A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
Second factor SMS: Worse than its reputation
81–90 of 323 posts
Re: Second factor SMS: Worse than its reputation
#82I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…
Basic usability? The security theatre is making computing more and more yanky every year, with questionable benefits, and with no regard to the drop in efficiency.
For most accounts I don't care much if they are compromised. And have never been compromised even with a lot of "worst practices".
Would you agree also that MFA should be mandated for everybody's doors? Or to my bike?
Re: Second factor SMS: Worse than its reputation
#83Earlier quoted context omitted.
Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank
This might not be sufficient anymore. Many online payments are rendered either on the shop's pages or on a third party payment provider, including 3DSecure implementations. These don't redirect to any sensible bank URLs. Both of my banks use a payment flow which uses a hardware authenticator. But only one bank seems secure: it prompts for an amount and a reference and generates an OTP based on that. This is distinct…
Re: Second factor SMS: Worse than its reputation
#84A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
This is a great example of why a search engine shouldn’t overtly let people pay them to alter rankings lol.
Re: Second factor SMS: Worse than its reputation
#85A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…
> an attacker who paid for Google Ads for a search term like "BANKNAME login" I tried out buy Google ads once out of curiosity cause they gave me a free credit. It was crazy how many ridiculous stipulations and guidelines I had to work around before they'd accept my ad. How are they that strict for me, but seemingly they'll sell to a phishing page that's impersonating a bank and targeting it to people searching for t…
Not to excuse failures, but there isn't a "it is easy for them but hard for me" situation.
Re: Second factor SMS: Worse than its reputation
#86I've long suspected that companies which force SMS 2FA don't really care about security, they just want your phone number, and 2FA is a convenient bit of security theatre to make you give it to them.
Re: Second factor SMS: Worse than its reputation
#87I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…
Re: Second factor SMS: Worse than its reputation
#88I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…
> I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. A password manager is, in essentially every respect except interoperability, inferior to WebAuthn. Let’s not make an inferior solution mandatory when we already have a superior solution.
With a slight caveat that it doesn't work. At least not on Linux without some proprietary junk dongles or their emulators.
Re: Second factor SMS: Worse than its reputation
#89And unfortunately almost every bank forces me to use them, because their apps refuse to run on my rooted phone. Nice security win there!
Hot take: rooted phones are inherently less secure. That does not include GrapheneOS btw, since you don't have root privileges on an official build of GrapheneOS.
Re: Second factor SMS: Worse than its reputation
#90I can't think of any reason why we should not make password managers mandatory for all web authentication today, with the password manager being the 2nd factor. Your desktop, laptop, tablet, and phone can all share a password manager. They work offline and online. Passwords generated are unique, breaking password reuse attacks. Password managers support auto-filled TOTP codes per-login. They support passkeys. There's…
SMS has an extraordinary advantage in that the vast majority of people transparently have access to it. No need to download another app. No need to install anything. No need to buy a special usb device. It also has a recovery mechanism built in, as the carriers will all let you move your phone number to a new device. This, of course, comes with the high cost of sim-swapping attacks. But few companies will be happy with "customers just lose their accounts when they drop their phones in the toilet."
We'll see if the google/apple security key system takes off. That's probably the best bet we've got given the ubiquity of these ecosystems.