Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

351–360 of 379 posts

Re: SMS is not 2FA-secure

#351
post #205

Earlier quoted context omitted.

Problem with a government photo ID, There's no way to verify its authentic besides a visual inspection. I consider them as secure as SMS 2FA. For $200 and someone could get passable ID with your name on it.

That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…

I'm in retail in the UK at the moment. For doing credit, the main way we use is by drivers license. I plug the details into a form at the till and check the face. It does an online check with the DVLA.

Re: SMS is not 2FA-secure

#352
post #341

Earlier quoted context omitted.

I think there's a misunderstanding of what is possible with DNA[0]. We take DNA from dead stuff all the time. I will agree with "you have to be physically present" is good enough password. This is Yubikey, which works fantastic. The problem with DNA is when it is compromised - you can't throw it away/change it without exorbant effort (bone marrow transplant? and then you're simply taking on someone else's identity? i…

I think people are misunderstanding what is being suggested here. The idea is that, for example, to unlock your bank account, you have to go to the bank where trusted bank employees will extract your DNA and have it sequenced, resulting in you being given access again. Others cannot spoof being you in this scenario because they cannot implant your DNA in themselves.

Ah you're right. I've re-read it and it is physically present someone verifying you using your DNA.

Which I agree, that works great, but quite narrow in the the use cases at that point.

Re: SMS is not 2FA-secure

#353
post #350

Earlier quoted context omitted.

You can require the clerk to note the document ID to avoid bribery.

How would this work exactly?

The clerk has to use some kind of online system to connect the new sim to the customers phone number. The system would obviously require the clerk to authenticate himself and could require him to enter the passport number or other document ID he checked to verify the customers identity.

If later it turns out this was a sim swapping attack you can verify if the clerk entered a valid document ID. He can’t do that without having been presented a proper document, so you can tell if he checked.

Re: SMS is not 2FA-secure

#354
This post [1] makes a very good point...

Using a few old Google accounts, I experimented with Google’s account recovery options and discovered that if a Google account does not have a backup phone number associated with it, Google requires you to have access to the recovery email account OR know the security questions in order to take over an account. However, if a backup phone number is on the account, Google allows you to type in a code from an SMS to the device in lieu of any other information.

[1] https://tech.vijayp.ca/adding-a-phone-number-to-your-google-...

Re: SMS is not 2FA-secure

#355

My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…

Does that mean an authoritarian government can read the location and sms of a number from foreign country without any cooperation from the carrier?

Scary thought

Re: SMS is not 2FA-secure

#356
post #97
post #37

Earlier quoted context omitted.

Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…

They (and similar corporate 2FA solutions like PingID and similar systems used by banks) basically assume uninterrupted access to the internet which is generally a poor assumption. It often breaks down when you're traveling either due to network or roaming issues just when you desperately need access. In all these situations, I've found companies which offer a back up SMS option very valuable since it usually gets de…

In my opinion, that sounds like precisely the sort of system that should not offer an SMS fallback unless the goal is to create a false sense of security in the user. But YMMV, I don't generally need to access my online banking applications when I don't have useful internet access.

I tend to use TOTP for systems where I'm concerned about offline usage. But again, YMMV.

Re: SMS is not 2FA-secure

#357

Earlier quoted context omitted.

That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…

You can get a federal ID. It's called a passport card. It costs $65. The US also has the REAL ID[0] standard that requires IDs to meet minimum standards in order to be accepted by the federal government. If carriers just required a REAL ID compliant ID in order to get a new SIM, and actually checked it via the chip or magnetic strip, I think we'd be good. [0] https://www.dhs.gov/real-id

You can get a federal ID. It's called a passport card. It costs $65.

Which is usually a really crappy idea when you want to save a few bucks compared to a real passport.

They're umpteen stories of heartbreak and hurt, by people not being allowed to board an international flight, or a cruise which stops at destinations not covered by a passport card.

They're also those that thought it's a great idea to get them for their kids.

With the same consequence. A passport card does not allow you to fly internationally. Not even to Mexico or Canada.

Re: SMS is not 2FA-secure

#358
post #225

Earlier quoted context omitted.

What worries me isn’t that I might not be able to recover my account if it uses some other form of authentication, it’s that I might not be able to recover my account because it requires authentication from a phone number I lose access to.

And by the time you regain access to the phone number, the account might already be using a different one...

They generally run a cron job on your email to see what are the vulnerable accounts & then decide in order to which one is most important

Re: SMS is not 2FA-secure

#359
post #350

Earlier quoted context omitted.

How would this work exactly?

The clerk has to use some kind of online system to connect the new sim to the customers phone number. The system would obviously require the clerk to authenticate himself and could require him to enter the passport number or other document ID he checked to verify the customers identity. If later it turns out this was a sim swapping attack you can verify if the clerk entered a valid document ID. He can’t do that witho…

Its just convenience over security. Lot of things can be done but then the extra burden that companies have to go through. Think about that people don't use app based authentication because it's inconvenient even though it matters to them. How can you expect carriers to do it

Re: SMS is not 2FA-secure

#360
post #314
post #273

Earlier quoted context omitted.

The clerk is looking at ID and comparing with data in the system. If bribed he can always claim that ID looked legit or he made honest mistake. So easy for evildoers and so much friction for law-abiding customers.

If you make the carrier liable for damages in case of fraud, there would be process to mitigate the risk from one bad actor. Like the bank requires a manager approval for certain high risk transactions like international wires.

Too long of a moon shot. Generally the T&C are limited to actual loss, like you lost your internet for 2 days so they'll reimburse you for 2 days of bill but not if you lost a business deal. Similarly in case of airline if you missed your game. they're not responsible for the game tickets
Post reply on HN