Live data from Hacker News

SMS 2FA is not just insecure, it's also hostile to mountain people

blog.stillgreenmoss.net

91–100 of 328 posts

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#91

TOTP are okay for some things but often regulation means each code/challenge needs to be tied to a specific action. TOTP codes typically last for 30s and mulitple actions can happen within 30s, so it's not possible to use TOTP in many cases. PUSH approval could be used instead but then you need to download an app for every service you use, which isn't very convenient. PASSKEYS offer a solution which will work on both…

My personal 2FA favorite is OTP + authenticator app. It behaves predictably and doesn’t have weird failure conditions. SMS 2FA tied to your mobile number sucks if it doesn’t support Google Voice, especially when traveling internationally and your SIM card isn’t in your phone. Email 2FA usually works, but I just find it annoying. App-specific push notifications mostly work, but it’s hard to debug if you don’t get the…

I hate email 2FA because I purposely don't have email on my phone. Unless I'm in front of my computer, I'm unable to log in to websites that use email 2FA.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#92
The point of SMS 2FA is not security and never has been.

The point of SMS 2FA is tracking.

It's to force you to give them your phone number, for their own marketing, but also selling your customer profile to companies like Palantir.

This also makes the government happy, because they can scoop up your SMSs and they get a nice handy list of every service you use which makes warrants easier, but also gives them info about when you log in or do other actions on those accounts.

SMS 2FA costs these companies far more than TOTP would, but they still use SMS 2FA. That tells you everything you need to know...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#93

Earlier quoted context omitted.

Google Authenticator is a separate app that you need to download from Google Play. Native android solution is Google Password app which is pre-installed (at least on Pixel) and its functionality is extremely rudimentary even compared to Apple Passwords. No TOTP support there. I think that Google does not care about security for their users, because their passwords app is clearly some intern work, not something really…

It's not ideal but there's been some progress. I'm not sure we can blame Google for not pushing their Authenticator more, most services have been dead set on SMS and are now slowly moving to Passkeys, probably for the best.

Passkeys are going to make these problems much worse.

What do you do if google/ms/apple won’t let you log in, or you lose a device, or you lose your phone?

If the answer is “there’s an account recovery path involving a password”, then just accept passwords!

If the answer is “recover the passkey provider account”, then that forces everyone to have a single password / security question / whatever that grants access to all their accounts.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#94
post #12

Earlier quoted context omitted.

> When you choose an eccentric lifestyle Many "eccentric" lifestyles are not chosen. For instance not owning a smartphone or not having access to power easily is not necessarily limited to well-off tech-savv hipsters who want to make a statement, homeless people, older people in less connected areas or people in developing countries can also be in that situation. When you make your services depend on specific access,…

Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.

Exactly! Why should I subsidize sewers in town?

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#95
post #52

Earlier quoted context omitted.

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?

I could not use my Google Voice number (that I've had since Grand Central) for most companies that only do SMS 2FA until it became my Google Fi number. Then I guess some flag got set in the database they check against.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#96

Earlier quoted context omitted.

Yeah wont work for everyone, but a directional antenna mounted high up on house might have a better chance than a phone antenna.

The idea of mounting a directional antenna "high up" on a house (or paying someone to do it) for the purposes of receiving SMS 2FA seems wild.

You can also get antennas with suction cups. I have used this before to get 4G internet in a house with no access downstairs, by sticking the antenna on an upstairs window.

An outdoor antenna would be better, but yeah more of a pain. I guess it really depends on how badly someone wants SMS.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#97

She just needs a microcell/femtocell. Talk to your provider, explain to them you get poor service at your home or place of work, and they'll send you a free Internet-in cellular-out radio AP. She doesn't need a tower-based booster if she's got fiber/cable/DSL, those only serve to amplify weak signals and she's too many miles and too many mountain ridges away from the nearest tower, she wants something with RJ-45 inpu…

It seems t-Mobile no longer offers such hardware: https://www.t-mobile.com/support/coverage/4g-lte-cellspot-se...

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#98
This made me wonder whether it would be possible to build a Wi-Fi-only, roaming-only carrier for computers.

Your carrier is already capable of redirecting your SMS messages to other carriers, that's what they do when you're abroad and roaming with a foreign operator. You could make a fake carrier that speaks the right protocols on the roaming side, but communicates with the customer over the internet (using an API or a proprietary app) instead of LTE or GSM.

This would essentially work like an SS7 redirection attack, but with the full knowledge and consent of the "victim." You could alleviate the security impact here by requiring SIM card authentication, just like a normal carrier does, which could be performed through the internet and an USB reader just fine.

Carriers would probably hate this and might not be willing to sign roaming agreements with such a company. I wonder whether a gray-hat route would be possible here, especially if the company was outside US jurisdiction.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#99
post #52
post #23

> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…

It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.

May vary by institution, but both banks I have accounts with also support having a robot call my phone where I can confirm the login. That should at least work with WiFi calling.

Re: SMS 2FA is not just insecure, it's also hostile to mountain people

#100

Earlier quoted context omitted.

There's plenty of locations with houses in Montana that have no cell service too.

the article isn't about them. Montana by and large is a lot less dense than Asheville NC, which is a small city surrounded by normal towns. Asheville would only seem eccentric if normal is San Francisco.

There’s no cell service in many places that are 20 minutes from Silicon Valley or SF.

Heck, there are places that are a 20 minute walk from Apple and Google HQ without cell service.

Post reply on HN