Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

341–350 of 379 posts

Re: SMS is not 2FA-secure

#341

Earlier quoted context omitted.

I think requiring you to be physically present and having a human take the sample in a prescribed manner serves as an effective 'password' - unless it's a live sample, the DNA is useless.

I think there's a misunderstanding of what is possible with DNA[0]. We take DNA from dead stuff all the time. I will agree with "you have to be physically present" is good enough password. This is Yubikey, which works fantastic. The problem with DNA is when it is compromised - you can't throw it away/change it without exorbant effort (bone marrow transplant? and then you're simply taking on someone else's identity? i…

I think people are misunderstanding what is being suggested here. The idea is that, for example, to unlock your bank account, you have to go to the bank where trusted bank employees will extract your DNA and have it sequenced, resulting in you being given access again. Others cannot spoof being you in this scenario because they cannot implant your DNA in themselves.

Re: SMS is not 2FA-secure

#342
post #253

Earlier quoted context omitted.

> Walk into a store and provide a government ID and the original SIM card. This is how it works in Poland since September 2019, after some recent SIM-swap attacks. You can swap SIM or get a replacement if stolen only at store showing government ID. It is free of charge with Orange and not always free with T-mobile. But this has some downsides in real life. 1) I had to walk my 88 yo Mom to the store to swap SIM card.…

The problem is that the ID is still checked by the clerk. They could be bribed or tricked by a fake ID. A recovery code snail-mailed/e-mailed to the account holder when they first open the account is the correct way to go, and if they can't provide it they need to go through a lengthy process where many factors are used to authenticate them (verify their physical address, verify their ID, ask to confirm last call rec…

You can require the clerk to note the document ID to avoid bribery.

Re: SMS is not 2FA-secure

#344
post #197
post #188

Earlier quoted context omitted.

Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.

What if you are abroad? My debit card was recently blocked and I had to wait until I went back, walked in the bank and show my face and ID.

I think we just need to be prepared for these sorts of things. Travel with cash, your debit card, and one or two credit cards. If you can afford it, have a backup SIM (Twilio sells SIM cards for about $3 and the cost to keep them activated is $1/mo, and nothing more if you don't use it [0]). Use a Twilio or Google Voice number that you don't use for anything else for 2FA or account recovery for services that require a phone number (some providers reject these numbers, but many will accept them).

[0] Full disclosure: I work at Twilio and built the first version of the wireless product, so I'm a bit biased.

Re: SMS is not 2FA-secure

#345
post #211
post #175

Earlier quoted context omitted.

Yes, super annoying. Now I can no longer get into my Apple Developer account without walking to my development mac I use to run xcode builds (for a react native app), since for some bizarre reason the only 2FA they support is their own which requires Apple hardware. It's bad enough their development toolchain requires you to buy their hardware, now to log into their websites you also have to buy their expensive hardw…

Apple continues to support SMS as 2FA. It is a bit hidden when signing in.

I just want TOTP.

Re: SMS is not 2FA-secure

#348
Unrelated -- I love how the domain name is literally the average Google query for when this becomes breaking news. Clever to make your domain name a literal Google query if you want to spread an idea...

Re: SMS is not 2FA-secure

#349

Not in Russia. Numerous examples exist when victim's number was linked to attacker's sim card to obtain 2FA code, then linked back to victim's sim so he does not notice anything. This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with su…

It's also important to know your threat model. Namely, random attacks versus targeted attacks.

Shitty 2fa will still deter people who get a list of a hundred million emails/usernames and passwords and try them on banks, Twitter etc from putting in the extra work to break into your account specifically.

If you expect targeted attacks - from governments, because you oppose them, from determined criminals, because you have a lot of nice stuff to steal, or from people around you, because you know too many assholes - maybe it might as well not exist, but for most people, most of the time, any 2fa is better than none.

Re: SMS is not 2FA-secure

#350

Earlier quoted context omitted.

The problem is that the ID is still checked by the clerk. They could be bribed or tricked by a fake ID. A recovery code snail-mailed/e-mailed to the account holder when they first open the account is the correct way to go, and if they can't provide it they need to go through a lengthy process where many factors are used to authenticate them (verify their physical address, verify their ID, ask to confirm last call rec…

You can require the clerk to note the document ID to avoid bribery.

How would this work exactly?
Post reply on HN