6 ms·
Security Analysis of SMS as a Second Factor of Authentication
- blakesterz 6y agoI feel like this is an important clarification from the end of the intro: "This article provides some insight into the security challenges of SMS-based multifactor authentication: mainly cellular security deficiencies, exploits in the SS7 (Signaling System No. 7) protocol, and the dangerously simple yet highly efficient fraud method known as SIM (subscriber identity module) swapping. Based on these insights, readers can gauge whether SMS tokens should be used for their online accounts. This article is not an actual analysis of multifactor authentication methods and what can be considered a second (or third, fourth, etc.) factor of authentication; for such a discussion, the author recommends reading security expert Troy Hunt's report on the topic."
- fulafel 6y agoIt would give a more credible impression without the exploit vs vulnerability terminology confusion (that repeats many times in the article)
- WhyNotHugo 6y agoI think the worst is when companies force you to leave SMS on as a fallback. On stripe, I use a security key. Someone has to either steal my keyring, or steal my backup key. But I'm force to leave SMS on as a fallback, so really, the weakest link is there, and a potential cracker only needs to break this extremely fragile insecure system, and completely bypass the security key.
- postalrat 6y agoI assume it's their attempt at reducing support calls.
- R0b0t1 6y agoSo is stripe liable for your account being compromised due to SIM hijacking? The telephone companies claim they're not liable, and you certainly aren't liable, so who is? This smells similar to banks not needing to check check signature anymore.
- snarf21 6y agoI agree. SMS is an attack vector, not an authentication.
- Arkanosis 6y agoEven worse is when companies force you to use SMS as the first and sufficient authentication factor. EDF (the biggest European electricity provider) does that in France.
- exabrial 6y agoPlease, no more SMS Authentication. Hacker news readers are in a unique position to prevent this "feature" from entering products. Let's work on putting this idea out to pasture. TOTP, while not perfect, is an improvement. The protocol could be improved to provide protection against proxy attacks, but the point I'm trying to make is that your regular user can use TOTP. I've successfully set it up for my parents (both closing in on 70years old and are not tech-savvy) and they have no issues using it. Personally I use a hardware U2F key everywhere I can. With the newest version of Safari Tech Preview _finally_ supporting U2F, I'm hoping we see some deeper market penetration.
- metalliqaz 6y agoI have something like 200 accounts stored in my LastPass account, and my main problem now is that I have no idea which of my accounts use SMS for 2FA. There was a period of time where 2FA was synonymous with SMS, and a further period of time where using a hardware key or authenticator app required setting up SMS first. I'm trying to clean it up, but it's a mess out there. Some accounts require a phone number and don't have an option to disable SMS as a option.
- AnonC 6y agoWhen I researched on the best/popular TOTP apps some years ago, I found Authy being highly recommended. When I tried it, I discovered that it first needs a phone number that it verifies through an SMS code. I promptly removed it and switched to another one (called OTP Auth).
- kevincox 6y agoWhat I would like to see is software U2F keys that browsers sync for you. I'm sure this would upset some people but I don't think the average user has the ability to understand and maintain a set of security keys. Furthermore you have to maintain the keys separately for each site. This means that I only use 2fa for a small number of valuable sites, because the pain of rotating the credentials is huge. However most people I know have browser sync set up. They are using it for passwords. It would be great if it could manage a security token for them and allow authentication to websites without risk of leak.
- 6y ago
- skrowl 6y agoEmail is also a very weak form of 2nd factor that's more popular than it should be.
- easton 6y agoNot if you are securing your email with a security key and enforcing that you can only access it from devices that meet security guidelines (as is easy to do with Office 365 and almost easy to do in GSuite). Unlike SMS, where you could lock down your phone and take every precaution and an attacker could still compromise your SIM via your carrier.
- lowcodetv 6y agoHow so? (So I don't duplicate: https://news.ycombinator.com/item?id=25047668 https://news.ycombinator.com/item?id=25047668)
- upofadown 6y ago>Email accounts have become, over the years, not only large repositories of highly sensitive and private data, but also single points of failure for digital footprints on the Internet. This is really the key issue here. Passwords are fine if you give people some place to keep them. >...it became widely acknowledged that passwords should be highly complex in order to maximize their entropy and, thus, substantially increase the amount of time it would take to crack them. This is only true if people reuse the same password for different sites. Otherwise the site can rate limit brute force attacks to the extent that even completely trivial passwords are OK. I dunno, it seems that in most cases second factor auth is not really needed. We need to address the actual problem, not attempt to paper it over by dumping stuff on top. The "let's just let the phone company do the identity stuff" approach is a good example of failing to deal.
- orev 6y agoMFA wouldn’t be needed in a perfect world, but that world clearly doesn’t exist, despite 50 years of pleading with people to pick good passwords and manage them correctly. At some point you just need to look at the evidence and find another way to accomplish your goals.
- motohagiography 6y agoSMS 2FA is weak, but it does two things: it shifts the attack from a passive opportunistic one to a targeted one, and, 2. in unionized environments you can add a second compliance factor without distributing new devices, "training" people to use TOTP apps, or "forcing" people to install an app on their personal devices. That is the big cultural reason why SMS 2FA is going to be with us for a while. Sure, use TOTP and FIDO tokens for systems people, but for institutions with thousands or tens of thousands of employees, SMS 2FA is still economical and will still be with us 5-10 years from now. It's the new passwords. The smart thing would be for MSFT/o365 to give you the option to switch to a TOTP token and other authenticators with a better experience so people can switch organically. Most security people still don't distinguish between authenticators and identities, as federation concepts like identity providers are still in the rarefied space of enterprise. Identity isn't well thought out either because it's a legal concept, and like most tech risk and liability, if anyone read the fine print they'd never use it. SMS 2FA is basically a ritual that allows people to agree to ignore risk.
- irjustin 6y agoAgreed with this analysis. Trying to teach my parents now to use a Authy, Google Auth, 1Password, LastPass is pretty much a non-starter. I'd be getting calls every other day. SMS 2FA allows my parents to considerably shrink their attack surface without a high barrier to entry.
- gruez 6y ago>2. in unionized environments what is meant by "unionized" here? It doesn't seem to be related to labor unions.
- motohagiography 6y agoSpecifically, in unionized environments introducing new technologies and methods no matter how seemingly trivial creates an obligation for formal job training. Setting up an hour of training for 5k+ people on how to install and use Auth0 is way more expensive than just sending someone an SMS. There is no implicit responsibility to adapt to change. If an employer wants employees in a bargaining unit to use their own mobile devices and install a TOTP app on them, employer has to pay, and then the responsibility for it working needs to be established. In normal environments, you just say "we use this here," and users figure it out. If it's organic bottom-up adoption based on the option, it works, but if you impose a change, it creates admin overheads.
- m3nu 6y agoHow about using virtual phone numbers (Twilio, Google Voice, etc) for SMS 2FA? Any better than a real SIM for services that don't support other 2FA options? Should eliminate OTA and SIM swap attack vectors from figure 2.
- Uhrheber 6y agoThe main reason why companies like SMS 2FA: It costs next to nothing, and it shifts the responsibility to the customer. Your account got hacked? Not our problem, we have 2FA. Must've been your fault.
- jiveturkey 6y agothe main reason: customers choose it over other options.
- jiveturkey 6y ago> Regardless of the critical nature of an online account or the individual who owns it, using a second form of authentication should always be the default option, regardless of the method chosen. Couldn’t disagree more. This is oversimplification of a complex subject.
- PaulDavisThe1st 6y agoCapital One continues to only make SMS available for 2FA. I had to close my account(s) with them last year when they refused to allow me to use my wife's phone for this purpose (since I don't have one). Their loss, not mine.
- dvirsky 6y agoThe worst thing about SMS authentication in terms of UX is what happens when you're outside your country. I moved countries recently, but I still need to do things like retrieve tax statements etc. Some companies only support SMS as a second tier authentication method (some at least allow you to use email as an alternative), some won't allow you to change to a foreign number, some will not be able to send you a text if you're in roaming mode abroad (I keep my old SIM active just for that).