TOTP are okay for some things but often regulation means each code/challenge needs to be tied to a specific action. TOTP codes typically last for 30s and mulitple actions can happen within 30s, so it's not possible to use TOTP in many cases. PUSH approval could be used instead but then you need to download an app for every service you use, which isn't very convenient. PASSKEYS offer a solution which will work on both…
My personal 2FA favorite is OTP + authenticator app. It behaves predictably and doesn’t have weird failure conditions. SMS 2FA tied to your mobile number sucks if it doesn’t support Google Voice, especially when traveling internationally and your SIM card isn’t in your phone. Email 2FA usually works, but I just find it annoying. App-specific push notifications mostly work, but it’s hard to debug if you don’t get the…
SMS 2FA is not just insecure, it's also hostile to mountain people
91–100 of 328 posts
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#92The point of SMS 2FA is tracking.
It's to force you to give them your phone number, for their own marketing, but also selling your customer profile to companies like Palantir.
This also makes the government happy, because they can scoop up your SMSs and they get a nice handy list of every service you use which makes warrants easier, but also gives them info about when you log in or do other actions on those accounts.
SMS 2FA costs these companies far more than TOTP would, but they still use SMS 2FA. That tells you everything you need to know...
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#93Earlier quoted context omitted.
Google Authenticator is a separate app that you need to download from Google Play. Native android solution is Google Password app which is pre-installed (at least on Pixel) and its functionality is extremely rudimentary even compared to Apple Passwords. No TOTP support there. I think that Google does not care about security for their users, because their passwords app is clearly some intern work, not something really…
It's not ideal but there's been some progress. I'm not sure we can blame Google for not pushing their Authenticator more, most services have been dead set on SMS and are now slowly moving to Passkeys, probably for the best.
What do you do if google/ms/apple won’t let you log in, or you lose a device, or you lose your phone?
If the answer is “there’s an account recovery path involving a password”, then just accept passwords!
If the answer is “recover the passkey provider account”, then that forces everyone to have a single password / security question / whatever that grants access to all their accounts.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#94Earlier quoted context omitted.
> When you choose an eccentric lifestyle Many "eccentric" lifestyles are not chosen. For instance not owning a smartphone or not having access to power easily is not necessarily limited to well-off tech-savv hipsters who want to make a statement, homeless people, older people in less connected areas or people in developing countries can also be in that situation. When you make your services depend on specific access,…
Homeless people get free smartphones and free service in the US. Living in very rural areas is in fact a lifestyle choice. Not all choices need to be subsidized.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#95Earlier quoted context omitted.
It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.
I've been using Citi and Discover for years with a Google Voice number. Possibly I've been grandfathered in though?
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#96Earlier quoted context omitted.
Yeah wont work for everyone, but a directional antenna mounted high up on house might have a better chance than a phone antenna.
The idea of mounting a directional antenna "high up" on a house (or paying someone to do it) for the purposes of receiving SMS 2FA seems wild.
An outdoor antenna would be better, but yeah more of a pain. I guess it really depends on how badly someone wants SMS.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#97She just needs a microcell/femtocell. Talk to your provider, explain to them you get poor service at your home or place of work, and they'll send you a free Internet-in cellular-out radio AP. She doesn't need a tower-based booster if she's got fiber/cable/DSL, those only serve to amplify weak signals and she's too many miles and too many mountain ridges away from the nearest tower, she wants something with RJ-45 inpu…
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#98Your carrier is already capable of redirecting your SMS messages to other carriers, that's what they do when you're abroad and roaming with a foreign operator. You could make a fake carrier that speaks the right protocols on the roaming side, but communicates with the customer over the internet (using an API or a proprietary app) instead of LTE or GSM.
This would essentially work like an SS7 redirection attack, but with the full knowledge and consent of the "victim." You could alleviate the security impact here by requiring SIM card authentication, just like a normal carrier does, which could be performed through the internet and an USB reader just fine.
Carriers would probably hate this and might not be willing to sign roaming agreements with such a company. I wonder whether a gray-hat route would be possible here, especially if the company was outside US jurisdiction.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#99> other options available to her include > port her cellphone number to a VOIP provider that does support receiving SMS from shortcodes over wifi That's generally a great solution – unless the company she's dealing with is one of those that don't send SMS-OTP codes to VoIP numbers for seCuRiTy reasons, or demand that the number is somehow "registered in her name" (which many smaller carriers apparently don't do). I r…
It really is absurd that the same companies that won’t allow 2FA with any other method outside of SMS are the same ones not sending to VoIP. Maybe they all go through a service for SMS that blocks it, but it still upsets me. It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.
Re: SMS 2FA is not just insecure, it's also hostile to mountain people
#100Earlier quoted context omitted.
There's plenty of locations with houses in Montana that have no cell service too.
the article isn't about them. Montana by and large is a lot less dense than Asheville NC, which is a small city surrounded by normal towns. Asheville would only seem eccentric if normal is San Francisco.
Heck, there are places that are a 20 minute walk from Apple and Google HQ without cell service.