11 ms·
It’s time to stop using SMS for security
- lholden 6y agoThe URL is giving an empty page for me, so I'm afraid I can't really comment on the content of the article itself. With that said, people should fear any site/service that uses SMS for anything security related. SMS 2fa is a fairly common vector for compromise. It can be nice for a "data feed" though. Like, getting an update on the status of your delivery driver. Though, this can also be really annoying when say... your old college starts spamming you with stuff... which I got to experience this weekend at 1am. :)
- tjs8rj 6y agoWhy is this a download? My covid project was an SMS news API completely controllable from your phone and delivers short news summaries on any topic scraped from across the web (www.zipnews.io). While fun and it has several paying customers, the SMS can be somewhat expensive to send. The strength is that everyone with a connected cell phone can access the API.
- givehimagun 6y agoMy bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let's do start to move away - yes!
- 177tcca 6y agoShould be optional. I feel equally threatened by a potentially weak bank app running on my phone all the time as I would my carrier giving away the keys to the castle.
- boring_twenties 6y agoIf only there were any perfectly good open standards for 2FA that were implemented by numerous free apps and/or secure hardware tokens...
- account42 6y agoTOTP is not good enough for banking where you really want to confirm specific transactions, not generate codes that an active attacker intercepting your session could use to do anything.
- boring_twenties 6y agoFair point, but if one declines to install their proprietary apps it just falls back to SMS verification which is obviously terrible. Kraken (a cryptocurrency exchange) allows you to set up one TOTP token for regular logins, and another, separate one for withdrawals... obviously not as good as individual confirmations but still a heck of a lot better than SMS!
- stonogo 6y agoIt is optional. I'm a USAA customer as well, here's a screenshot from thirty seconds ago: https://i.imgur.com/boA4dc1.png https://i.imgur.com/boA4dc1.png
- bawolff 6y agoEmail is much worse than SMS.
- akvadrako 6y agoIt could be better if the sender's SMTP server forced the use of TLS. Most emails are now sent encrypted but it isn't usually enforced. If your control your own receiving server then it would be hard for someone to intercept the message.
- bawolff 6y agoThat's not why its bad. Its bad because 85% of the usecase of 2fa is people using bad passwords. If you use a bad password in one place, you probably are also doing so on your email.
- grep_name 6y agoWhat did they switch to? I've been wanting to use my u2f token for my bank account for awhile but haven't seen any that support that yet
- slovette 6y agoSo, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of how using SMS as part of a layered security verification is somehow unacceptably vulnerable.
- sildur 6y agoThe hatred is because it costs 16 dollars to take over a number: https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-16-dollars-sakari-netnumber https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
- mysterydip 6y agoEven easier are the sites that do this: "Please enter the phone number where we should send your one-time 2FA code: [_______]" I've had that happen on more than one site. Surely anyone who stole my password would just put in their own number?
- elcomet 6y agoThey would surely compare the number to the one they have registered, right ?
- sodality2 6y agoYou'd think they would make it more clear ("verify your 2fa number"). Maybe they want to bait criminals into entering their own or something.
- whatastory 6y agoGoogle oftentimes doesn't. One of my accounts requires a phone number to verify every single time I login. I have no clue why, and it accepts absolutely any phone number. I have no clue what the purpose is aside from forcing me to give sensitive information to other people when my phone isn't available or I'm traveling (which I've been forced to do already).
- fomine3 6y agoYahoo! Japan, One of the most famous website in Japan, forces users to use insane auth method: SMS 1FA. It even accepts phone number as login ID. This is really stupid.
- Arkanosis 6y agoEDF, the largest electricity provider in Europe does the same in France. Actually, it even manages to do a bit worse: 1FA using SMS or email, but choice is left to the potential attacker. I've spent countless hours trying to explain them the issue in 2019 and gave up as nobody cared.
- neolefty 6y agoWhat's the incentive for attackers?
- unscaled 6y agoIt's a rather recent thing, and it's touted as a security feature. To be fair, Japan seems to be safer than most of the world when it SIM swapping (there are pretty strict identification requirements defined by law) and for porting phone numbers between SIM cards. I also never heard of any case of attacks against SS7 or other part of the telecommunication stack in Japan (I'd be happy to know if someone does) That being said, a certain class of SIM cards (SMS-only cards, without voice functionality) is exempt from most of these strict checks as far as I know, and there are other technical vulnerabilities that are probably just waiting to happen in Japan before they're taking seriously. I'm a little bit surprised that Yahoo! Japan went for SMS as the only authentication method, since their one of the main sponsors of the FIDO Japan WG.
- dgellow 6y agoLiving in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?
- colordrops 6y agoUS was the last to start using SMS and will apparently be the last to stop. The US was behind the curve because it was one of the few places in the world where local calls were free so people didn't bother with SMS for a long time. As for why it's still here, my guess is that the messaging space is extremely fractured here and it's the only text messaging someone is guaranteed to receive.
- calvano915 6y agoAnd SMS was stupidly expensive like 10 cents a message for years. It wasn't quickly adopted because it was not a good value.
- erfgh 6y agoNot all people have or want smartphones.
- realusername 6y agoDon't know about the US but I haven't seen anybody using classic GSM for years now...
- blowski 6y agoI wonder how much of an overlap there is between those still using classic GSM phones, and those who listen to vinyl records.
- southerntofu 6y agoI know plenty of folks using those. Most people do it by choice because the hardware is more reliable and the battery more durable, but some also do it because their planned-obsolete smartphone broke down.
- jfktktmgn 6y agoWhen dis medium become a paywalled site? Do writers on it know that you can only read 3 articles before you are required to create an account and login? (like pinterest)
- sgift 6y agoUse a private window to get around this. It's not a very advanced mechanic (yet).
- eingaeKaiy8ujie 6y agoCookie Auto Delete solves the issue
- selfhoster11 6y agoThe title is misleading. This is not in fact "stop using SMS for anything", but "stop using SMS for security purposes". There is a great reason why SMS should still be in use: nothing interoperable exists with an equal adoption rate. I will not rehash the usual argument about WeChat and Whatsapp, there is plenty of discussion about them.
- herbst 6y agoAs someone who does not keep a fixed phone number this reality really sucks. But i dont want security trough something i dont own, and there is no way to actually own a phone number
- sdfhbdf 6y agoThe link is pointing to 0 content length page with no content type header so it behaves weirdly in for example Safari trying to download.
- eythian 6y agoIn firefox for me, it's just a blank page and the headers returned seem mostly to be from cloudflare rather than medium.
- fwn 6y agoThe website does not currently work for me. Here's a working archive.org mirror: https://web.archive.org/web/20210316074533/https://lucky225.medium.com/its-time-to-stop-using-sms-for-anything-203c41361c80 https://web.archive.org/web/20210316074533/https://lucky225.... If that mirror keeps hiding the text, blocking all inline scripts with uBlock Origin solved it for me.
- deleted 6y ago[deleted]
- zimbatm 6y agoDid anybody experiment using Twillio (or similar) to receive 2FA SMS? There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-day number.
- Jenk 6y agoA few of my employers use(d) Twilio for 2FA SMS, one of whom are UK FCA regulated.
- Nextgrid 6y agoA lot of services reject numbers from known VoIP providers as a way to reject fraud (and I guess prevent people from defeating number-based marketing/advertising tracking by using unique numbers?). You can work around that by using lesser-known providers. In the UK, Andrews & Arnold (https://www.aa.net.uk https://www.aa.net.uk) provide UK mobile numbers which don't seem to be rejected by anything.
- closeparen 6y agoIt’s about making bans for fraud and abuse more expensive to repeatedly evade. The expected value of a few extra spam messages is lower than the cost of a new number.
- 4lun 6y agoI tried this for a bit, but it turned out a number of services (Google, Facebook) would fail (silently) when sending an SMS to Twilio numbers. It might no longer be true as there was a Twilio support page that confirmed this behaviour but is now just a 404[0] (though you can see a mention of it on StackOverflow[1]) [0] https://support.twilio.com/hc/en-us/articles/223134367-Sending-messages-from-Facebook-and-other-services-to-Twilio https://support.twilio.com/hc/en-us/articles/223134367-Sendi... [1] https://stackoverflow.com/a/55852784 https://stackoverflow.com/a/55852784
- ddevault 6y agoFor the love of God, stop using Medium. I don't understand how authors don't know better by now.
- tony0x02 6y agoWhy?
- ddevault 6y agohttps://l.sr.ht/XhOm.png https://l.sr.ht/XhOm.png If you actually want people to read your content, then don't put it on Medium. Not to mention that it's bloated as hell, requires JavaScript, burns batteries on mobile devices, and is full of loathesome spyware software.
- yabones 6y agoAgree. It's also one of the annoying websites that breaks scrolling with yet more javascript crap. It's a lot of cruft for a text-with-images page that hasn't changed conceptually since 1995.
- audience_mem 6y agoWhat was the conceptual change that occurred in 1995?
- john-doe 6y ago“It’s time to stop using Medium for anything”
- upofadown 6y ago"Identity management is hard. I know, let's just let the phone company deal with it!" Later... "Oh no! The phone company is doing a terrible job of solving our identity issue!"