Live data from Hacker News

How SMS fraud works and how to guard against it

apuchitnis.substack.com

71–80 of 107 posts

Re: How SMS fraud works and how to guard against it

#71
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.

At least for the Apple ecosystem 2FA is built into the iCloud Keychain so you can access it from multiple devices. While there are security implications, in general it is a good trade off that the Safari or apps will only offer to auto-fill on the matching site. For the general population it is a far nicer, safer, and faster solution than waiting for the matching SMS code to login.

The biggest downside is if the site isn't set up correctly it is a long trek into Settings to get the code and it makes the site seem less trustworthy.

Re: How SMS fraud works and how to guard against it

#72
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

With authenticator apps, if you lose your phone, you lose access to everything. Your life is fucked. With SMS, you just get a new sim (free in my country).

Basically authenticator apps create a much bigger problem than getting hacked, and there's a far greater probability of me losing my phone (has happened before) than getting hacked.

Re: How SMS fraud works and how to guard against it

#73

Earlier quoted context omitted.

authenticator apps come with privacy concerns. Right now, Microsoft has no means to collect my location data, they don't have any access to my phone, including my phone's camera. The moment I install Microsoft authenticator that situation changes. No thanks.

SMS has even more privacy concerns. To be able to receive SMS, the network must know your location. You are also forced to use proprietary firmware for most radio components. SMS is also subject to attacks against the telecom, such as by tricking their staff into producing a new sim card with your number.

> To be able to receive SMS, the network must know your location. You are also forced to use proprietary firmware for most radio components.

These are risks you have just by owning a cell phone, having an authenticator app doesn't change that.

> SMS is also subject to attacks against the telecom, such as by tricking their staff into producing a new sim card with your number.

This is absolutely a legitimate concern, and the lack of security in carrier practices in particular honestly makes me want to avoid 2FA entirely. Fortunately, I've never needed it for account recovery. I use a password manager so all accounts get unique logins and I'm savvy enough not to fall for your typical phishing scams which helps. There's no guarantees my luck will hold out though so I'll be looking into privacy preserving options for the most critical things or for cases where I'm not left with any choice.

Re: How SMS fraud works and how to guard against it

#74
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

I finally got my 75-year-old mother to add 2FA/SMS to her online banking account. She calls me (from her landline ) every time she tries to login. I have to walk her through the process. We usually have to request a new auth code be sent at least twice. It generally takes 10 or 15 minutes, although, admittedly, half the time is her complaining. So, yeah, there's no way I could get her to use an Authenticator app. (Al…

Wait until you mother is 89, like mine! It just gets worse. She is unable to retrieve a text message once it times out off her screen. (She uses a flip-phone).

Re: How SMS fraud works and how to guard against it

#75

Earlier quoted context omitted.

SMS has even more privacy concerns. To be able to receive SMS, the network must know your location. You are also forced to use proprietary firmware for most radio components. SMS is also subject to attacks against the telecom, such as by tricking their staff into producing a new sim card with your number.

> To be able to receive SMS, the network must know your location. You are also forced to use proprietary firmware for most radio components. These are risks you have just by owning a cell phone, having an authenticator app doesn't change that. > SMS is also subject to attacks against the telecom, such as by tricking their staff into producing a new sim card with your number. This is absolutely a legitimate concern, a…

TOTP does not require internet or a phone, even though it is commonly available as an phone app. It only requires an accurate system clock to work properly.

Re: How SMS fraud works and how to guard against it

#76
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

Everyone with a cell phone has SMS. It's already set up. And it's recoverable plus someone else's problem to recover. Add that's it's a pretty good universal id.

I hate SMS 2FA but it makes sense.

Re: How SMS fraud works and how to guard against it

#77
post #24
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

Nobody in my family - parents, kids, spouse - knows what an authenticator app is or would what to do if presented that as an option, although my teen could probably figure it out. For everyone else, it would be a cascading series of installation and password and app switching and immediacy problems. This would create a great deal of frustration, and ultimately a call to family tech support (me) or the service provide…

The biggest hurdle to authenticator app adoption for the masses is the one that only bites you a year or more down the road when you get a new phone. If you didn't transfer your seed info over to the new phone before trading in the old one, you are locked out of all your accounts.

Re: How SMS fraud works and how to guard against it

#78
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

> it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA As a data point, USAA (which is not the biggest bank, of course, but it is not tiny either) has supported TOTP for years. There are probably others, but at least some banks support relatively modern security.

My credit union supports TOTP. They also sent me a one time code generator thingy that I can use as a 2nd factor. Trouble is, there's a big link on the login screen that will allow anyone to bypass those options and fallback to SMS or email.

Re: How SMS fraud works and how to guard against it

#79
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

Have they? It seems the trend is to support Authenticator apps (i.e. one-time scan a QR code to a TOTP URL that I store on my own device). I haven't seen too many products that support TOTP 2FA but require SMS 2FA. Some companies do require a phone number to setup an account (because it's the best proxy we have for "one per real person" or "expensive for one person to get many of"), but if they're competent then you…

> It seems the trend is to support Authenticator apps

Oh, I wish that were true for financial institutions. But for my sample size of 3 credit unions, 1 large bank, and 1 brokerage, only one (small CU) supports TOTP. All the others have SMS as the only, mandatory 2FA. It drives me crazy how backwards that is.

Re: How SMS fraud works and how to guard against it

#80

Earlier quoted context omitted.

Some folks build (or use) telecommunication systems that work for (cell) phones. Believe it or not but for receiving a notification via text message you nobody needs to install any apps or even require a smartphone and/or internet access :)

It's still mostly used for malicious tracking. In many countries you have to use your identity to get a phone number, and SMS verification exploits this to track users.

Never heard of getting a convenience store burner phone for cash?
Post reply on HN