Live data from Hacker News

A hacker got all my texts for $16

vice.com

1–10 of 296 posts

Re: A hacker got all my texts for $16

#5

SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.

"2 Factor" isn't the right word choice. SMS isn't being used as a second factor here; it's the only factor.

"sms based one time passcodes" needs to die

and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph

Re: A hacker got all my texts for $16

#7

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

It's neither convenient nor stable for anyone moving between countries either. When given the choice between a service that uses my phone number as my permanent user identifier and one that uses my email, I'll always go for the latter.

Unfortunately, big parts of the industry seem to be headed the other direction.

Re: A hacker got all my texts for $16

#8

Earlier quoted context omitted.

"2 Factor" isn't the right word choice. SMS isn't being used as a second factor here; it's the only factor.

"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).

The problem is purely with how some companies are applying SMS as an auth factor. In cases where SMS us being used as a recovery factor, it should not be allow for immediate recovery. Instead the user should be notified via other channels (email, phone notifications) about the recovery attempt, be given the opportunity to reject it, and for the recovery to only succeed if it is not denied after e.g. 3 days.

Post reply on HN