5 ms·
Google also tells you to add a second, "backup" number for two factor auth, or even more of them. It can be a landline, or a trusted person phone.
by iokanuon 10y ago
Google also tells you to add a second, "backup" number for two factor auth, or even more of them. It can be a landline, or a trusted person phone.
- atemerev 10y agoPhone or SMS based 2FA is inherently insecure. Can be intercepted at carrier level (and it is quite cheap to do it — some political targets in Russia and Turkey were attacked this way).
- lorenzhs 10y agoYeah but that's a different threat model than the one discussed. It will prevent 99% of attacks but someone always comes in yelling "BUT IT'S NOT PERFECT". As they say, perfect is the enemy of good.
- atemerev 10y agoThe solution which is considered to be "almost perfect" and relied upon as that, but failing unexpectedly is arguably worse than imperfect solution with known imperfections.
- rhizome 10y agoThe solution which is considered to be "almost perfect" and relied upon as that, but failing unexpectedly What other failure mode is there? A solution that's considered to be actually perfect? Regardless, you have to account for Godel.
- atemerev 10y agoBlack swans arise because when people design things that work 99.99% of the time, they tend to relax and rely on the system more than they should, and when this 0.001% event happens, they are completely unprepared. The correct mode of operation is to always be prepared, without relying on the "perfect" system too much. If system is actually good, "chaos monkeys" may be employed to keep everybody prepared.
- prodigal_erik 10y agoWhy would 99% of adversaries fail to choose the attack that's known to work?
- lorenzhs 10y agoNot everyone is a nation state or has SS7 access. Intercepting SMS isn't as easy as you make it out to be.
- doctorshady 10y agoI think the SS7 vulnerability in question you're talking about is limited to the MAP portion of SS7. So for 2FA with a landline, you should be fine.
- alexsmolen 10y agoThe problem is that SMS provides better recovery rates than TOTP/HOTP + backup codes, because people can go to their carrier and get a new device at the same number. It's important to remember that availability is an important aspect of security. If you protect a user primarily concerned with mass-account takeover attacks from a low-probability threat (people intercepting their SMS channel) but introduce a high-probability threat (dropping their phone in the toilet and being locked out of their account forever) you may not have made a good security tradeoff.