3 ms·
What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS
by fitzroy 5y ago
What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)?
Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like most 2FA is just opening up a much easier attack vector (social engineering a phone number port) vs guessing a long, random, unique password. A password manager with browser plugin (or iCloud Keychain) mostly solves the phishing issue if you stop a second to think on the rare occasions when you need to manually copy/paste because of a weird subdomain or partner domain.
I've been 'about to' set up 2FA for over a decade now, but it always seems like a bad idea.
Edit: Also, who's to say customer service agents won't/don't fallback to sending an SMS reset code even if the account supposedly requires a dongle or app for 2FA.
- Y_Y 5y ago2FA (is supposed to) mean you have both factors, not one or the other. It's strictly more secure that either alone, even if SMS sucks.
- mod 5y agoYes, but in some cases it's "2 outta 3" (or worse)
- someguydave 5y ago> What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? One possible point is that you could still log in somewhere that has internet but no cell service
- int_19h 5y agoWe have a better way of handling that these days: https://en.wikipedia.org/wiki/Generic_Access_Network https://en.wikipedia.org/wiki/Generic_Access_Network
- someguydave 5y agoThat practically requires wifi. In some scenarios you might have wired internet only.
- nijave 5y agoIt seems like the places that rely on SMS generally don't have hardware 2FA. Or, most websites that allow configuring multiple 2FA methods support disabling SMS The ones that let you configure a single MFA method or single with backup are usually where I run into issues, personally For instance, on Github, I have 2x U2F tokens and paper recovery codes but there's not even a phone number configured on the account
- mr_toad 5y ago> What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Most people probably use it because it’s more convenient and reliable than SMS, not because it’s more secure.