Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

51–60 of 149 posts

Re: It’s time to stop using SMS for security

#51
post #33
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

It's still used a lot also in Europe for OTP codes (banking and such), as well as for shops/deliveries, where they send an SMS for order status changes (shipped from the warehouse, in transit, ...).

Since PSD2 every German bank I know moved to 2fa mobile applications instead of SMS, I expected the same for the rest of the EU. I'm quite sure that delivery company also work with emails (at least that's the case of DHL, UPS, DPD, etc, they always send me notifications via emails).

Re: It’s time to stop using SMS for security

#52
Did anybody experiment using Twillio (or similar) to receive 2FA SMS?

There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-day number.

Re: It’s time to stop using SMS for security

#53
post #12

Yahoo! Japan, One of the most famous website in Japan, forces users to use insane auth method: SMS 1FA. It even accepts phone number as login ID. This is really stupid.

It's a rather recent thing, and it's touted as a security feature. To be fair, Japan seems to be safer than most of the world when it SIM swapping (there are pretty strict identification requirements defined by law) and for porting phone numbers between SIM cards. I also never heard of any case of attacks against SS7 or other part of the telecommunication stack in Japan (I'd be happy to know if someone does)

That being said, a certain class of SIM cards (SMS-only cards, without voice functionality) is exempt from most of these strict checks as far as I know, and there are other technical vulnerabilities that are probably just waiting to happen in Japan before they're taking seriously.

I'm a little bit surprised that Yahoo! Japan went for SMS as the only authentication method, since their one of the main sponsors of the FIDO Japan WG.

Re: It’s time to stop using SMS for security

#54
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

SMS 2FA costs money per message. It's also subject to telecom rules -- you usually need to buy short codes by geography if you're sending at scale, and that involves dealing with bureaucracies at scale, too. Getting a short code can take weeks and cost thousands of dollars. Of course you can always pay to have other people do that management for you. But you're going to pay, nonetheless.

Then you have to worry about fraud, and whether telcos in have been hacked, or are corrupt, and are leaking messages to bad guys.

I've seen entire (small) countries drop out, too. Usually the way you find out about this is that support notices an uptick in users in complaining about not getting messages, or you notice that the entirety of some geography isn't successfully completing the transactions you tried to protect with SMS. Er, you did consult the (changing) prefix database and phone number parser to (semi) reliably determine a geography from a phone number, right? Isn't parsing phone numbers fun?

It's fractally terrible and expensive, and I haven't even talked about APIs yet.

Re: It’s time to stop using SMS for security

#55
post #52

Did anybody experiment using Twillio (or similar) to receive 2FA SMS? There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-d…

A few of my employers use(d) Twilio for 2FA SMS, one of whom are UK FCA regulated.

Re: It’s time to stop using SMS for security

#56
post #23

Earlier quoted context omitted.

Not all people have or want smartphones.

Don't know about the US but I haven't seen anybody using classic GSM for years now...

I know plenty of folks using those. Most people do it by choice because the hardware is more reliable and the battery more durable, but some also do it because their planned-obsolete smartphone broke down.

Re: It’s time to stop using SMS for security

#57
post #54
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

SMS 2FA costs money per message. It's also subject to telecom rules -- you usually need to buy short codes by geography if you're sending at scale, and that involves dealing with bureaucracies at scale, too. Getting a short code can take weeks and cost thousands of dollars. Of course you can always pay to have other people do that management for you. But you're going to pay, nonetheless. Then you have to worry about…

> SMS 2FA costs money per message.

This is only because the telephone cartels control the networks. The same is more or less true of Internet. Operators have advocated for anti-open-wifi laws across the globe so they can sell their internet access plans (xDSL/3G), when we could have free networking for all in all places.

Seriously though, why couldn't we have FREE privacy-friendly networking as a public service?

Re: It’s time to stop using SMS for security

#58
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

I’m an Australian that was in India for the last year (just arrived back, up to day 2 of my 14 day quarantine). Anything that has needed to verify me through SMS (e.g. filing my Australian tax return via myGov, paying for things with my credit card if they used the fancy security thing, like most airlines do and Amazon apparently does, and logging into one or two things) has required me to contact my parents to turn on and check the old phone I left with them, because roaming for a year is expensive and otherwise pointless (I barely use a phone), but transferring my number to a prepaid Amaysim SIM let me keep it alive and mine for the year for $10.

Actually, the myGov thing was a real piece of work. They offer secret questions as a second factor that you can opt to use instead of SMS codes (and yes, secret questions are stupid), but when I did that, it silently unlinked my Australian Tax Office account. I tried to link it up again (a bit of a pain in its own right), and it told me that ATO has decided that it won’t let you link it up if you use secret questions as the second factor technique. Seriously. So I had to switch back. Oh yeah, they do also have a third option, an app of their own that can generate codes (not TOTP), but that app had something like 2 stars on Google Play Store, with many reviews saying it didn’t work at all, so I didn’t even bother trying that.

When I’m in Australia with my phone handy, SMS verification seems not too bad, but when out of the country and not roaming, it may vary between very inconvenient and completely debilitating.

Re: It’s time to stop using SMS for security

#59
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

I probably hate it for different reasons from others on HN, but I move countries (and change numbers) and travel a lot, and SMS just isn't a reliable way to reach me. On top of that, attempting to log in to a website from a foreign country is often itself a trigger for 2FA, and exactly the moment when I'm not reachable by SMS. This has bitten me a few times, sometimes in desperate situations. Like when I've needed to…

Unfortunately, the only remedy to this i've found is to travel like james bond with two cell phones. I keep a second android phone with my 'back home' sim on the cheapest monthly plan possible and only turn it on to read sms codes. It really comes in handy when needing to sign up to a new service in your home country while abroad. Just don't forget to keep data roaming turned off

Re: It’s time to stop using SMS for security

#60
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

Beyond it being insecure, I see it used too often as the only alternative to yet another proprietary MFA app.

Like Microsoft Authenticator. It wanted way too many permissions on my phone, and provided less security than my Yubikey authenticator. My yubikey provides a standard open OTP but requires the device to generate it (phone tap or plugin via USB to computer or phone).

Open standards are better. I don't want a different authenticator app for every website. It's so much simpler to use a single app.

Post reply on HN