do the same for passwords, but none do.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#322

Earlier quoted context omitted.

Oh and passwords don't require you to link your identity to every single service you use online

"This terrible idea could actually be worse" is about the level I've come to expect. Congratulations, passwords haven't managed to be worse in every way than every possible alternative, mostly, yet.

Thats a huge benefit. Dont you hate that every service requires you to give them your identity?

As I said most sites I dont even give a shit if my account gets hacked.

Do you think HN for example would be better off if they decided everyone now has to do 2FA?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#323
post #91

Earlier quoted context omitted.

I hate email 2FA because I purposely don't have email on my phone. Unless I'm in front of my computer, I'm unable to log in to websites that use email 2FA.

Have you considered installing an email client on your phone, but not giving it the credentials it would need to fetch mail from the mailboxes you don't want to be tempted to look at when away from a keyboard?

It's basically all one mailbox, but lots of forwards, so that wouldn't work. But my reasoning is not so much because I'd be tempted to look at email when AFK, but more for security: I don't want email to be accessible from my phone.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#324
post #97

Earlier quoted context omitted.

It seems t-Mobile no longer offers such hardware: https://www.t-mobile.com/support/coverage/4g-lte-cellspot-se...

Maybe T-Mobile doesn't need to. I've used their WiFi calling for, what, going on ten years probably. Works a treat, including getting short code SMS. Ergo, I don't know the use case for femtocell for T-Mobile. That's why I was surprised to learn via TFA that WiFi isn't the solution in all cases.

The use case is anywhere Wi-Fi and cell coverage is spotty or nonexistent. There are probably plenty of t-Mobile customers in that position.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#325

Earlier quoted context omitted.

"This terrible idea could actually be worse" is about the level I've come to expect. Congratulations, passwords haven't managed to be worse in every way than every possible alternative, mostly, yet.

Thats a huge benefit. Dont you hate that every service requires you to give them your identity? As I said most sites I dont even give a shit if my account gets hacked. Do you think HN for example would be better off if they decided everyone now has to do 2FA?

> Dont you hate that every service requires you to give them your identity?

I have Security Keys, which are entirely anonymous†, so actually I have much better security and do not "give them my identity" since I am, as I said, entirely anonymous.

In 1925 the understanding needed to do this did not exist. In 1975 the technology to implement it would have been prohibitive. In 2025 it's easily possible and indeed I use one every day - and yet here you are.

> Do you think HN for example would be better off if they decided everyone now has to do 2FA?

As so often it would depend on the implementation. I have absolutely no doubt that HN regulars would have strong opinions about what they should or should not use to achieve this.

† Obviously the choice to be named tialaramex everywhere is not "anonymous" - with a little effort you can even connect that to the name on legal paperwork, but on the other hand I also have accounts which aren't named tialaramex because they're intentionally not connected to this identity, and those use Security Keys too, by design it's not possible to connect the two.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#326
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

The problem isn't discrimination of SMS number types, it's SMS itself should be illegal, period.

> SMS itself should be illegal, period.

Why ? I still send SMS. Wifi is not available overall. The Google SMS app is not able to retry sending when connectivity is back and the UI is enshitified, but this is norm in modern software.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#327
post #296
post #167

Earlier quoted context omitted.

>Google shuts off the data on Fi after you've been outside the USA for a month. No problem, I'm happy to pay $25 a month for a 'dataless' connection that gives me SMS and voice. To be somewhat more specific: while I travel extensively and am in the US often, I am often outside of it for more than a month at a time, and it appears that Google will shut off data outside the US if you use data outside the US for too lon…

I just came back from 3 straight months in the UK with google fi and had mobile data for that entire time. Perhaps it's country dependent? Or based on other metrics? I wasn't a heavy mobile data user, but didn't intentionally avoid it either...

My comparison here is actually that I've never had it shut off. I'm not quite sure what the criteria are. I do have a friend who had it cut off after a few months of using it for all his data in the EU.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#328
post #324

Earlier quoted context omitted.

Maybe T-Mobile doesn't need to. I've used their WiFi calling for, what, going on ten years probably. Works a treat, including getting short code SMS. Ergo, I don't know the use case for femtocell for T-Mobile. That's why I was surprised to learn via TFA that WiFi isn't the solution in all cases.

The use case is anywhere Wi-Fi and cell coverage is spotty or nonexistent. There are probably plenty of t-Mobile customers in that position.

The use case is anywhere Wi-Fi and cell coverage is spotty or nonexistent.

Not in TFA, it’s not.

Post reply on HN