4 ms·
Sometimes we don’t have a choice, e.g. many American banks use SMS as the only 2FA
by linux2647 4y ago
Sometimes we don’t have a choice, e.g. many American banks use SMS as the only 2FA
- latchkey 4y agoThe choice could be to use another bank.
- Firmwarrior 4y agoWhat bank? Every US bank requires phone-based 2fa so far as I know I bought a YubiKey a few years ago, and was extremely disappointed to find that there are only a tiny number of important services that actually support it without requiring insecure SMS as a backdoor
- latchkey 4y agoChase: email Ally: email Citibank: phone app
- Firmwarrior 4y agoThe problem here is we're talking about "simjacking" (where you exploit one of the many, many security loopholes in the cellular network to take over someone's phone line for a while and get SMS 2FA codes) I don't know about Ally or Citibank and will check those out, but it's been my experience that Chase requires a phone number and it makes sending 2FA codes to that number an option.
- latchkey 4y agoChase has two auth methods that you have to deal with: 1. the not recognized device. in this case, it is only text or call. 2. recognized device, 2fa login: in this case, you get text or email as options.
- joshmanders 4y agoSo your options to avoid 2FA via text is to use email, something highly more likely to be compromised than simjacking is? mmk.
- latchkey 4y agoYes, that is right. I don't see how my email, which is secured with 2FA, is more likely to be compromised than simjacking.
- joshmanders 4y agoYou realize you're applying your own "acceptable amount of security" and expecting bank users to be this sophisticated? lol. If you're gonna advocate for better security when it comes to authenticating your banking details, please, for everyone's sake; don't just shift the attack vector to another service and claim it's superior because YOU use TOTP 2FA with YOUR email account. Be better to advocate that services use TOTP 2FA directly.
- latchkey 4y agoI'd argue that even without 2FA on email, it is still less risk than simjacking.
- joshmanders 4y agoI think you over estimate how hard it is to simjack vs bruteforcing a simple password to email.
- latchkey 4y agoDisagree [0]. Name one major email provider that doesn't have bruteforce protection. This is a silly circular argument anyway. You're just upset that I'd have the gall to suggest that you use online banking to someone who lives in a rural town in Iowa. Instead, you keep pontificating on the level of security between email and sms... while at the same time, being perfectly ok with using a bank that only offers sms 2fa. Facepalm. At the end of the day, neither matter... your funds get stolen from simjacking because a bank only offers that as protection? Read this [1]... max loss is $500 and more likely $0. This is bike shedding a moot issue. 2fa is more relevant for other issues. Have a nice day, sir. [0] https://www.ic3.gov/Media/Y2022/PSA220208 https://www.ic3.gov/Media/Y2022/PSA220208 [1] https://www.identitytheft.gov/#/Know-Your-Rights https://www.identitytheft.gov/#/Know-Your-Rights
- joshmanders 4y agoThat's a very privileged thing to do. I live in a small rural town in Iowa. All our banks use SMS to send 2FA, are you suggesting I move... because my bank uses SMS for sending a code?
- latchkey 4y agoOnline banking is everywhere.