4 ms·
Stop Using SMS
- jacquesm 5y agoIt isn't the users that are the problem here, it is the telcos with respect to the simswaps: if social engineering is used to get sims to be issued without proper verification, then fix that. If SMS isn't encrypted properly that is an issue, but pushing various commercial alternatives that have broken and/or partial support isn't a solution either. As for my telco seeing the message content, I'm not too worried about them having access to one time use codes that will live for the next minute at best. And the institutions that force SMS usage on their users are the real issue. It is fairly easy to point to a problem but solving it is an entirely different level and this article doesn't really do anything that would allow your average user to say get VISA/MC to use other channels, ditto for various datarooms and other instances where 2FA and SMS have somehow become synonymous. The only party that does any of this properly is my bank, which issued a secure hardware token that I need to operate separately from my computer in order to generate one time use codes. I'm sure that there are ways to abuse those (a gun to the head of a family member would do nicely) but they are a lot more secure than anything else that I see out there.
- throwaway67743 5y agoIt isn't the telcos, it's the people asserting that SMS is the only way to authenticate someone (my bank does this), it's not only absurd but also horrifically inconvenient as it assumes the number happens to be tied to the SIM in your device, in my case the number is in another country, and ends up on a VM, not my mobile device (I don't give my real number to anyone and I rarely use voice), SMS was never secure since it's readable by at the very least 3 entities, but yet it's treated as such by all sorts of people who should know better but it ticks some checkbox for compliance.
- jacquesm 5y agoSMS isn't secure and I don't think anybody ever advertised it as such, the security for MFA use derives from the use of various channels even if the information itself travels in plaintext, the theory being that your average hacker won't have access to all of those channels. This is a broken assumption at the root of many multi-factor authentication methods. SMS should not be used like this but telling users to stop it isn't productive, it is the various institutions that demand it be used that are the problem.
- throwaway67743 5y agoThat's what I was saying, it's the enforced use of insecure channels by institutions (and also horribly inconvenient)
- eternityforest 5y agoSMS auth has one really big advantage. There is a human run authority one can appeal to if a device is ever lost, stolen, or forgotten, which you might not be able to afford to manage yourself. It also makes spam accounts harder to make. I think it should always be an option until something with similar properties arrives(Like a YubiKey with the option to have them keep a key on file and reorder, with their agents somehow making sure it's you).
- novocantico 5y agoIt's also extremely easy to abuse, which IMO kind of negates the benefit you pointed out.
- RadixDLT 5y agoagree 100% but telegram won't let me login if I use my google number
- cersa8 5y agoFor the reasons listed I got myself three Yubikey 5 NFC dongles and removed SMS wherever possible. Unfortunately the authentication landscape is still very fragmented. AWS root accounts for instance cannot be secured with multiple hardware keys, only one. So no backup. The only solution is to use virtual OTP and register the same OTP setup key on multiple hardware keys. Only Google seems to have the ability to register as many keys as you want.
- camgunz 5y agoThe AWS thing is wild to me. It's been this way for years. Please please add this, benevolent Amazon devs.