3 ms·
I'm not clear on how #1 is related to the SIM swapping problem. Yes, I encounter a lot of services that put way too much weight on phone number (maybe because
by tomComb 7y ago
I'm not clear on how #1 is related to the SIM swapping problem.
Yes, I encounter a lot of services that put way too much weight on phone number (maybe because phone number has some legal status) but not the big platforms. For Google, at least, they go well beyond making other methods available - they really seem to encourage/push users to use better second factors.
In my experience the big platforms are the least guilty. My Google account/data is by far the most secure account I have online or off.
- iudqnolq 7y agoI'm not sure if - given my threat model - it makes sense for me to disable phone based 2FA on my Google account. I'm not prominent at all, so I don't expect to be individually targeted. I store 2FA tokens in my password manager (1Password) so that I could recover from my phone being stolen or damaged. However, I don't have a printout of my 1Password backup code stored under my mattress (or in my desk) because I don't completely trust my roommates. If I had my phone and laptop with me and was mugged, or if both were damaged at the same time, I would be locked out of everything if I didn't have phone-based 2FA. With it I could get a replacement SIM card, regain access to my Google account, and then use that to bootstrap password resets to everything else. (For the same reason, my only duplicate passwords are memorized randomly generated passwords for phone, primary Google account, and laptop (and there is some duplication between them))
- deanmoriarty 7y agoWhy not simply save the backup codes on a couple usb keys encrypted with a reasonably long password that you can remember, and leave one at home and one in another geographical area (e.g. parents house)? I do that and feel pretty good in completely ditching SMS 2fa. Once a year or so I plug the USB keys to check they still work. I, like you, don’t expect to be a target and have a very minimal social media/web presence with my real name.
- iudqnolq 7y agoAny advice on finding a small object you need infrequently in say a parent's house? I have a poor track record with that sort of thing that makes me hesitant.
- deanmoriarty 7y agoHaha no. My dad has a lock safe where they store jewels and important documents, and I just put it there.
- thephyber 7y ago> I'm not clear on how #1 is related to the SIM swapping problem. If controlling a phone number was not how platforms authenticated users, the impact of SIM swapping would end in someone else being able to run up a cell phone bill. I’m practice, authentication of web platforms is based on the authentication and security protocols of the weakest cell phone provider (because cell phone numbers can be transferred from provider to another provider). We have no comprehensive authentication system, so our security is held hostage to the weakest link in a chain of (email provider, cell provider, platform OAuth provider, commodity web system)