7 ms·
2FA over SMS is fine. It’s not a terribly strong second factor, but it’s decent, and far better than nothing. The problem is when companies implement 1FA over
by mikeash 7y ago
2FA over SMS is fine. It’s not a terribly strong second factor, but it’s decent, and far better than nothing.
The problem is when companies implement 1FA over SMS and call it “2FA.” That is a catastrophically had idea, and unfortunately it confuses people into thinking that 2FA over SMS is somehow dangerous.
- lotsofpulp 7y agoIt's not fine, considering the zero cost of enabling TOTP 2 factor authentication. The only reason I can see for why companies don't give the option for TOTP is to force people to hand over phone numbers so they can be tracked, and in the process make the system less secure.
- rolltiide 7y agoJust one lawsuit away from it never happening anymore
- crankylinuxuser 7y agoSo whats the procedure for someone to recover an account if the 2fa is busted/lost ?
- lotsofpulp 7y agoWhen you setup TOTP 2FA, the application should offer a few one time use codes (google offers 10, for example). These can be copied and stored safely somewhere. If you lose the one time use codes, then you're screwed. But that's the risk you face if you want the most simple and most secure method.
- WorldMaker 7y agoAlso, most providers allow you to setup multiple simultaneous TOTP devices (and those that don't, should). On my personal TODO list is setting up a "safe deposit box" TOTP device sometime.
- driverdan 7y agoWhile you're correct it's not fine, not everyone has a smart phone or a TOTP device. There are some cases where SMS makes sense as 2FA since it's a reasonable compromise between having no 2FA or a TOTP device.
- lotsofpulp 7y agoMy claim is that SMS as the only 2FA option never makes sense. Wherever 2FA is enabled, a TOTP option (or equivalent that doesn't rely on third parties) should be provided.
- badrequest 7y agoYou don't need a smartphone or 2FA device to generate TOTP codes, and in fact, can use applications like Bitwarden. SMS is obviously not adequate, or the Jack Dorsey wouldn't have been hacked.
- mikeash 7y agoTwitter doesn’t use 2FA over SMS. Dorsey’s hack doesn’t tell us anything about that.
- WorldMaker 7y agoMost feature phones can also easily run a TOTP application (and have/do). There are J2ME TOTP applications that will run on hardware far back into the ancient past. There are all sorts of fun TOTP apps in the AdaFruit, Arduino, RPi hacking worlds. The algorithm is rather straightforward. The "hardest" part is the SHA1 hashing algorithm and people have written versions of that for just about every hardware under the sun, including 6502 assembly. (Hmm, an old Game Boy would make an amusing TOTP device. I should add that to my list of possible future hack project ideas.)
- Kalium 7y agoI can see more mundane reasons for SMS second factor. In some places, SMS is simply what people are accustomed to, and the idea of using an app feels like a weird intrusion. Couple this with a PM saying "What if someone changes phones? SMS is more convenient and everyone already uses it anyway". Add a couple of years of SMS-factor, and it can quickly become considered good enough and no more work on MFA is required. It doesn't take nefarious motives.
- deleted 7y ago[deleted]