Earlier quoted context omitted.
Problem with a government photo ID, There's no way to verify its authentic besides a visual inspection. I consider them as secure as SMS 2FA. For $200 and someone could get passable ID with your name on it.
That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…
SMS is not 2FA-secure
351–360 of 379 posts
Re: SMS is not 2FA-secure
#352Earlier quoted context omitted.
I think there's a misunderstanding of what is possible with DNA[0]. We take DNA from dead stuff all the time. I will agree with "you have to be physically present" is good enough password. This is Yubikey, which works fantastic. The problem with DNA is when it is compromised - you can't throw it away/change it without exorbant effort (bone marrow transplant? and then you're simply taking on someone else's identity? i…
I think people are misunderstanding what is being suggested here. The idea is that, for example, to unlock your bank account, you have to go to the bank where trusted bank employees will extract your DNA and have it sequenced, resulting in you being given access again. Others cannot spoof being you in this scenario because they cannot implant your DNA in themselves.
Which I agree, that works great, but quite narrow in the the use cases at that point.
Re: SMS is not 2FA-secure
#353Earlier quoted context omitted.
You can require the clerk to note the document ID to avoid bribery.
How would this work exactly?
If later it turns out this was a sim swapping attack you can verify if the clerk entered a valid document ID. He can’t do that without having been presented a proper document, so you can tell if he checked.
Re: SMS is not 2FA-secure
#354Using a few old Google accounts, I experimented with Google’s account recovery options and discovered that if a Google account does not have a backup phone number associated with it, Google requires you to have access to the recovery email account OR know the security questions in order to take over an account. However, if a backup phone number is on the account, Google allows you to type in a code from an SMS to the device in lieu of any other information.
[1] https://tech.vijayp.ca/adding-a-phone-number-to-your-google-...
Re: SMS is not 2FA-secure
#355My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…
Scary thought
Re: SMS is not 2FA-secure
#356Earlier quoted context omitted.
Have you seen the prompt system, as used by Google, Micosoft, Okta, et al.? In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though. In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't hav…
They (and similar corporate 2FA solutions like PingID and similar systems used by banks) basically assume uninterrupted access to the internet which is generally a poor assumption. It often breaks down when you're traveling either due to network or roaming issues just when you desperately need access. In all these situations, I've found companies which offer a back up SMS option very valuable since it usually gets de…
I tend to use TOTP for systems where I'm concerned about offline usage. But again, YMMV.
Re: SMS is not 2FA-secure
#357Earlier quoted context omitted.
That's the key problem that US needs to solve - the businesses don't really have a solid gov't ID system to fall back on. In most of Europe (UK seems to be more like USA as far as I understand) passing on a counterfeit ID to a mobile shop is harder (and more rare) than paying with counterfeit money, the IDs can be checked, employees are required to verify online if that ID has been reported lost or stolen, etc. I mea…
You can get a federal ID. It's called a passport card. It costs $65. The US also has the REAL ID[0] standard that requires IDs to meet minimum standards in order to be accepted by the federal government. If carriers just required a REAL ID compliant ID in order to get a new SIM, and actually checked it via the chip or magnetic strip, I think we'd be good. [0] https://www.dhs.gov/real-id
Which is usually a really crappy idea when you want to save a few bucks compared to a real passport.
They're umpteen stories of heartbreak and hurt, by people not being allowed to board an international flight, or a cruise which stops at destinations not covered by a passport card.
They're also those that thought it's a great idea to get them for their kids.
With the same consequence. A passport card does not allow you to fly internationally. Not even to Mexico or Canada.
Re: SMS is not 2FA-secure
#358Earlier quoted context omitted.
What worries me isn’t that I might not be able to recover my account if it uses some other form of authentication, it’s that I might not be able to recover my account because it requires authentication from a phone number I lose access to.
And by the time you regain access to the phone number, the account might already be using a different one...
Re: SMS is not 2FA-secure
#359Earlier quoted context omitted.
How would this work exactly?
The clerk has to use some kind of online system to connect the new sim to the customers phone number. The system would obviously require the clerk to authenticate himself and could require him to enter the passport number or other document ID he checked to verify the customers identity. If later it turns out this was a sim swapping attack you can verify if the clerk entered a valid document ID. He can’t do that witho…
Re: SMS is not 2FA-secure
#360Earlier quoted context omitted.
The clerk is looking at ID and comparing with data in the system. If bribed he can always claim that ID looked legit or he made honest mistake. So easy for evildoers and so much friction for law-abiding customers.
If you make the carrier liable for damages in case of fraud, there would be process to mitigate the risk from one bad actor. Like the bank requires a manager approval for certain high risk transactions like international wires.