7 ms·
No doubt because Jack Dorsey was SIM jacked[1]. SMS 2FA is incredibly insecure. [1] https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-dorsey-hack.htm
by olliepop 7y ago
No doubt because Jack Dorsey was SIM jacked[1]. SMS 2FA is incredibly insecure.
[1] https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-dorsey-hack.html https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
- GhostVII 7y agoI think SMS 2FA is fine for the most part, so long as you have a decent password, the problem is when companies introduce recovery numbers and make it back into 1FA
- lotsofpulp 7y agoHow is it fine for the most part when it’s been shown that thousands of employees working at the mobile network have the ability to forward your number thereby rendering the 2nd factor useless? More importantly, there simply isn’t a reason why TOTP, a superior actually secure 2nd factor that doesn’t rely on a third party, can’t be offered, unless you want to force the user to cough up their phone number so you can track them.
- FabHK 7y agoThe attacker would have to steal the password and SMSjack someone; that’s a fairly tall order (maybe feasible for targeted attacks, but it should be sufficient to thwart opportunistic attacks.) The problem is that many sites allow password resets with the SMS, thus rendering it 1F, as GP said.
- GhostVII 7y agoI think it's fine because in order for someone to hack me if I have true 2FA authentication with SMS, they would both have to both get my password, and do some kind of social engineering attack to get access to my messages. If you have a secure password already, that is probably good enough security for the vast majority of people. Just because the second factor can be compromised, doesn't make it useless. Pretty much any security mechanism can be breached, it's all about increasing the difficulty of an attack until it matches the value of what you are trying to protect. SMS 2FA protects you against untargeted attacks like credential stuffing, which is probably sufficient for 95% of people.
- oefrha 7y ago> they would both have to both get my password, and do some kind of social engineering attack to get access to my messages. You must have not followed any SIM-jacking story, which is the point of this entire thread. 1. They don’t need your password because their goal is a password reset through your recovery phone, or recovery email address “secured” by a recovery phone. 2. They do social engineering on telecom employees (or outright buy them out for a pittance) to not only get access to your messages, but take over your entire link to your cellular network. You’re not involved in any of this. TL;DR: the second factor makes you less secure, not more. It’s a downgrade from a secure password. It makes you defenseless.
- GhostVII 7y agoAs I said in my first comment, a recovery numbers turns it from 2FA into single factor. Obviously that is less secure, since a phone number is generally less secure than a password. I'm talking about true 2FA over SMS.
- tylerhou 7y agoRecovery numbers should be stored somewhere safe, like your house. If your attackers have access to your house they could beat you up with a baseball bat instead of going through the trouble with finding your recovery codes and phishing your passwords.
- scottlocklin 7y agoRecovery numbers are recovery telephone numbers. If they sim-swap you, they have your telephone number. The end. Virtually all email accounts and online services tie themselves to your damn telephone number, and there are tens of thousands of people in each phone companies who can move your number.
- tylerhou 7y agoOh, I thought you meant backup 2FA codes: https://support.google.com/accounts/answer/1187538 https://support.google.com/accounts/answer/1187538
- oefrha 7y agoTOTP is great for you and me, but the average Joe totally does lose their phone and get locked out. Forget recovery codes, what the hell are those, they can’t even keep track of passwords. Authy provides encrypted backups you say? See “can’t keep track passwords”. Don’t even get me started on physical security keys. I could hardly even convince myself to use one, let alone always having at least one backup. Imagine asking my mom to do that. At the end of the day, the average Joe needs a recovery mechanism that’s not tied to their memory and doesn’t make their everyday interactions a pita. Phone number is just one step below government IDs (which people would be uncomfortable to supply for most sites) and the challenge response could be easily automated, making it ideal. It’s being ruined because of the incompetence of telecom operators. I wonder if requiring physical appearance with government ID for a SIM change, and making fraudulent SIM issuance a fireable offense would drastically cut down on SIM jacking. (Before anyone points it out, I do envision fraudsters applying for telecom jobs just to do this.) Now, I’m not arguing TOTP without recovery phone number shouldn’t be an option. I opt into it whenever possible.
- romwell 7y ago>Don’t even get me started on physical security keys Well, I haven't seen a single person who wouldn't have one. We use them for cars and houses, though. And credit/debit cards, I bet you have them too. It's a physical security key to the ATM. Classic 2FA spirit: something you have (the card) + something you know (PIN code). The point is, people don't have problems with physical security keys. Programmers do (and hardware vendors) do, which means no standards and clunky UI.
- oefrha 7y agoPhysical key keys go into designated keyholes, and give you physical access to something. Physical cards go into dedicated machines, and give you access to a physical transaction, cash, deposit box, etc. Physical objects for physical access. Physical U2F keys get in the way of all-digital flows. They also need to interact with all kinds of non-dedicated devices, something they do a less than stellar job of. Bluetooth and NFC keys are young, setup process isn’t great and reliability seems to vary; USB keys require a USB port which might be occupied by other things or available only in another physically incompatible shape.
- Iv 7y ago2FA is more secure than 1FA as it takes more efforts to break. It is enough for many people, but targets that are worth the money and risk of bribing a phone company's employees may need additional security. Breakable != useless.
- fulafel 7y agoReally 1/2 FA.
- cryptonector 7y agoWhat part of SIM-jacked did you not understand? It's not about your password. It's about social engineering. Bad guys call their buddies at some mobile phone co. and get your number switched for a few minutes, then they call your bank and get them to change your password which they do because they trust SMS 2FA which now goes to the bad guys, and then they take your money, and you find out much later. Password quality has zero to do with any of this.
- tzs 7y agoYou seem to have missed part of his comment: "the problem is when companies introduce recovery numbers and make it back into 1FA".
- rdl 7y agoI agree when SMS 2FA is strictly in addition to a password, and the phone number isn’t used for account recovery (or marketing), it is theoretically no worse than just a password. The problem is it still with great 2FA, and the kind of sites which do SMS 2FA are exactly the ones incompetent enough to turn it into SMS-based password recovery which is worse than no 2FA. (The other use of SMS which is somewhat legitimate is as a cost gate to create new accounts. Generally creating a new SMS receiving phone number costs someone more than a new email, so if you want to crudely limit creation of large numbers of accounts by individual users, it can be an option.)
- ksec 7y agoI still dont understand this, if SIM Swapping were the problem then it isn't SMS 2FA that is insecure, it is the telco themselves, and specially US Telco. In many other part of the world, Switching Sim ( SIM Swapping ) requires to show proof of identification, as well as written form and signature. And any CS accessing customer information are instantly logged, there is no way paying $1000 dollar to change or SIM Swap without going through the proper procedure, ( Should there be one ) and they will be fired for any misconduct. SMS might not be the best solution to security, but for average Joe, that is near 4 billion of Smartphone users they are better than nothing. May be had Apple created their own MVNO this problem could be solved.
- rando444 7y agoSMS 2FA is insecure because companies implement it in a way that it becomes one-factor. Forgot your password - reset your password - get an SMS When there is no second factor involved, it's not 2FA despite people calling it that.
- yabadabadoes 7y agoI agree the problem is that implementation of a backup for 1FA ends up coming back to the phone. But often the target service has no certainty of which mechanisms are going where. They send to your email.. They use TOTP. They use Oauth, etc, etc. What other things accounts go back to either your SIM or someone stealing your phone, SIM and all? Even U2F will fall down this hole soon since everyone wants to implement it on phones! Will the attestation certs for phones say multipurpose device that is probably involved in other factors?
- balboah 7y agoYou can also show fake ID at a competing telco sales point and tell them you want to move the number in Sweden. Happened to me that depending on which provider the call was coming from, sometimes it would reach me and sometimes not.
- phicoh 7y agoAs far as I know, the service telcos provide is the ability to make calls, receive calls, send text messages, receive them, etc. Telcos don't get paid to securely provide SIMs. They make hardly any claims regarding the security of your calls, text messages, etc. So it is rather odd to hold telcos reponsible for the failure of some security mechanism they where never part of.
- rags2riches 7y agoPassword reset by SMS is not 2FA. It's a single insecure factor.
- paulcarroty 7y agoYeah, a lot of banks still use SMS 2FA and even don't let you login/approve payment without SMS verification.
- Faark 7y agoI wish. Mine just removed the SMS option. I now have to install an App that wants full telephony access. And is obviously only available in the google play store, requiring me to accept google terms. Is it safe? I don't know. Doesn't seem to be a widely used standard. Haven't found technical details. Only a mention of "cryptography" in the marketing material. So yeah, I don't really feel much safer.
- paulcarroty 7y agoGive them the access to your Android-x86 VM first :)