7 ms·
Please use secure channels for authentication. SMS is antiquatedly insecure (Any way it's sent: SS7, SMPP, etc.). More traffic benefits the industry (since som
by apienx 3y ago
Please use secure channels for authentication. SMS is antiquatedly insecure (Any way it's sent: SS7, SMPP, etc.).
More traffic benefits the industry (since some sucker pays for it). There's no incentive for any of the entities that profit from this to stop it (unless it's too sell you a premium protection service).
- jnwatson 3y agoNIST recommended getting off SMS in 2016. I’d say 7 years is plenty of time that folks really shouldn’t be using it. https://www.schneier.com/blog/archives/2016/08/nist_is_no_long.html https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo...
- ComodoHacker 3y agoMeanwhile, there are countries whose entire banking, tax filing, CC processing and various public service systems rely on SMS as the only second factor.
- vladvasiliu 3y agoI don't know about those countries, but I know of one who says it's trying to compete with the US on tech, and one of their biggest banks moved away from hardware TOTP tokens to some kind of "secure app" and now to... SMS! To name and shame: BNP in France. My personal account stayed on the app, but for my company account, it I only get SMS now.
- KronisLV 3y ago> To name and shame: BNP in France. My personal account stayed on the app, but for my company account, it I only get SMS now. I remember a story about a university in Lithuania also opting for either SMS or a proprietary 2FA app, but not allowing TOTP either: https://fsfe.org/news/2023/news-20230418-01.html https://fsfe.org/news/2023/news-20230418-01.html What's worse, all they had to do was enable a checkbox in the settings somewhere but they went on an embarrassingly long e-mail thread back and forth, not even willing to help the users. So I think that in cases like that, it's definitely a good idea to call attention to the issue and tell more people about open technologies like that! Unfortunately, most people just won't care. That said, TOTP is actually decent and I'm surprised that it's not supported everywhere, especially given how much shouting about SMS not being secure enough goes around.
- lxgr 3y agoTOTP unfortunately does not satisfy the “transaction binding” requirement of PSD2, since the token does not tell you what you’re confirming at the time you share it with a (potentially MITMing) website. SMS-OTP, despite its many other flaws, at least offers a trusted path to say “by sharing this code, you are paying x€ to y corp”.
- vladvasiliu 3y agoI think that since the issue at hand is that SMS can be intercepted, the protection afforded by this information is minimal. Anecdotally, in the case of my bank, if I try to make a transfer, the SMS is something along the lines of "Are you trying to transfer 1234 €? If yes, enter the code 12345, or else call your representative asap". One terrible point being that once you've entered the confirmation code, they consider the transaction as "strongly verified", so it's not that easy to roll it back. Fortunately, I've never had this happen to me so I don't know what that entails, but contesting a random unverified charge is as easy as clicking on the transaction list and then "dispute".
- lxgr 3y agoYes, all in all I'm not happy with SMS-OTP still being considered just as secure as e.g. WebAuthN, and much more secure than Email-OTP (which is explicitly prohibited for PSD2/SCA purposes). The problem isn't really interception in my view (even though SIM-jacking and porting attacks are scary enough!), but rather the high likelihood of phishing/UI confusion: With modern mobile OSes auto-filling transaction details, I'm not too sure if everybody is still reading the text accompanying the confirmation code. It's quite possible for a fraud victim to be directed to amaz0n.com and tricked into entering an SMS-OTP confirmation code to confirm a purchase of €5.00, without noticing that the accompanying text actually says "only enter this code on BuyCryptoNoKycOrBacksies.com to confirm your purchase of €500".
- Cthulhu_ 3y agoThat's also because these systems are large, complicated, and slow moving. Not only that, but the users are resistant to change; the older you get, the faster time moves, and a decade between one system (SMS) and the next (e.g. a two factor auth app) feels short and unnecessary.
- ComodoHacker 3y agoThat's primarily because a significant portion of population there don't have smartphones.
- lotsofpulp 3y agoLast I checked, even the US federal government required SMS 2FA to get into your Social Security account. But the problem is also only allowing SMS 2FA. Why not allow both and let people choose TOTP? I have a feeling SMS 2FA is used as a cheap way to implement a rough social credit score. If you have a stable life and follow the rules, then you have continuous access to the same phone number. And only allowing SMS 2FA allows you to only deal with this population, and ignore populations that might have higher proportions of “costly” customers.
- lxgr 3y agoVery true, unfortunately. My country’s administration lets people e-sign PDFs that are accepted throughout the EU as legally binding/equivalent to a paper signature using only a static password and SMS-OTP. (The system used to be based on PCKS#11-compatible smart cards, but nobody managed to use the software, so they switched to SMS…)
- ghusbands 3y agoSure, but it seems a bit short-sighted to assume that SMS brings no benefit. If a customer somehow loses access, SMS is far cheaper and more available for all involved than any other alternative. Most people don't want to carry any dongles (especially not institution-specific ones) and many don't really want to install apps or have phones that will wipe app data for infrequently-used apps.
- bigDinosaur 3y agoSMS as a backup is very different to SMS as your only option. For one it can be made much more inconvenient to use SMS so as to reduce the surface area for scams. Plenty of places still have it as the primary and only 2FA mechanism. Of course SMS itself is awful which is the key problem here. What you mean is that having your phone tied to an identity is useful (what if you lose your phone? SMS is no longer at all useful) and we could do much better than SMS for that.
- berkes 3y ago> SMS as a backup Indeed. I once worked on a system where we had SMS as one of the "last resorts". When someone used SMS as recovery, we'd disable withdrawals and fundings (it was some sort of wallet) as well as severely limit their daily limits. Until the account was fully restored again using normal, secure methods (Mail, KYC, etc). We were hit by a similar "attack" where our "let us call you to start recovery" was abused by putting a toll-number there, and our system would then call this toll-number and we'd get rediculous bills. But putting in limitations helped a lot, so we did this for SMS too.
- ta1243 3y agoIf I lose my phone I get a replacement simcard from my provider in a day or two, and SMS continues to work If I lose my phone I've lost all my various OTP authenticator apps - I don't think they are backed up to icloud
- bigDinosaur 3y agoYou should be able to back up your OTP generator codes, I have mine in KeepassXC and on my phone. Note as well that you really don't want to rely on SMS if travelling internationally, which is a use case I hit reasonably frequently.
- Phurist 3y agoWhy would I want to buy a smartphone, just to log in to some service? Why would I want to install some crappy auth app on my computer (That most likely does not have a Flatpak for it even)? Most places do not support Yubikey... so getting SMS on my Nokia 3310 is the best option for me. SMS is the way to go.
- ThePowerOfFuet 3y agoSMS is the way to go until your operator swaps the SIM on your line without your approval. SMS is the way to go until you need to sign in from somewhere you don't have cellular coverage. TOTP is superior in almost every way. Failing that, sending a login link (or code) to the user's email address is more secure than SMS.
- pjmlp 3y agoWhich feature phones usually used by aging population support TOTP?
- notpushkin 3y agoAny phone that supports J2ME should do, there's several apps: https://github.com/kwart/totp-me https://github.com/kwart/totp-me https://github.com/baumschubser/hotpants https://github.com/baumschubser/hotpants (Couldn't find one that supports QR codes, though I don't see why that would be hard to implement)
- pjmlp 3y agoI guess there is a business figuring out how to compile out of github into phones for non-techies, specially in the aging population.
- notpushkin 3y agoHopefully their relatives can remember how to install JAR/JAD apps: https://github.com/baumschubser/hotpants/releases https://github.com/baumschubser/hotpants/releases (Yeah, the UX could be better probably, but hey.)
- timwis 3y agoJust want to flag that Twilio’s 2FA service, Authy, is tightly tied to SMS. For example, if you want to login to iwantmyname.com, it asks you for your Authy totp, but if you don’t remember it, they’ll settle for an SMS code instead. And that’s a ‘feature’ of the Authy integration.
- Dachande663 3y agoAdditionally, other services in their family won't let you use other TOTP apps. Looking at you sendgrid. Utter travesty of a company.
- glogla 3y agoSMS is the only second factor that works for people without smartphones. Having a smartphone means signing your life (your location 24/7, your messages, your contacts, your everything) over to either Google or Apple. I understand the security aspect and realistically most people will have smartphones anyway, but forcing everyone into this surveillance duopoly, especially as Apple is overpriced and Google is ad company with stated mission of removing privacy, makes me pretty salty. There should be a better way.
- scrollaway 3y agoThere is a better way. There are plenty of non-phone-based totp authenticators, and many of the password managers provide one. I’m using 1Password for example and I do not use phones for second factor.
- harg 3y ago> SMS is the only second factor that works for people without smartphones. That's not correct. Many password managers have TOTP authentication features built in. There's also increasing support for security keys (e.g. yubikey) with many websites. Passkeys are also on the rise.
- pjmlp 3y agoWhich set of population without smartphones even know what a password manager is?
- lxgr 3y agoGP has also listed FIDO authenticators (Yubikey etc.), which are arguably a much better alternative for non-tech-savvy people than TOTP.
- notpushkin 3y agoI think a pretty decent set of people who care about surveillance duopoly know about password managers too.