3 ms·
It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecur
by f0e4c2f7 3y ago
It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point.
You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them.
Private key auth systems have security challenges of their own (losing access forever when you lose your key) but I wish they were an option in place of the current regime.
In the 90s you could bypass security locally on a machine by clicking cancel and it would just log you in. Feels like today it's only slightly more complicated and costs a bit of money to access twitter, email, bank accounts etc.
Seemingly little to no interest in resolving this state of affairs beyond obscure and increasingly less legal crypto based systems.
- lxgr 3y agoThat’s what happens when we designate phone providers as the single point of identity verification without creating any incentives for them to actually fulfill that role. One of my banks basically only accepts what they call “phone number verification” to clear a false fraud alert on my cards (or generally talk to them about anything regarding my account). What that means is (at least I’m fairly sure) that the agent on the phone will ask me for any phone number, they ask the carrier for the name on that line and compare it with mine, and if it’s a match, they send an OTP to that number. This is even worse than SMS-OTP, since a fraudster doesn’t even need to change my number on file with my bank – opening a phone line in my name with any of the big three carriers is enough!
- lr1970 3y ago> It's pretty wild how baked into modern life insecure 2fa is. And a solution to this is very simple. Make telcos legally liable for losses due to SIM-swap attacks and before the ink is dry on such a law, Telcos will ban using phone numbers for authentication in their TOS. The banks and alike will be forced to come up with another, hopefully, better auth system.
- guiambros 3y agoNot sure why you're being downvoted; I think this is pretty reasonable idea. Of course, there's zero chance of this happening in the US, given telcos would lobby heavily against it. But as a thought experiment, I think that's exactly what should happen: telcos should be held liable for their piss-poor security practices against SIM swapping. And you never know what's going to come up from EU from a regulatory perspective.
- freedomben 3y agoI didn't down vote GP and I agree with both of you, but I think a reason for down votes could be because it's quite authoritarian.
- ahaseeb 3y agoSecurity comes with cost and inconvenience. Like would you pay $50 everytime you've to swap a SIM ?
- DANmode 3y agoHis..twitter account. Not his private wallet.