3 ms·
The author has a few assumptions that I think are incorrect. Not all accounts need the same level of security or protection. SMS 2FA can be a very reasonable o
by drivebycomment 3y ago
The author has a few assumptions that I think are incorrect.
Not all accounts need the same level of security or protection. SMS 2FA can be a very reasonable option depending on the accounts. No law can make that kind of a decision in a reasonable way. So the law has to be toothless (if it leaves too much leeway) or it will remove a valid option from people.
The usability and the availability of other 2FA are not on par with SMS. The gap is not trivial as the author makes it sound like. Account recovery problem is a very difficult one to fix cleanly for all types of accounts. SMS is still a useful option.
Sim swap attack is multiple orders of magnitude more difficult than credential stuffing. It's not close to the most important attack vector for majority of people. It certainly is not worth legislating a solution for specifically. There are reasonable practical solutions for people who want protection against SMS as 2fa from sim hijacking - e.g. many cell phone providers support 2fa or pin to protect it from the sim attack in most scenarios. It's a much cheaper solution for the society than banning SMS 2fa.