4 ms·
This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then
by ssklash 3y ago
This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.
- baerrie 3y agoIf you have access to someone’s email account can’t you dl the totp authenticator and bypass this? Effectively that makes email the authenticator which isn’t better than a phone number and device
- kevincox 3y agoWhat do you mean by "dl the totp authenticator"? But the answer is no. Without the TOTP secret no one else can generate valid codes. If you sync your secrets to some cloud service then yes, you are trusting that cloud service. And if you let your TOTP cloud service reset your account with an email then it probably isn't the most secure option. But the important thing here is that the user is in control. They can memorize their secret if they want to an no one can take it from them. Or they can publish it online if they don't like security. With SMS 2FA you need to trust your telecom provider, I very much don't.
- baerrie 3y agoI meant “download the totp generator”. Correct me if I’m wrong but the totp generator has to linked with some account, the security of which is not managed by you, and is just as vulnerable as that account
- peeters 3y agoTOTP is a completely offline protocol. Basically you scan a QR code which is a signing key that is saved to your phone. Then all your phone needs is an accurate time source, and periodically signs the current time with that key to produce a 6-digit code. As such, no, it's not associated with anything from the source account. It is not challenge/response, and you can scan the QR code with 10 different phones and they will all produce the same codes at the same time.
- kevincox 3y agoNo, TOTP is a cryptographic protocol for generating One Time Passcodes (OTP) based on a seed. Frequently this seed is displayed to the user as a QR code, but it is just a random string. The user will then somehow save this seed (usually by scanning the QR code with their TOTP app). When a password is required you just use the seed and the current time to generate a code. No accounts are required, just the current time and the seed. You may be confusing TOTP with proprietary app-based 2FA solutions which just send the token in a push notification or similar.
- baerrie 3y agoOkay, thanks, now i get it i think
- neilv 3y agoThe TOTP authenticator apps are usually initialized only once per account -- when the user first enables that 2FA for the account. The system is designed to assume that the user doing the initializing that one time is the legitimate user. (There's a bootstrapping problem for the authenticators, that the account provider needs to "trust once" that the user is legitimate. The best time to do that is as early as possible. Preferably when the account is set up, and before much value/dependence has been invested in the account.) After that first initialization of an authenticator for an account, anyone trying to initialize another authenticator would have the burden of trying to prove to the account provider that they aren't just an illegitimate person trying to bypass the 2FA. So, you probably can't just use email to do a "lost my authenticator lol", unless the account provider doesn't really care about 2FA, and has implemented it in a very weak way.
- Saris 3y agoNope, email access won't allow you to bypass TOTP 2FA.
- peeters 3y agoMy favourite is TD Bank in Canada, who started supporting an authenticator app (but it had to be theirs) because it was more secure than SMS. Except...they also don't allow you to disable SMS as an option for 2FA. So whoever is logging in gets to choose whether to use the secure authenticator app, or SMS.
- playingalong 3y agoThis might be temporary as part of some rollout, e.g. they might disable the choice in a year, etc. Banks evolve slowly.
- bonton89 3y agoI prefer TOTP for privacy and control reasons, but I think you're overselling the disadvantages of SMS here. If you have to find and pay an inside guy to do SIM swaps, they'll be limited in the number they can do before getting caught so it really will only be suitable to do targeted attacks on targets you're pretty sure have something worth stealing. There was a DND that talked about how sim swaps used to be a cakewalk over the phone social engineering exercise but were now kind of expensive to pull off and required a man in a physical location, with T-mobile remaining the easiest target. The black hat guy they were talking to said his first steps were finding a target worth swapping, usually some one that bragged a lot about bitcoin or some other crypto currency on twitter. And getting the phone number was usually really easy to do with a combination of OSINT and abusing the fact services will give you a partially masked phone number when you try to login.
- ssklash 3y agoI agree it's a threat that is not exactly easy to pull off. But my main issue with is is represents an attack vector that you can do exactly nothing to defend against yourself. If you use other forms of MFA, you are at least in charge. Sure you can lose your TOTP seed or something, but you have agency in how it is stored. SMS forces you to rely on companies that have log histories of failing to protect your phone number.
- FireBeyond 3y ago... AND because you have 2FA, everybody assumes "you MUST have shared credentials because using 2FA is secure...", including bank fraud departments.
- cqqxo4zV46cp 3y agoSMS MFA thwarts the vast vast vast majority of attacks that a typical user reality. Yes, you’re almost certainly a typical user. Considering usability issues related to TOTP, SMS MFA well and truly has its place. Computer nerds get so giddy about TOTP that they keep making these ‘perfect v good’ arguments. Be realistic here.