4 ms·
Hmm interesting read. In Sweden there is a thing called BankID and basically you can use your mobile device as a universal authenticator. Of course, you need to
by CorvusCrypto 8y ago
Hmm interesting read. In Sweden there is a thing called BankID and basically you can use your mobile device as a universal authenticator. Of course, you need to have the device and enter a 6-digit pin, but I often wondered how dangerous it was to use this so much. And on top of that I know people that used it in local cafes on public WiFi.
I would love to do an examination of communication via BankIDs app to the internet to see what kind of security exists to protect the user. If you can get the person's social number (personnummer) and their 6-digit code, then spoof their device (probably the easier part) you can basically take over their life in Sweden.
- vlovich123 8y agoU2F & authenticator apps are way better than cellular. Cellular provider companies suck at infosec in massive ways.
- CorvusCrypto 8y agoPretty much my hope. If it's so easy to snoop on cell traffic my hope then is that the app communication is encrypted using modern standards and airtight. Though I'm sure you're right since these apps are more under the microscope. It's probably fine.
- vlovich123 8y agoI had my Uber account hacked even though it had SMS 2FA enabled (from Russia as best I could tell). Now maybe there was some flaw in Uber's implementation but I don't trust SMS 2FA. Talk to any competent security researcher - SMS 2FA is only mildly better than no 2FA. The fact that cellular traffic to this day isn't encrypted properly[1] even though LTE was supposed to should indicate just how horrible cellular providers are at infosec & what happens when they drive security requirements. [1] https://arstechnica.com/information-technology/2018/06/lte-wireless-connections-used-by-billions-arent-as-secure-as-we-thought/ https://arstechnica.com/information-technology/2018/06/lte-w...
- ahje 8y agoBankID should be safe, as the communication can be secured by other means like HTTPS/TLS (assuming it's still an app/applet -- haven't used it in many years). The article is about the basic communication between the phone and the cell tower, which has other issues.