4 ms·
In my opinion, Microsoft's implementation of MFA on Office 365 (at least our instance) is broken. SMS MFA is inadequate and should not be used, the SS7 network
by dillutedfixer 7y ago
In my opinion, Microsoft's implementation of MFA on Office 365 (at least our instance) is broken. SMS MFA is inadequate and should not be used, the SS7 network is apparently trivially hackable in some circles and text messages can be rerouted. So they want us to use MS Authenticator, great. However the 365 login screen always has the "Sign in another way" option in which I can just bypass the Authenticator app and use an SMS text. I cannot remove my mobile number from my profile to disable the option to SMS text because they are worried about me losing access to my app. I don't know if this is a limitation of Office 365 through our VAR or what, but it just seems pointless to offer an Authenticator app if there's an easy way to fall back to SMS and no way to disable SMS. If someone has my password and can reroute my text messages, a fancy shmancy Authenticator app is pointless. If this is not how it is for others with 365 I would love to know that, I hope it's not a limitation or policy put in place by our VAR.
- privateSFacct 7y agoThis. I deal with relatively higher volumes of information that must remain secure. With google, I have hardware authentication device and 10 codes. Every 30 days or so it asks me to plug in the hardware device. Randomly it asks me more often - I have no idea why but no objection. My password is secure as well and only used on google but THANKFULLY I do not need to change it all the time and so I don't have to write it down. This feels like a reasonably secure approach. No SMS text option. The idea that your phone number is the key that allows you to reset all your passwords (no matter how complicated / securing no matter how much sensitive info) is ridiculous.
- smitty1e 7y agoAny redundancy on that piece of hardware? "Two is one and one is none," as the Special Operations folks will explain. Sure, the math is squirrely; but the sentiment is real.
- stouset 7y agoThe recovery codes.
- simonebrunozzi 7y ago> No SMS text option. ... ridicolous Agreed. My Twitter account was recently hacked thanks to T-Mobile's incompetence. [0] [0]: https://medium.com/@simon/mobile-twitter-hacked-please-help-2f65c691edf8 https://medium.com/@simon/mobile-twitter-hacked-please-help-...
- senectus1 7y agoI'm confused... because the whole reason your twitter was able to be hacked was because the SMS option allowed it to be hacked.. They stole your SIM. SMS option was now in their control. SMS is not a secure 2FA option. sure its better than not having 2FA but only a little better.
- Thorrez 7y agoEverything you said agrees with what simonebrunozzi said. SMS is a bad 2FA option.
- mehrdadn 7y ago> sure its better than not having 2FA but only a little better. I'm becoming convinced this is a pervasive fallacy (perhaps not for all users in all cases, but for many). Having SMS as your 2FA potentially makes your phone, phone line, and everything linked to it an attack target. So you might lose a heck of a lot more than you would if they were all unlinked. It depends kind of on what your current security practices are, but I think for many it can well be indirectly risking more damage than it's preventing.
- petjuh 7y agoSomeone who steals your phone needs to have "physical access" to you. A random pickpocket is most likely to steal your phone and they're not interested in your phone. Most hackers never have physical access to people. The intersection between the 2 sets - hackers and pickpockets - approaches zero.
- 7y ago
- djakjxnanjak 7y agoDoes anyone know if there’s a way to prevent your SMS from being rerouted, or get a special protected number? The ability to do this would not mitigate Microsoft’s responsibilities here, but at least it would allow some people to help themselves.
- red_phone 7y agoI'm not a subject matter expert, but a Google Voice number can be used to receive texts and is protected by the relatively robust security of your Google account.
- kortilla 7y agoIf the issue is the SS7 network, that won’t help unless the originating text is also in Google Voice.
- testvox 7y agoThat seems pretty possible though, if SS7 is the only issue then providers of 2factor SMS auth should just have a number on each network and when a 2factor request comes in they should determine what network its being sent to and then actually send the SMS from the number they have on that network.
- gdfiutyer 7y agoUnfortunately, some services won’t accept a Google Voice or any voip number.
- lopmotr 7y agoIf you had that protection, what would you do if your phone was lost/stolen and you wanted the number transferred to a new SIM card? You lose your number forever if it was impossible to transfer. If there's some way to transfer it, like showing your passport in person in the phone company's office, a hacker can pretend to be you and do that too if your account is valuable enough to be worth the risk. Ultimately, you're still trusting the phone company not to assign your number to somebody else, and that's what they're not good at.
- elliekelly 7y agoCan you explain this a bit further? We just switched to Office 365 and I ran into this today but I had assumed user error. So even though I have an authentication key set up there’s always the possibility that a password reset can be authenticated via my phone number?
- quartz 7y agoPretty sure you can remove sms from the 2fac process by going to: My Account > Security & Privacy > Additional Security Verification > Update Your Phone Numbers Used for Account Security And then setting the preferred method to "use verification code from app". Once you finish setting up the authenticator app you can delete your phone number from the 2fac list. At the end of that process you should be left with only having the app authenticator as a 2fac option. See https://docs.microsoft.com/en-us/azure/active-directory/user-help/multi-factor-authentication-end-user-first-time https://docs.microsoft.com/en-us/azure/active-directory/user... for some details, but the MSFT documentation on this isn't very good in general.
- dillutedfixer 7y agoWhen I uncheck Authentication phone I get a red error message: "Configure at least one phone so that if you lose the app you are not locked out of the account." If You are able to remove it, I’m wondering if there is some sort of policy or limitation our VAR is adding to our instance. edit - added quotes to the error message
- elliekelly 7y agoYes, same thing happens to me. I’m the first account (and the only current admin) that purchased all the licenses so I wonder if that’s why. Is your account an admin or do you have any additional privileges? It makes sense that they need at least one phone number on file but there should be a way to opt out of SMS 2FA.
- dillutedfixer 7y ago
- mr_toad 7y ago> However the 365 login screen always has the "Sign in another way" option in which I can just bypass the Authenticator app and use an SMS text. Not sure how that works if they (Microsoft) don’t have your phone number.
- lopmotr 7y agoThese gaps would be obvious if services displayed all their authentication options completely in some graphical or table form. I personally would like a logic circuit diagram showing eg: (password AND SMS) OR (password AND app) OR SMS --> Get in! Then it would be obvious that the password is sort of redundant and it's really less secure than 1FA. It would also be clear what you have to lose to be locked out yourself. Only having 2 factors is not great because that's twice as many ways to get locked out. You really need 3 or more but it's never clear if that's reducing security to 1FA level or not because they don't clearly show you what the account recovery options are.
- gdfiutyer 7y agoApple’s iCloud Accounts are the same now. They now require a phone number for new accounts and there is no way to remove the number.
- 188201 7y agoI don't think SMS is real 2FA, because many site can reset password by SMS, meaning having the phone number = controlling the account = 1FA. So, it is not better but worse to have SMS "2FA" since it depends on competence of mobile provider, which may be absurdly weak at preventing social engineering.