Live data from Hacker News

SMS is not 2FA-secure

issms2fasecure.com

51–60 of 379 posts

Re: SMS is not 2FA-secure

#53
You know what's funny? LinkedIn is supposed to be a 'professional' social network (Microsoft owned) and a friend of mine was asked to add a phone number 'For security purposes'. I knew this was suspiciously involving 2FA SMS + a bonus of spam callers and I told him to press "Not Now". Whilst the world is moving to U2F and time-sensitive codes, a security system using SMS 2FA is now equivalent to a single PC running Windows XP in a bank.

But its not just LinkedIn. Its a huge list of major companies including some FAANG ones too. Oh dear.

Re: SMS is not 2FA-secure

#54

HN seems to be getting a lot of these submissions lately where the question asked in the title is the same as the domain name. Sometimes the content of the page doesn't even answer the question. Feels like some kind of spammy PageRank manipulation going on. I'm happy to be wrong about this, but I wanted to see if anyone else has noticed. Maybe I'm just smoking crack waffles again.

[deleted]

Re: SMS is not 2FA-secure

#55
Worth having a private number on a low or PAYG plan and use that for your security separate from your main mobile number.

After all, most have a spare phone and great use for those Nokia's.

Re: SMS is not 2FA-secure

#57

Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no". https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...

I’m surprised I was downvoted too.

Honestly I think the headline is attention grabbing. A much more useful headline would have been “An analysis of the vulnerabilities of 2FA over SMS”.

But the Betteridge headline is in the domain name!

Re: SMS is not 2FA-secure

#59
post #44

Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no". https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...

The key part here is to only post this comment under headlines for which the answer in "no".

What I normally do is remember the law, and generally I don’t click through headlines which are questions.

But this one felt more like it would be something a little deeper.

So then I clicked through - and the page fills up with the word “no”.

So I feel pretty duped.

Re: SMS is not 2FA-secure

#60

Is SMS 2FA Secure? No, I agree. Is SMS 2FA enough for most of the people today? Yes Is SMS a cost-benefit solution for most uses? Yes

Is offering or forcing SMS 2FA and not offering an option for only TOTP asinine? Yes.

It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.

Post reply on HN