Live data from Hacker News

HTML attributes to improve your users' two factor authentication experience

twilio.com

81–82 of 82 posts

Re: HTML attributes to improve your users' two factor authentication experience

#81

Earlier quoted context omitted.

There are a numbers of things here that are true. * Applications that take a phone number for one reason (2FA or otherwise) and also use it as a single factor for account reset are less secure in the case of number recyling. * Applications that do 2FA via SMS do not necessarily do account resets via SMS * 2FA over SMS is more secure than just having a password to secure an account. I am sorry your girlfriend had this…

Ok, makes sense. Thank you for the kind response and I approve of most of it. I think we will have to agree to disagree on the last * though. I think that statement is very much 'it depends.' I apologize for going in circles one more time... but by not providing 2FA SMS, it is impossible to f'ck it up or be abused. Right?

I shy away from any rules that say you can’t mess something up simply by avoiding one thing, especially in this sort of case. Consider also that avoiding 2FA by SMS may avoid sim swap or recycle attacks, but it could also eliminate 2FA for users who don’t have a device capable of running an authenticator application (a feature phone).

There’s a lot more at play here, and “just don’t” isn’t a nuanced enough answer to 2FA by SMS.

Re: HTML attributes to improve your users' two factor authentication experience

#82

Dealing with 2FA ux right now. There is a massive gap between threat intel people, product owners, and end users. From an identity assurance perspective, SMS is the best available. From an authentication perspective, it's increasingly dodgy. Reality is telcos have user enrollment almost on par with bank KYC, where everything else has great authN but with user asserted identity. Critics of SMS are technically correct,…

> Reality is telcos have user enrollment almost on par with bank KYC, where everything else has great authN but with user asserted identity. Are you sure? I don't mean that to sound hostile, genuinely asking. Because, at least in the States and Canada, I can get all of the +1 numbers I want on real SIMs for around a dollar apiece--or less if I work at it instead of just trotting down to Walgreens--and attach any name…

It's the credit check part of the KYC for telcos that makes them like banks. The pay as you go SIMs, absolutely arbitrary, but there are back end id verification services offered by telcos that have been in design a very long time. Not sure their current status, but they have the KYC data.
Post reply on HN