3 ms·
> A bit more on the account recovery: given a valid email address, PayPal will happily send you a text to verify a password reset, and Amazon lets you reset you
by gregmac 3y ago
> A bit more on the account recovery: given a valid email address, PayPal will happily send you a text to verify a password reset, and Amazon lets you reset your password with just a phone number. This means that as long as you know that somebody has an Amazon account that may be linked to their phone number, a simple SIM swapping attack or even snooping on local text messages can easily give you full access to somebody’s Amazon account.
The trouble is not SMS being used for 2FA, but rather that using it as the password reset mechanism effectively means it's now the single authentication factor. This is really bad because SMS (due to SIM swapping) is significantly worse than regular passwords.
When SMS is actually a second factor it's still actually an improvement over no 2FA for most users, because now in addition to just stealing your password the attacker has to SIM swap you or find some other means to get the 2FA code.
Your proposed fixes (TOTP, Passkeys) are arguably no better if they are also used as single factor password resets.
I think the problem is really for password recovery you need N+1 authentication mechanisms -- in other words for 2FA login, you need a 3rd password recovery mechanism so you can still do a 2FA password recovery in case one of the first two factors is unusable. Few sites do this right.