3 ms·
This is utter stupidity. Somehow voicemail PIN weaknesses translate to being able to intercept SMS's? Security is about systems, not individual components. T
by poutine 13y ago
This is utter stupidity. Somehow voicemail PIN weaknesses translate to being able to intercept SMS's?
Security is about systems, not individual components. Take a random Internet service protected by passwords and add a second factor to the login step where after login and password you must enter a code that gets SMS'd to your preconfigured phone number. The number of fraudulent logins will drop to near zero as password guessing is no longer sufficient to break in to an account. The number of attackers that will be able to attack your login page and intercept SMS's for a specific user within the phone network is limited to three letter agencies.
The best security is security that people will actually use. Virtually everyone has a mobile phone and thus why the SMS channel is attractive.
Sure, this isn't the be all and end all in security and an app like Google Authenticator is more secure but SMS as a second factor is ideal for most consumer applications.
- pfraze 13y agoIn the case he cited with CloudFlare, the phishing the voicemail was a pretty effective attack vector. Also, where does he tie PIN weakness to SMS interception? They're uniquely vulnerable. > Take a random Internet service protected by passwords and add a second factor to the login step where after login and password you must enter a code that gets SMS'd to your preconfigured phone number. The number of fraudulent logins will drop to near zero as password guessing is no longer sufficient to break in to an account. I think you're mitigating one set of risks while adding others. EDIT: just want to add, I do think UX should be a primary concern of security; I just disagree with your analysis of his post.
- poutine 13y agoOh really? You think that login+password is a trade of equal risk with login+password+sms? Sorry, but the second is clearly has much less risk. Twitter introduced SMS authentication as a second factor. Do you really think that their number of fraudulent logins for users protected by that second factor hasn't gone down to near zero?
- pfraze 13y agoI think some of the use-cases are getting mixed, including by myself and by the author. I do agree that 2FA, even with cell-phones, will improve the security of the web interface. The CloudFlare breach was caused by using the phone as an independent authenticator (overriding the password) which is not 2FA, as I understand it. And I agree, the likelihood of SMS interception or spoofing during the verification process seems pretty slim. I'm going to bow out to the security experts at this point.
- pyre 13y agoIIRC, GSM has been cracked. I'm not an expert, so I'm not sure how this affects SMS, but as SMS is done via a control channel (that was not originally intended to be used for text messaging), I'm assuming that there are no extra protections there. Granted, this requires physical proximity though, which definitely raises the bar for any attacker.
- poutine 13y ago> EDIT: just want to add, I do think UX should be a primary concern of security; I just disagree with your analysis of his post. Fair enough. I think the interesting thing to debate is his conclusion: that two factor auth using SMS is so flawed as to be avoided completely. That's complete nonsense.
- niels_olson 13y ago> Security is about systems That should be the top comment. Having done force protection for an aircraft carrier before, during, and after 9/11, it's all about systems. We involved nation-states in this. All our systems and all their systems. It took months if not years of planning, advance trips, meetings in SCIFs and prestaging assets to bring one of those into a foreign port. Lasers, standoff air defense, dolphins, guys in in cafes "reading the paper". Training 2000 sailors on .50 cal, shotgun, 9 mm. Boat teams. Here's us getting underway from Virginia a week after 9/11: http://m.usni.org/magazines/proceedings/2001-12 http://m.usni.org/magazines/proceedings/2001-12 People with no dog in the fight, famously the older warrant and limited duty officers, guys who came up through the ranks for 30 years, would continuously poo-poo my plans. "What if this...." "What if that..." Toward the end of my tour, the fleet force protection officer, a senior SEAL commander, drug my counterpart from another ship in, an old warrant officer who had been doing physical security since before I was born. The SEAL drilled our team on scenarios in front of this other guy for an hour. Then he turned to the warrant and said "These guys might take the first hit, but I know what they're going to do. I can count on them. I can plan around what they'll do. I have no idea what your ship is going to do. Fix it." Screw the what-iffers, but make sure you can annihilate their what if scenario twice before it ever comes to that. Take ownership of you defense. Take you job personally. Use the what-iffers for the cheap war gaming they offer, and then don't worry about them. Get everyone in your organization on board with your plan. Make sure you know who has the authority to pull which triggers, and make sure they're available on the necessary timeline, or devolve that authority to people who are. But don't let the intern have so much authority he can inadvertently start a war. Know what your internal and external reporting requirements are, and why. For example, I'm willing to bet the security of gmail is considered a national security priority at this point. Even if no one in DC can do a damn thing about it. It's been wargamed, and the Pentagon battle watch commander can get a googler with need-to-know on the phone in under a minute. If that googler doesn't know that, he probably ought to have figured out why.