5 ms·
Meanwhile, there are countries whose entire banking, tax filing, CC processing and various public service systems rely on SMS as the only second factor.
by ComodoHacker 3y ago
Meanwhile, there are countries whose entire banking, tax filing, CC processing and various public service systems rely on SMS as the only second factor.
- vladvasiliu 3y agoI don't know about those countries, but I know of one who says it's trying to compete with the US on tech, and one of their biggest banks moved away from hardware TOTP tokens to some kind of "secure app" and now to... SMS! To name and shame: BNP in France. My personal account stayed on the app, but for my company account, it I only get SMS now.
- KronisLV 3y ago> To name and shame: BNP in France. My personal account stayed on the app, but for my company account, it I only get SMS now. I remember a story about a university in Lithuania also opting for either SMS or a proprietary 2FA app, but not allowing TOTP either: https://fsfe.org/news/2023/news-20230418-01.html https://fsfe.org/news/2023/news-20230418-01.html What's worse, all they had to do was enable a checkbox in the settings somewhere but they went on an embarrassingly long e-mail thread back and forth, not even willing to help the users. So I think that in cases like that, it's definitely a good idea to call attention to the issue and tell more people about open technologies like that! Unfortunately, most people just won't care. That said, TOTP is actually decent and I'm surprised that it's not supported everywhere, especially given how much shouting about SMS not being secure enough goes around.
- lxgr 3y agoTOTP unfortunately does not satisfy the “transaction binding” requirement of PSD2, since the token does not tell you what you’re confirming at the time you share it with a (potentially MITMing) website. SMS-OTP, despite its many other flaws, at least offers a trusted path to say “by sharing this code, you are paying x€ to y corp”.
- vladvasiliu 3y agoI think that since the issue at hand is that SMS can be intercepted, the protection afforded by this information is minimal. Anecdotally, in the case of my bank, if I try to make a transfer, the SMS is something along the lines of "Are you trying to transfer 1234 €? If yes, enter the code 12345, or else call your representative asap". One terrible point being that once you've entered the confirmation code, they consider the transaction as "strongly verified", so it's not that easy to roll it back. Fortunately, I've never had this happen to me so I don't know what that entails, but contesting a random unverified charge is as easy as clicking on the transaction list and then "dispute".
- lxgr 3y agoYes, all in all I'm not happy with SMS-OTP still being considered just as secure as e.g. WebAuthN, and much more secure than Email-OTP (which is explicitly prohibited for PSD2/SCA purposes). The problem isn't really interception in my view (even though SIM-jacking and porting attacks are scary enough!), but rather the high likelihood of phishing/UI confusion: With modern mobile OSes auto-filling transaction details, I'm not too sure if everybody is still reading the text accompanying the confirmation code. It's quite possible for a fraud victim to be directed to amaz0n.com and tricked into entering an SMS-OTP confirmation code to confirm a purchase of €5.00, without noticing that the accompanying text actually says "only enter this code on BuyCryptoNoKycOrBacksies.com to confirm your purchase of €500".
- Cthulhu_ 3y agoThat's also because these systems are large, complicated, and slow moving. Not only that, but the users are resistant to change; the older you get, the faster time moves, and a decade between one system (SMS) and the next (e.g. a two factor auth app) feels short and unnecessary.
- ComodoHacker 3y agoThat's primarily because a significant portion of population there don't have smartphones.
- lotsofpulp 3y agoLast I checked, even the US federal government required SMS 2FA to get into your Social Security account. But the problem is also only allowing SMS 2FA. Why not allow both and let people choose TOTP? I have a feeling SMS 2FA is used as a cheap way to implement a rough social credit score. If you have a stable life and follow the rules, then you have continuous access to the same phone number. And only allowing SMS 2FA allows you to only deal with this population, and ignore populations that might have higher proportions of “costly” customers.
- lxgr 3y agoVery true, unfortunately. My country’s administration lets people e-sign PDFs that are accepted throughout the EU as legally binding/equivalent to a paper signature using only a static password and SMS-OTP. (The system used to be based on PCKS#11-compatible smart cards, but nobody managed to use the software, so they switched to SMS…)