19 ms·
Tell HN: SMS-based two-factor authentication is not secure
SMS-based Two-Factor Authentication is not Secure. I’ve read this before but brushed it off. It wouldn’t happen to me. It did.
I am with Boost Mobile. On Sunday night I received a text message that my PIN was changed. Within minutes I confirmed this to be true on my PC. I used the Boost application on my phone to change the PIN and received a confirmation text.
A few minute later I received a text message welcoming me to Metro PCS.
A few minute later I received emails to my business email that my account security information was deleted from my person email account. They used SMS authentication to my mobile number, that they now have control of to gain access.
A few minutes later I received an email there was an account recovery attempt on my coinbase.com account.
It took less than 30 minutes for these events to transpire.
I've spent about 15 hours trying to get my phone number and my email address back to my control.
I've accumulated a list of eight other people in the Boost Mobile Reddit.com forum where the exact same thing happened to them.
I filed a police report and filed a report with the FCC. I received a response from the FCC that they have started the inquiry and contacted Boost.
I finally did get my cell phone number ported back to Boost. I have not gained control of my Microsoft email address.
I didn’t realize I could only have messages of 2,000 characters. So I will wrap this up.
When account settings were changed, Coinbase gave me a link to lock my account, Microsoft gave me a link to log in to my account, which I no longer have control of.
Unlike competitors, which allow pins from 6 to 15 characters and for accounts to be administrative locked, Boost offers none of these options. The last Boost operator suggested I pick a more secure PIN.
I am calculating my losses and documenting all interactions.
- jsnell 5y agoYour problem is not with SMS as a second factor though. (Unless you think the attacker had your password as well). It is with the use of SMS as a single recovery factor. The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene.
- raesene9 5y agoFWIW I wouldn't regard SMS as a good 2nd authentication factor either, for the same reasons as this issue, it's too easy to get a carrier to transfer a number to an attacker. Where it's used as a second factor, this still has an impact which is, if an attacker can get the password (and there's been enough breaches and keystroke logging for that to be common) they can then grab the number to get full control of the account. TOTP or hardware tokens don't generally suffer from the same problem.
- addingnumbers 5y agoThe problem is with most online services, the only second factor allowed is SMS. If you see it as "don't bother, they can just steal your SMS number" instead of "that's slightly better, at least now they can't get in without stealing my number" then you're not thinking about this reasonably. It's inane to neglect to use SMS where it's the only second factor available. The exception is when a service allows you to use SMS alone for password resets, which isn't MFA, is 1FA with a weaker factor than a password. What would you think if someone took you for a joyride in a classic car and said "shoulder belts would be so much better than these lap-only belts, so don't bother buckling up!"
- raesene9 5y agoI didn't say it was worse than just password, I said it was a bad second factor, which it is. SMS 2FA was vaguely reasonable before TOTP applications and smartphones capable of running them were widely available. That's no longer the case.
- iso1210 5y agoWhat's the recovery process when your phone gets stolen, or you drop it?
- raesene9 5y agoFor me, for TOTP, I use one that backs up to iCloud. that obviously weakens the security, but increases the availability. With some applications, you can add additional devices, so you can add multiple, if you have 'em.
- staticassertion 5y agoIf the argument is "but you still have a password" it really kind of shows how weak SMS 2FA is. Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe - it is itself just a strong auth mechanism, whereas SMS is adding extremely questionable value between the ability to phish SMS 2FAs or hijack the number. Even in a situation where the attacker would have needed the password too, consider how much more vulnerable you are now that they have a significant piece of your auth - could they leverage that to social engineer an account recovery? Phone numbers are terrible at conveying identity, unfortunately, so bringing them into the "who are you" heuristic is kinda just a net loss.
- baybal2 5y agoI want warn people about U2F. U2F is only an authentication tool, not security/encryption one. If you have your smartphone/browser/pc pwned, you are even more screwed than with offline key table/token. For something truly security critical, you need security against MITM on your own device, which only leaves smartcards as an option.
- StavrosK 5y ago> Compare that to a U2F token where you can very reasonably remove the password entirely and still be just as safe Not only that, but you can remove the username too: WebAuthn supports a "usernameless" mode where you press "login", touch your authenticator and you're in.
- withinboredom 5y agoBut that isn’t portable. If you lose your device or just reinstall the OS, you can never login again.
- StavrosK 5y agoSure, but that's why you add multiple devices/keys to your account. Reinstalling the OS should be fine. I'm very much looking forward to password managers acting as soft-WebAuthn tokens so they can hold a simple private key and log you in to sites automatically by answering the login request. That way, you only need to unlock your password manager and you can log in to any site without a u/p. Just don't get your password manager stolen, I guess, but that's already the case.
- StavrosK 5y ago> The very things that make SMS a uniquely good second factor make it an awful only factor. Use of SMS for account recovery should in general (or at least for important accounts) have a delay (order of days) that allows the real user to intervene. No, SMS shouldn't be a single factor, period. It doesn't prove much, and is insecure, as the current post shows.
- birktj 5y agoThis. SMS is a great second factor and is perfectly suitable to prevent the main attack that you want second factors to prevent: that is if your password appears in a password list for any reason it should stopp anyone from just running away with your account. Note that if you are targeted directly SMS is not going to help you much but in this case maybe your password can (depending on the capabilities of the attacker). Now is SMS the best second factor? Of course not and a proper U2F token will be a lot more secure in many cases but for most people SMS should be perfectly suitable. All this of course requires the auth provider to be somewhat competent and not use SMS as an only factor in any circumstances.
- j45 5y agoSMS will remain vulnerable as long as the mobile accounts that hold them upstream remain vulnerable. One option I’ve heard might be different is to not your your mobile sms on accounts, but to get a voip based sms number. It might leave things at the mercy of a different system but the footprint might be different.
- LinuxBender 5y agoI've tried this, but many companies block VoIP numbers for MFA/2FA. Some don't. This works with LinkedIn, but not any companies I have purchased things from.
- 1cvmask 5y agoThe option for a delay of is great. The option of adding a custom security question/password etc. is even better. The option of completely turning off recovery is also great. The ability to have your solution on multiple devices without a need for a mobile phone number based recovery is great as well. I hate it that Twitter forces you to enter a mobile phone number even when you set up an authenticator code generator as 2FA. Oftentimes the weakest link in most of these services is the account recovery part. When we set up the self service account recovery in saas pass password manager and authenticator we added all of these customizable options to mitigate against potential SIM Swap attacks.
- 1cvmask 5y agoMore details of customizable recovery and backup and restore is available here with visuals: https://blog.saaspass.com/saaspass-password-manager-authenticator-e44b51de46c8 https://blog.saaspass.com/saaspass-password-manager-authenti...
- vitaflo 5y agoOn Twitter you can remove your phone number after the fact tho. In fact most sites that req a phone number to sign up etc allow you to remove the phone number later if you choose.
- cik 5y agoExactly this. Here in Israel, SMS is used extensively as part of a multi-factor authentication system. I also require my National ID. To move my phone number (consent or not) between any phone companies requires an SMS, my National ID, and verification of my ID, and personal details in the government database. SMS by itself is not secure.
- 2rsf 5y agoAnd still numbers are being hijacked even in Israel [1], and even in Sweden, where I live now, I swept my SIM without my ID being properly checked [1] https://www.gov.il/he/departments/news/sim https://www.gov.il/he/departments/news/sim
- cik 5y agoAbsolutely. This is the problem - it's not the ideal method.
- tinus_hn 5y agoYou can’t control some random guy in a provider store giving out a new sim for your account, whether maliciously or because they were deceived.
- fulafel 5y agoThis kind of arrangement is often mockingly, but accurately, called 1/2 factor authentication.
- exabrial 5y agoThere is no situation where it is good at anything.
- sfteus 5y agoI've posted before on here about my experience getting SIM swapped and how quickly someone was able to gain access to a bunch of my accounts. If I hadn't been at home and looking at my phone while it was happening, it could have been much worse, but thankfully I was able to get in and terminate most of their login sessions before too much damage was done. The one thing I distinctly remember was two of my GMail accounts starting the recovery process. Thankfully, that process apparently gives either 14 or 30 days to stop the recovery and secure my own account. Had I not been connected, that may have been my only saving grace, as I was able to secure those accounts and subsequently use them to recover other compromised accounts. The larger lesson for me was to always use TOTP tokens where possible over SMS, and to completely disable SMS recovery for accounts that didn't have a delay on SMS-only recovery.
- vlovich123 5y agoI got my Uber account taken over this way and I wasn’t using my cell for recovery of anything. SMS is terrible for all these purposes
- dheera 5y agoSMS is not a good second factor, even as a second factor. I deprecated SMS 10 years ago and the only way I receive SMS codes is via an online interface that is password access. For most people, SMS fails miserably when you need to change your SIM card or fly to another country, or work out of a place with no cell reception but has wired or wi-fi internet access. That's a big part of the reason why I deprecated it in favor of e-mail, which works flawlessly anywhere in the world you have an internet connection. I only support U2F or TOTP based 2FA and it's upto providers to get with the beat if they want me to use real 2FA.
- an_opabinia 5y agoI sympathize with the user. It's a little mind boggling though. Securing money with a $15/mo phone plan. It's an extremely ghetto phone service. If anyone's to blame, it's Boost Mobile. Cricket Wireless. Pay for a major carrier plan.
- emodendroket 5y agoThis always bothers me. People say "SMS-based 2FA is bad" and then all the reasons they give have nothing to do with 2FA at all.
- rvz 5y agoI made a point about this previously and unfortunately, your situation is exactly the reason why SMS authentication should be avoided, since these sort of attacks are now becoming common. [0] [0] https://news.ycombinator.com/item?id=27311641 https://news.ycombinator.com/item?id=27311641
- UncleMeat 5y agoThat isn't 2FA. That is a single factor recovery process. SIM-swapping only defeats SMS-based 2FA if the attacker also has your password, which is difficult to accomplish if you are using good passwords that are unique.
- Zolt 5y agoI had to remove this detail from my original post as it was too long: Boost mobile is negligent and not following industry standards. Their whole security model is based on a 4-digit pin. At first I thought somebody had a script working its way up through all the combinations at the login screen, but I no longer feel that is the case. The fact that at least nine of us had this same issue within days makes me think there is a wide-spread issue here.
- grlass 5y agoI don't have a source to hand, but I've heard from other post-mortems that in SIM-jacking attack the carrier has been socially engineered into not bothering with the pin, ongoing court cases RE negligence perhaps on-going.
- grishka 5y agoIf they're able to issue a new SIM card without the system requiring them to enter the PIN first, then it's a very terribly designed system.
- mook 5y agoThey have to be able to issue a new SIM card without a pin in the case of a lost phone though. In that case they should probably check government identification, of course, and not be available remotely.
- grishka 5y agoI thought you needed the PIN if you wanted that, too? As in, if you lose your phone and don't have the PIN set up with your carrier, you've lost your number and can't restore it.
- cassianoleal 5y agoSorry you went through all that, and even more sorry that you'll probably be dealing with the fallout for quite some time. I agree that SMS 2FA is not secure and a terrible idea. I've moved countries and my old mobile number has been given out to someone else. I don't even know what accounts I have might be tied to that phone number and I don't have any way to find out. I have had friends message that person without knowing it as well. He could easily impersonate me on WhatsApp and fish for my personal info from those contacts. Luckily, he seems to be a decent person but I not only have to trust this stranger to be honest, but also need to trust that the number stops at him or goes to another honest person if he drops it. Phone numbers are not identity and using it for verifications of this sort is a horrible idea.
- swiley 5y agoNot only is SMS two factor authentication not secure, it weakens the security of accounts it is enabled on. Experts know this (because it's obvious) but large companies like Google continue to insist on using it either because they like the data collection or because they're just covering their asses.
- teekert 5y agoCan you explain how I'm weaker with 2FA via SMS than without 2FA? I agree SMS is not good 2FA but your statement is more extreme.
- Zolt 5y agoIf I didn’t have SMS-2FA enabled, they would not have been able to take control of my email address without guessing the password.
- deleted 5y ago[deleted]
- teekert 5y ago“But we send YOU and sms on YOUR phone number you left in our systems!”
- StavrosK 5y agoBecause companies routinely and silently use SMS 2FA as SMS 1FA.
- ascar 5y agoBut that's not an inherent problem of SMS 2FA. It's just bad implementation.
- StavrosK 5y agoNo, the inherent problem of SMS is that it can be stolen/redirected. Given that, and given that companies are too eager to use it as 1FA, you shouldn't use it. If I'm giving advice to companies, I say "don't use SMS 2FA as 1FA" (well, I actually say "don't use SMS 2FA at all, it's too tempting for a support person to use it as 1FA"), but this thread is about the user, and as a user, you shouldn't use SMS 2FA.
- meowster 5y agoI think crypto companies should block withdraws for a period of time after a password recovery. (OP, you are calculating your losses, but didn't specify what those losses were. Did the theif get your crypto?)
- Zolt 5y agoI have not regained access to my bitcoin account, in part because I have not contacted customer support to do so. I’ve been too busy regaining access and continuing to support my client base. My account is locked, and I am pretty sure my funds are still there. It will be a significant loss, but not devastating as this was my non-primary investment account. I still don’t know the full extent of my losses. So far, my losses are primarily loss of billable time. I am not a litigious person, but I am also going to educate myself as to what ‘pain-and-suffering’ means. Both my personal and business bank accounts are ok. I now understand why banks do not use email addresses as the login id. The thief would not (easily) be able to align my email address with my bank login id. Once through this, I plan disassociate any portion of my login id with my name.
- ThePowerOfFuet 5y agoIf your crypto was stored on an exchange then this is par for the course; rule number one is that if you don't control the private keys, the coins are not yours. You haven't even tried to regain access to it? Instead of spending time on HN you might want to reach out to Coinbase.
- Zolt 5y agoAgreed. Done. "Thanks for taking the time to contact us. We're currently receiving a high number of requests so we may take longer to respond, but our team is working hard to get to every inquiry quickly."
- ysavir 5y ago> I now understand why banks do not use email addresses as the login id. The thief would not (easily) be able to align my email address with my bank login id. This is an important point and one I've been thinking about for years. There's so much discussion about using password managers and good password practices and 2fA but almost no discussion on how using a single identifier to log into all these various services is in itself a huge security vulnerability. If we had different login usernames for each service, gaining access to people's accounts would be that much more difficult. Email should be reserved for communications and not double as a means for authentication.
- bszupnick 5y agoNot only is it not secure, it's not a constant for everyone. I moved countries and I am now locked out of my bank account abroad since they verify logins via OTP over SMS.
- njacobs5074 5y agoMaybe look into whether you can get a Skype number set up to receive the SMSs. Some countries/banks will work with this arrangement. But I feel your pain. It is very frustrating situation to be in.
- ThePowerOfFuet 5y agoWhy cancel your old phone number in that country when you still have a bank account there? I suggest a bank which doesn't suck, such as bunq.
- Ensorceled 5y agoMaybe they didn't know they needed a phone number to maintain access to the account? Let's not blame the victim here.
- ThePowerOfFuet 5y agoThe bank is at least equally at fault, if not more so.
- 2rsf 5y agoif you immigrate, like I did, but still have some pension funds or saving accounts in your home country. Why would I want a local phone line?
- ThePowerOfFuet 5y agoSo your bank can send you the SMS you need to sign in (which in itself indicates their security is poor).
- chris_st 5y agoGot an email from Heroku last night saying they're discontinuing SMS as a 2FA scheme... yay Heroku!
- ncphil 5y agoYep. They've been planning that for awhile, hopefully a case of "leading by example". For me hardware keys (U2F) with TOTP as a backup are really essential. I've purged SMS where I can. Unfortunately, too many (like banks) have stopped at SMS and email as options -- and that only recently. My (insert name of wildly popular open source password manager here) vault is secured by U2F with TOTP as a fallback, and I use its TOTP feature to secure logins for less sensitive services. Someone mentioned building in delays for resets: that's actually how both the US IRS and Social Security roll. Last time I reset SSA I had to wait for a physical letter with further instructions. Inconvenient, but probably a step in the right direction. If government intel agencies weren't so uptight about crypto, we could all have our own officially issued crypto keys by now. But no. The prols can't be trusted -- and don't deserve it anyway.
- chris_st 5y agoFor whatever it's worth, the US government has shown itself to be spectacularly bad at keeping secrets (proof left as an exercise for the reader).
- bouke 5y agoMaking existing accounts less secure by removing a second factor is not “leading by example” in my book. Just make me pick a different second factor on my next sign-in.
- GhostVII 5y agoUnless they are requiring everyone to use 2FA, isn't that objectively worse than having the option of SMS 2FA? I'm sure there are a significant number of people who would just switch back to using a password instead of SMS 2FA rather than having to get a non-SMS second factor, since it is much less convenient than just putting in a phone number.
- PascLeRasc 5y agoFor anyone in the US wondering, Ting and Google Fi both allow authenticator-exclusive 2FA. I’m very happy with Ting.
- sometimesshit 5y agoBut the banks and crypto exchanges are blocking VOIP numbers like Google's
- calltrak 5y agoQuite right. The other thing is people can use fake numbers like https://fakenum.io https://fakenum.io to bypass phone verification!
- LinAGKar 5y agoToo bad there are those that still only allow SMS, e.g. Sony. Patreon used to be the same.
- headmelted 5y agoSony allows TOTP.
- LinAGKar 5y agoApparently they do now. It's about time.
- inetknght 5y agoI lost my Microsoft account years ago. I still get emails from Microsoft stating that there's suspicious activity on the account. I got two just yesterday. Despite that, despite still having access to the email the account is on, I cannot recover the Microsoft account. Despite Microsoft notifying me that the account is still, years later to this day, being abused, cannot use any form of recovery. I cannot access the account with help from support or even after visiting a brick-and-mortar store. It's one big reason that I've long since refused to purchase anything more from Microsoft and have ditched Windows. Good luck recovering your stuff.
- whymauri 5y ago>Despite that, despite still having access to the email the account is on, I cannot recover the Microsoft account. Despite Microsoft notifying me that the account is still, years later to this day, being abused, cannot use any form of recovery. I cannot access the account with help from support or even after visiting a brick-and-mortar store. This happened to me. I was briefly a contractor at MSFT and was able to escalate the issue -- after a few years, these accounts get automatically deleted. It's likely that your account is completely wiped and no longer exists.
- inetknght 5y ago> It's likely that your account is completely wiped and no longer exists. If that's the case then why do I get emails notifying me that unusual sign-in activity is occurring? And, why am I unable to create a new account with the same email?
- saos 5y agoIn the same boat. Really annoyed I can longer access it. The process to recovery is a total joke too.
- paulpauper 5y agogoogle does the same thing Protonmail is the best beacause it does not require backup emmail or SMS, just the username and password and 2fa being optional (but you must have the password), which is how it should be. So many people have gotten hacked through phones and or recovery emails.
- aphextron 5y agoNothing is secure against a determined targeted attack. That's why we have layers of security. SMS 2FA adds a layer of protection against random attacks, and for that it works great. It should never be solely relied upon for high value accounts.
- zachrose 5y agoSMS 2FA isn’t secure, but what about a small retail/delivery business that uses SMS as the only means of authentication? Payment is not done over SMS but separately through cash or Venmo, so it seems like the worst that could happen is a delivery gets nefariously ordered for someone who didn’t want it.
- Avamander 5y agoIt all boils down to the fact that the states don't have a reliable identity verification system. Can't securely recover accounts, have to resort to silly 2FA methods, and so on.
- Zolt 5y agoI forgot to include this in my original post. I use the Microsoft authenticator application to authenticate my account. My mistake was also including my mobile number as an alternative way to authenticate my account. I don’t know if I was aware of this or if Microsoft prompted me for my phone number at one time and I did not think through all the ramifications.
- 1cvmask 5y agoWe set up multiple different types of recovery and backup and restore options for the saas pass authenticator and password manager to let you the individual be able to customize it as you wish. The threat model is increasing for personal use as solely SMS based account recovery is becoming more widespread. The increase in crypto usage is another accelerant. Good luck solving this unfortunate incident.
- dools 5y agoSIM jacking is pretty easy. In Australia if you know someone’s mobile number and date of birth you can port a prepaid mobile. For postpaid accounts all you need is a bill. The barrier is higher than random automated port scans but the value of being able to get access to financial accounts is high enough to justify the investment. I use Authenticator apps wherever I can. Where I can’t, I use a completely private number for 2fa (I run a virtual number product that is like Google voice for Australians to do so http://www.benkophone.com http://www.benkophone.com)
- jokethrowaway 5y agoVery true. I think it's a shame most banks (at least here in the UK) implemented 2 factor auth with sms only just to comply with "strong" auth regulations. Authy on your phone or multiple u2f tokens are definitely better than SMS. I wish computer manufacturers started including tokens with computers, so that at least people would start using them.
- indymike 5y agoThis is really interesting because of a few things: * SMS authentication is not the same thing as 2FA, but people think that it is. * SMS account recovery is convenient for the bad guys. * The fact you got a welcome text from Metro PCS. If that was sent to your Boost device, someone from TMobile (they operate the networks that both Boost and Metro ride on) needs to take a look as that should not have been able to happen. * In order to port a number you have to know the account security question's answer. Boost does have this. Was this bypassed?
- rsync 5y agoYou're thinking about this wrong. SMS 2FA is not for you. They say it's for you (for your security or your protection or your ease of use or whatever) but that is a lie. In cases where SMS 2FA is forced, to the exclusion of all other proofing mechanisms, it is generally because the provider has a brutally difficult spam/scam problem that is complicated to solve. So, instead of solving their spam/scam problem, they just throw some sand in the gears (of their users) and very loosely attempt to piggyback on the physical phone / physical SIM / physical ID confluence that constitutes a "normal user". This is, of course, a very leaky mapping and anyone determined can, of course, work right around this. But it does seem to lessen their (again, brutally difficult) spam/scam problem. The most ironic deployment of this (desperate) technique is Twilio whose own numbers cannot be used for SMS 2FA auth[1] and yet they require a true, mobile (non-VOIP) number to use their own service. [1] Twilio numbers are not mobile numbers. Most SMS 2FA is sent from "short codes" and short codes cannot SMS non-mobile ("voip") numbers.
- loteck 5y agoThis continues to be debated by so many, but like this person, the debate is meaningless in the face of realities. I'd refer everyone back to @taviso's work up of SMS "2FA". [0] The amount of 'splaining going on in this discussion helps illustrate the trouble. If SMS2FA were actually fit for purpose it would not require so many internet defenders. [0] https://blog.cmpxchg8b.com/2020/07/you-dont-need-sms-2fa.html?m=1 https://blog.cmpxchg8b.com/2020/07/you-dont-need-sms-2fa.htm...
- exabrial 5y agoYet Apple, SendGrid, any many other require it.
- rawgabbit 5y agoAs others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to backing it up? You cannot prove you are you and so customer support cannot help you. Google, Microsoft, and Apple are not known for helping consumers get themselves out of this catch-22. It is a mistake to ask consumers to protect, backup, and secure their digital lives themselves. Consumers don't have the time or skills to keep up with the hackers. If Apple, Google, ATT, Verizon etc. cannot provide digital security, this is an opportunity for someone else to step in. My personal suggestion is this is a ripe opportunity for someone like the US Post Office or Department of Motor Vehicles. Consumers would go to the US Post Office or DMV and purchase a Yubi key from them. The additional value they add, is they can verify the identity of the consumers who is purchasing the Yubi key and replace the key if it is lost/stolen. Similar to how they process driver licenses or passports. This service is optional and would actually cost money. I would gladly pay a monthly fee for this peace of mind.
- spicybright 5y agoAbsolutely this, but the service should act like a driver's license if you want people to actually use it. Pay some $ for the key, renew it every 2 years for a fee, pay for a replacement if needed. No one wants another monthly fee, taxes should keep the infra up like any other license.
- danieljacksonno 5y agoWe have something vaguely similar with "BankID" in Norway. It's a bank issued digital ID that submits a 2FA to your phone (not through SMS, but through some other system that takes over the whole screen - not sure what it is). It's usable for almost all government agencies or official stuff online here, but I haven't seen anyone use it for third party auth as it costs roughly 10 cents per login for the service using it.
- 5y ago
- ddtaylor 5y agoRecently Mozilla started requiring 2FA for their AMO site used to publish addons. I have a few private addons that I develop and use, nothing big yet, but I really didn't want to link anything up with 2FA over SMS and I'm also trying to reduce my "Google footprint" so instead I selected their only alternative that doesn't use a centralized third party. It was a bit complex, but I eventually got Keepass to generate the TOTP codes which so far are pretty awesome.
- vinay_ys 5y agoOne of the protections enforced in my country is this – for 24 hours after mobile number porting, all incoming/outgoing sms are blocked. And on both the current sim and new sim, notification sms are sent to inform the user that mobile number migration is occurring. This gives you the opportunity to notice and put a stop to it if it was triggered fraudulently. But of course there are corner-cases to this. If you are personally targeted in the meatspace, then all bets are off.
- robomartin 5y agoI had to go look for how people might be able to hijack the SMS system. This led to [0], which was discussed on HN about three months ago [1]. Interesting, yet an attacker would have to spend some amount of money per attempt. Unless they are targeting high value individuals this does not seem a likely threat for the average person. Other methods exist, such as SIM-jacking [2]. I wish the article included a list of phones that might be vulnerable to this attack. Are iPhone's vulnerable? And yet, while "free" this still requires a massive automated net to be deployed in order to gain some information and then socially engineer your way into gaining access to sites and services that might be of value. I guess my question is: How common are these attacks? What's the scale of the activity? I have never heard of anyone in my immediate and even extended circles having any such issues. OK, I have indoctrinated most of my family into not clicking links in SMS messages and most of my extended circles are technically savvy. What does this look like in the general population? [0] https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-16-dollars-sakari-netnumber https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1... [1] https://news.ycombinator.com/item?id=26468892 https://news.ycombinator.com/item?id=26468892 [2] https://medium.com/auedbaki/how-hackers-hack-phone-using-sms-89a5de67e776 https://medium.com/auedbaki/how-hackers-hack-phone-using-sms...
- 3np 5y agoWhat really grinds my gears is the seemingly unstoppable global transition towards SMS to a mobile phone number as means of identifying an individual, conflated with "security" through 2FA/account recovery, with this as the only option. This is especially popular within Fintech. Wise (formerly Transferwise) recently started requiring 2FA for signing in - SMS is the one and only option. Revolut requires it for acknowledging transactions and changing/viewing debit card info. That legacy banks do this is expected, but I'm really concerned about this trend among newer global and big actors who otherwise present themselves as modern. I strongly urge other users here to reach out to customer support of these companies and request them to supplement this with some other more secure means of 2FA, such as TOTP (hey, we gotta take what we can get), U2F, or Webauthn.
- FabHK 5y agoSuper annoying, especially when (prior to the pandemic) I traveled a lot and had a new SIM every month or two. Insanity.
- potatoz2 5y agoWise supports 2FA through their app (similar to what Google does, with a prompt).
- oezi 5y agoWell, the European PSD2 has forbidden the use of SMS TANs last year for banking applications while requiring much more stringent 2FA use (for account balances more than 30 days in the past for instance). So, I would say quite the opposite to unstoppable.
- cromka 5y agoYep, and the banks are literally reaching the deadline as we speak. All my EU banks are notifying me that within a week or so the SMS codes will stop working, and their mobile app will be required for 2FA.
- tgsovlerkhgsel 5y agoAnd because it has not required some open standard as a replacement, I now have hundreds of MB of different bloatware bank apps on my phone, each of which I have to use in a slightly different way when logging into my bank accounts, usually with scanning barcodes or remembering yet another PIN. Migrating to a new phone is a nightmare. For extra convenience, PSD2 also mandated a logout after 5 minutes of inactivity. Some of the ideas behind PSD2 are great, but the outcome is about as good as the cookie directive.
- sometimesshit 5y agoTo the OP, Please don't use cheap providers like Boost. I have done audit and I found Sprint to be superior; however, they got merged with T-Mobile now. Sprint was the best provider that prevented most hijacks.
- spicybright 5y agoThat's pretty neat, can you describe what you check when auditing a network?
- max_ 5y agoTOTP is the best. The problem is how to effectively store the secrets for recovery.
- eslaught 5y agoPart of the issue here that I don't see people addressing is that SMS as an only-factor recovery tool is often not optional. I hit a case like this just the other day: the service would not allow me to log in at all without adding an SMS number. This is becoming increasingly common. The irony is that my security is now worse. At least my password was randomly generated. I'm not sure what there is to do about this, other than educating as broadly as we can and hope that engineers advocate in their own organizations to change this.
- paulpauper 5y agothat is because google and other companies derive more $ from your number than protecting your privacy/security
- kyle-rb 5y agoGoogle doesn't require SMS. They often ask me when I log in, but I can always hit 'skip', which I do because I'm scared of this exact case.
- tgsovlerkhgsel 5y agoThis is not universally true. If Google decides that your account looks suspicious, either at creation or a later date, you are unable to access it until you provide a phone number. You also used to be unable to set up a U2F/FIDO 2FA without first setting up SMS 2FA (but you could delete the phone number from the account later). Not sure if that's still the case.
- 3np 5y agoI really hope that I am not the only one requesting businesses to not do this when I encounter it. It may be the only way to get it to stop. Open a case with customer service and represent it for what it is; a security hole that prevents you from using the service.
- paulpauper 5y agoThe worst part is, Coinbase will not cover your losses. They have absolved themselves of any responsibly for users being hacked, only if they [coinbase] gets hacked.
- nodesocket 5y agoWorst part, I mean that’s the majority of the risk of crypto. These aren’t government backed accounts, why would there be insurance.
- tgsovlerkhgsel 5y agoSince I wasn't sure if this is just what their ToS claim or how it's handled in practice, I googled a bit, and found this case: https://finance.yahoo.com/news/coinbase-hacked-accounts-get-no-justice-from-horrible-us-laws-fintech-lawyer-113520348.html https://finance.yahoo.com/news/coinbase-hacked-accounts-get-... So this indeed seems to be how Coinbase handles it.
- aiisahik 5y agoQuestion: Have people used Google Voice SMS accounts or Twilio SMS accounts for 2FA? Would that be more secure?
- irfwashere 5y agoI have heard that this is actually better and more secure. Google voice I think isn't susceptible to social engineering attacks like typical phone carriers. Also it's a smarter move to have a separate phone number that isn't related to what a hacker might be able to find out about you just doing basic search engine queries.
- aarreedd 5y agoYou can request that your mobile provider put a port freeze and SIM lock on your account and require you to be in-store with a valid photo ID to transfer your number to another device. https://help.coinbase.com/en/coinbase/privacy-and-security/data-privacy/how-can-i-make-my-account-more-secure#lock-down-your-mobile-account https://help.coinbase.com/en/coinbase/privacy-and-security/d...
- xphos 5y agoYeah but if that's not the default 2 factor authentication is not secure and its an illusion of safety. For companies and groups to claim its gives you all this security when it doesn't follow through even in the default case is misleading. No shade on you but your talking about a lot of hops to go thru just to make someones broken model work.
- irfwashere 5y agoDoes anyone else here use Google voice for sms 2fa? You get another number and you should be safe from sim swap attacks.
- platty 5y agoI had this happen with AT&T. Someone bought a new phone on my account with a phone upgrade, they transferred my service to the new phone, and I had to go through a ton of headache getting them to give me my service back to my old phone and trying to figure out what happened. At the end, they acknowledged it was fraud. Additionally, added guards on the account with an additional passcode and wording stating that a person must confirm with me specifically before anything like transferring services is done again. It did however blow my mind that something like that could happen and if someone intended on getting access to my accounts, the situation could have been much worse.
- TheHippo 5y agoThis seems more of an problem when living in the USA than an SMS problem. I'm in Germany and there is no way someone gets a new SIM card without someone checking the persons personal ID.
- myrond 5y agoHappened to me as well. I found out who the actual people who hijacked it due to their poor operational security awareness. Found out they did this to someone every 2 weeks. Nobody cared as they successfully stole $0. I've watched the news to see if they were ever caught; I assume they are still doing it to this day.
- sabhiram 5y agoIf you have to use it, do so on a non-portable phone number.
- Havoc 5y agoIt's a major issue in South Africa too with bank accounts being raided. Bank says not my problem if your password got compromised. Cellphone provider says not my problem - SMS was never advertised/intended as secure. So the user just has to deal with bank account being drained
- arthurcolle 5y agoWere you at the Bitcoin 2021 Conference? I saw many people acting shady, looking over people’s shoulders as they were using Coinbase, other wallets. Do you think there’s any way this might be related? (Obviously moot if you weren’t there...)
- scottmcdot 5y agoHaving had this almost happen to me, I always strongly recommend that you remove your phone number from Gmail as a recovery method. And then go and test it out to double check. SMS 2fa is okay but SMS recovery is not okay and high risk. It's also ideal to have obscure email addresses used for, say, coinbase so that in the data dump they they likely have, containing your email to phone number mapping, points them to the email address not linked to coinbase.
- matheusmoreira 5y agoCoinbase has no other security options? I have passwords, email, SMS, mobile app and a hardware token. Binance actually makes me input every single code under a 60 seconds time limit.
- minusSeven 5y agoIn India almost all security mechanism is through 2 factor authentication that too mainly sms, with very few companies offering other forms of 2 factor authentication like authenticator app etc. If this happens in India there will be massive repercussions. Does anybody have any work arounds to this should it start happening to a few people?
- niyaven 5y agoDisclaimer: not Indian but living in India and I've not attempted to perform this hack. But if I'm not mistaken a SIM swap procedure is the similar to asking for a new SIM. For Vodafone India, in addition to traditional info (date of birth, passport number, address), they actually asked me to give the number of someone whom I've called with this SIM, then they called that person and asked them to verify my identity. I found this to be quite secure. But maybe the procedure is different for foreigners (at least the SIM creation procedure is different).
- lobocinza 5y ago+1 for pass-otp or keepasxc because the chain is strong as the weaker link (cause 2FA is generally badly implemented) and password/mail is reliable.
- easterncalculus 5y agoI'm sorry to read this, and it only makes me more annoyed considering which systems have proper MFA methods. It's ridiculous that you can open a bank account only supporting SMS while GMail supports TOTP or smart cards.
- herbst 5y agoAs someone advocating against this for a while, who has a internet only sim these days and no phone number it is scary how many companies depend on SMS for security. Even if it's only second factor today, what really prevents the company from allowing password resets one day? Nothing, I likely would not even notice it until it is to late. I can own an email address, but I can never own a phone number. Nearly all contracts clearly state that the number is not actually yours in different wordings and nothing prevents anyone from reclaiming the number and give it to someone else. It's stupid. And annoying.