3 ms·
NIST has explicitly said you shouldn't use SMS 2FA for a while now: NIST SP 800-63B §5.1.3.3. https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB https://pa
by Hobadee 2y ago
NIST has explicitly said you shouldn't use SMS 2FA for a while now:
NIST SP 800-63B §5.1.3.3.
https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB https://pages.nist.gov/800-63-3/sp800-63b.html#pstnOOB
- brandon272 2y agoThe perspectives and interests of NIST and the things that a service provider has has to worry about with respect to their customer/user experience are not necessarily aligned. Customer: "What do you mean two factor app? I thought the code was supposed to come to my phone?" Support: "It did, but we no longer support SMS two factor authentication." Customer: "But I had no problems when the code came to my phone." Support: "Yes, but NIST recommends that we don't use SMS 2FA" Customer: "What's NIST? I'm finding this very frustrating, I need to get into my account."
- Hello71 2y agoit would be most convenient to have no 2FA. hell, skip the password too, then nobody will forget theirs. security is tradeoffs, but NIST says "if you take security seriously, you should not use SMS 2FA".
- LordKeren 2y agoIt’s all a gradual improvement over time though, as both companies are able to adopt better practices and customers become accustomed to it. Many, many more people are using TOPT than a decade ago.
- akira2501 2y ago> Customer: "But I had no problems when the code came to my phone." "Unfortunately, many of our other customers, and customers of other financial institutions were not correctly protected by the code alone.. and were still getting scammed or confused.. and losing _all_ their money." > Customer: "[...] I'm finding this very frustrating, I need to get into my account." "That is understandable, but we take the security of your account and your personal information very seriously, and this requires us to make changes to maintain that security in the face of new threats and actors as they evolve."
- Terretta 2y agoStop threatening me. And what does Hollywood have to do with me logging in?
- brandon272 2y agoIt is very much software-world-thinking to believe that dismissive Kafkaesque responses that just shut down the conversation without addressing the fundamental issues around usability and customer satisfaction will ameliorate the situation. For a lot of service based businesses they see their customers face to face and it is imperative that the customers have a seamless experience. Imagine having a business where customers who can't sign into some online system you have are bringing in old Android phones and wanting help from your staff members on how to get 2FA set up on those devices and it is easy to understand why many such businesses settle on SMS based 2FA.
- akira2501 2y ago"We face this. It's about 5% of users. Our margins are large enough we don't worry about this segment. They need our service more than we need them." - Any Large Bank Anywhere
- brandon272 2y agoMost large banks already largely offer non-SMS 2FA through their companion mobile apps. This is about pretty much every other service you have that does not have a dedicated mobile app and doesn't want to teach their users how to manage your 2FA codes.
- xp84 2y agoThe problem with the above statement is that merely “offering” a better option doesn’t solve the issue. The mere presence of SMS as one option gives the same risk as if it were SMS- only. An attacker can choose the sms option (after slipping $100 or even just a fake ID to the teen at the phone store to sim-swap you) even if you never would use it. It needs to be at minimum able to be permanently disabled on demand.