3 ms·
Yes, SIMs can be swapped and SMS can be eavesdropped. But SMS 2FA has some qualities hard to replicate by other solutions: Reliability. It's extremely hard to
by janci 3y ago
Yes, SIMs can be swapped and SMS can be eavesdropped. But SMS 2FA has some qualities hard to replicate by other solutions:
Reliability. It's extremely hard to accidentally break a SIM card. If you drop or drown your phone it may easily become inoperable, but the SIM will be still OK and ready to work in other device.
Availability. If you somehow destroy your SIM it is reasonably easy to get a replacement. Properely and securely backing up an app-based authenticator is difficult. Enrolling multiple authenticators is cumbersome and sometimes not possible at all. Migrating to new device is as easy as it gets.
Attack discovery. If you are being sim-swapped, you will notice immediately as your phone stops working. If someone is eavesdroppoing your SMS OTP you will notice as you will receive unsolicited authentication attempts.
Attack scope. The attack must be targeted as it is much more costly to do it in larger scale.
Attack mitigation. You can take back your stolen SIM as opposed to leaked keys.
I'm not saying SMS is best solution, but it is good enough in many aspects. Other solutions are best in one aspect and much worse in others. SMS strikes the right balance IMO and can be rasonably secure when used as second factor. (Not first and only!)