40 ms·
I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point,
by usui 2y ago
I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point, but you're saying networks did a good job protecting against SMS spam and this is the reason why people trust it?
- ajross 2y agoSpam delivered over SMS and the security (perceived or real) of SMS-based 2FA are entirely different subjects, though. But to kibitz on the second: a validated phone account remains by far the easiest 2FA mechanism to deploy and rely on, and 2FA remains by far more secure than simple password authentication. Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all.
- usui 2y ago> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all. It was your interpretation that I advise people to not use any 2FA at all. I won't honor the request to not dump on SMS, as I am perfectly happy to dump on an "extremely valuable technology" on technical demerits, on the grounds of security while simultaneously acknowledging highly debatable, highly questionable positive merits on grounds of user-experience, which more often than not oppose each other. Why do you construct a single-faceted single-shot ability for us to evaluate SMS? It sucks and it also doesn't, and saying it sucks isn't going to entirely destroy its already-terrible reputation amongst technicals. I would much rather have a message sent to my email address since that is harder to lose than a text message or phone number, and it costs me far less per month.
- ajross 2y ago> It was your interpretation that I advise people to not use any 2FA at all. No, to be clear, it's the obvious interpretation of a non-expert user, which is why your advice is so dangerous. They don't have a yubikey, don't understand how the apps work, and are faced with a decision to either enable SMS 2FA or not. And you're telling them not to, so they won't. And we'll all suffer. Again, work the other side of the problem if this is important to you. Make the other solutions better and educate people about them. Don't tell them not to use something that might very well save their bank account.
- tialaramex 2y ago> They don't have a yubikey, don't understand how the apps work... But they almost certainly do have a phone, any vaguely modern phone is also a valid hardware credential - and given how much time people spend using a phone it might even be more practical for them. I would argue that the problem is we've made the inconvenience symbolic - people see me sign in at work (with a Yubico Security Key 2 typically) and assume that's some sort of get out or workaround rather than, in reality, the much more secure option that my employer was too cheap to provide. They intuit that the thing they're doing is annoying and takes more effort so logically it must be more secure not less, right ?
- ajross 2y agoOnce more, I'm not saying that SMS 2FA is the best choice. I'm saying it's a vastly better choice than "1FA", and that telling people not to use it is hurting and not helping.
- tialaramex 2y agoAs I stated above because it can cause people to believe they're doing the right thing when they aren't I am actualy not convinced it's necessarily better than nothing.
- tialaramex 2y agoIt's an attractive nuisance. And the SMS request that's actually part of the problem can be misunderstood by users (whose model is understandably less technical) as a validation that this is authentic. "Ooh I'm not sure about these texts from Big Bank, maybe I should call them instead... Oh it did the 2FA code text, I guess it's legitimate"
- nolongerthere 2y agoIts a learned trust, most people don't realize that their phone service provider blocks something like 90% of all messages they receive, they made a conscious decision to not show the users their spam folders, so we don't see what's not getting through like you can when you check your email.