Phone Numbers Stink as Identity Proof
krebsonsecurity.com
krebsonsecurity.com
edit: there is another account linked to this phone number I activated last week. I could log in as that user as well. When I chose to recover my account and entered my phone number, Facebook listed all the accounts linked to this phone number.
edit2: of course, I can also log in to these people Instagram accounts
And it's totally a Catch 22 for the previous "owner" of the number. Once they've lost the number, any glitch in status of linked accounts that requires phone authentication will lock them out. So if they forget to update authentication numbers promptly, they risk losing control.
What a mess.
The yahoo example is horrifying.
Apple is going BACKWARD on this amateur-hour practice, now requiring your Apple ID not only to be an E-mail address... but a WORKING one.
Stupid: https://goldmanosi.blogspot.com/2012/06/forcing-people-to-us...
Otherwise you're leaving an opening for someone else to come along later, set up that address, and take over your account.
It’s personally annoying to me how many 2 factor equipped sites force the use of SMS as the second factor. I imagine the conversation with the PO/PM for the feature must frequently include discussion of fears that allowing customers to opt out of SMS 2FA and use their own code generation tools is risky; you are relying on customer not screwing up to keep them as a paying customer.
They lose their personal Authenticator and recovery keys, it can be really awkward to fix. SMS could be argued to be superficially more attractive in this regard, given a cell number can be reissued unlike the permanently lost authenticator device/app. Of course the security of SMS 2FA is terrible etc, but I can understand some of the fear of the alternatives if you need to keep customers happy and able to actually use your service.
Or, you know, just travel to a jurisdiction where I can't get SMSs from my home SIM.
By comparison one-time pads have been substantially easier to keep around and protect.
Recently I wanted to log in to AirBnB. I hadn't signed in in 3 years. I was welcomed with a nice "We don't recognize this device. Get a code by text message or phone call at <number at my previous country of residence>." The thing is, I use social login on AirBnB! Specifically because I want to delegate MFA to a service where I'll keep my profile and login information up to date. I don't remember agreeing to my phone number being used as a second factor or as a way to recover my account. So I contacted their customer service and they unlocked my account within 2 days, without any further verification.
Had to do this last week, VPN to my home country to enable code via email.
Sheer stupidity.
2. use a DID from that service for your 2FA
3. use a softphone app with SMS support to receive 2FA codes (or just have SMSes sent to that number forward to your email; either or)
4. when in a new country with a new SIM card, just make sure to sign up for data. Then you'll continue to receive your SMSes like normal. And your phone calls, too!
(It's honestly insane that this isn't just... how phone infrastructure works, though.)
Except for the myriad companies who flatly refuse to permit their customers to use "VoIP" or "virtual" or anything-other-than-mobile numbers for SMS-based 2FA.
My personal favorite is Zelle. I got a terms of service update a month or so ago, "you will no longer be permitted to use Google Voice other other VoIP or virtual numbers for Zelle and must provide a cell phone number to continue." Except that my cell phone service is provided by a company that buys blocks of data service and voice and SMS ride on that data, so the number "validates" as a VoIP number.
I contacted my financial institution, "what do I do you have this number and it's worked great and it's the only number I have." Sorry, can't use Zelle any more.
(a) t-mobile is famous for being socially engineered to give out sims on other people's accounts.
(b) I have no loyalty to this plan. I've had 5 or 6 underlying phone numbers since I started using grand central (now google voice) in the 2000s. I don't even know what my t-mobile number is (i have to look it up on my phone's settings).
No 2FA (or KYC/AML) processes flatly reject my number, because it looks entirely legitimate to their heuristics. Still, sometimes the actual activation codes just mysteriously never arrive. Then I switch to using the actual DID associated with my (data-only) SIM, and the codes arrive instantly. I'm not sure whether this is their sending system being smarter about virtual numbers than their pre-check heuristics; or if it's just some weird gateway failure between my old and new carriers when (I presume) they try to forward the SMS from their SMSC to the VoIP carrier's SMSC.
No way am I going to spend big money for a cell phone plan when I also have to pay top dollar for a substandard landline and DSL. Sure, I could just use it when I am out and about and find some alternative way to get calls when I get home, but why reward the phone companies for underinvesting.
It used to be I could get a prepaid phone that was pretty good but the last few ones I have tried I had awful coverage, maybe they are only using Sprint for their networks now.
But one thing that I've found beneficial is that a lot of modern smartphones support wifi calling. I haven't had a single dropped call in my basement since enabling it.
Yes, someone could get your phone number someday. And someone could get your password someday. But it's much less likely anyone would get both at the same time.
Stupid question, is it straightforward to change the phone number you are using for a second factor for most web sites?
And that's a factor you don't have complete control over and once you lose, you lose forever.
The best part? Right, you can lose your phone number if you lose your phone, because T-Mobile allows one to reset their account via SMS.
You can lose your phone number if you misstep just once. My mom got one of those scam calls from people pretending to be customer service. They asked her to read off the numbers from an SMS to verify her identity, and she did.
She got lucky because the account is in my name. Otherwise, the scammers would have had complete control over all lines. They'd have transferred it to themselves, amd used that to take over ALL other accounts.
And that has happened many thousands of times:
https://motherboard.vice.com/en_us/article/gy8bxy/t-mobile-t...
Faxing in photos of ID is just asking for someone to forget to delete it too, having it end up in some data dump one day
This seems much more trustworthy to me than mobile phone numbers.
However I am curious to hear counterarguments, if there are any.
Are you saying that speed affects trustworthiness?
When a call is made or a text is sent to a mobile number is is not addressed to anyone in particular. It is addressed to the number only.
Mobile phone "MFA" only proves someone has access to the SIM card. It could be anyone.
When a letter is sent to a mailing address, it can be addressed to a particular person.
In many countries, there are laws that protect postal mail from tampering.
Bonus: phone number databases are used in online tracking for connecting accounts across many websites to datamine more accurate data and form better profiles. Everyone privacy minded should be aware of this.
Obviously it would be better to not reuse passwords, but in general it seems to be easier to encourage users to do 2FA than to not reuse passwords.
Phone numbers combined with SMS are not perfect, but they are something the average user has, something that the average user can recover (if they lose a phone, they can get a new one but still keep the same number). No, they are not perfect, and if you are being targeted, they will not help you, but most people are not targeted, but they do use bad passwords and using phone numbers as the 2nd factor improves security.
I bought a bunch of Yubikeys and tried giving them away like candy to friends and family. I couldn't even give them away; people still weren't interested, including several developers (!).
We'll never be able to save everyone, so my only wish now is that for the people who do care, everybody implements 2FA/WebAuthn properly and uniformly. Even that we're so far away from. Maybe eventually we'll get to some level of herd immunity, where >90% of accounts are 2FA protected, so trying to exploit them is a massive waste of time, and can be detected early.
I'm a developer and I own a couple of Yubikeys that I picked up to play with the concept. I don't actually use them for real authentication, though.
Now, I know that I'm a weirdo, but the reason I don't use them for real is because they're less convenient for me than just using unique, strong passwords.
I'm not surprised nobody uses them.
The only practical application I can think of is some sort of central authority configuration like a corporation where yubikeys are given to employees.
sure, somebody could steal it, but I'm bit going to lose it
The technology appears fine, it’s the culture/industry norms that aren’t catching up. Until you can reliably and easily use it most places in most browsers it’s always going to be a niche solution for security geeks.
I do think they have great potential in the workplace though, especially the nfc ones - the same yubikey could be used for both physical door access controls as well as online services like email etc.
I experimented with requiring the yubikey to unlock my MacBook, but the risks are enormous, even with a spare yubikey. Lose the yubikeys and getting your personal data off a FileVault encrypted volume is going to be great fun I imagine...
My problem is what if I lose it. I know there are ways round it, but it's a layer of complexity passwords just _don't_ have. That's enough of a hurdle for me.
In addition to (hopefully) cutting down on spam calls, it's much much harder to hijack my google account than a cell phone account
(Just be sure to turn call and text forwarding off)