Twitter lets you use 2FA without a phone number
twitter.com
twitter.com
[1] https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
More importantly, there simply isn’t a reason why TOTP, a superior actually secure 2nd factor that doesn’t rely on a third party, can’t be offered, unless you want to force the user to cough up their phone number so you can track them.
Just because the second factor can be compromised, doesn't make it useless. Pretty much any security mechanism can be breached, it's all about increasing the difficulty of an attack until it matches the value of what you are trying to protect. SMS 2FA protects you against untargeted attacks like credential stuffing, which is probably sufficient for 95% of people.
You must have not followed any SIM-jacking story, which is the point of this entire thread.
1. They don’t need your password because their goal is a password reset through your recovery phone, or recovery email address “secured” by a recovery phone.
2. They do social engineering on telecom employees (or outright buy them out for a pittance) to not only get access to your messages, but take over your entire link to your cellular network. You’re not involved in any of this.
TL;DR: the second factor makes you less secure, not more. It’s a downgrade from a secure password. It makes you defenseless.
Don’t even get me started on physical security keys. I could hardly even convince myself to use one, let alone always having at least one backup. Imagine asking my mom to do that.
At the end of the day, the average Joe needs a recovery mechanism that’s not tied to their memory and doesn’t make their everyday interactions a pita. Phone number is just one step below government IDs (which people would be uncomfortable to supply for most sites) and the challenge response could be easily automated, making it ideal. It’s being ruined because of the incompetence of telecom operators.
I wonder if requiring physical appearance with government ID for a SIM change, and making fraudulent SIM issuance a fireable offense would drastically cut down on SIM jacking. (Before anyone points it out, I do envision fraudsters applying for telecom jobs just to do this.)
Now, I’m not arguing TOTP without recovery phone number shouldn’t be an option. I opt into it whenever possible.
Well, I haven't seen a single person who wouldn't have one. We use them for cars and houses, though.
And credit/debit cards, I bet you have them too. It's a physical security key to the ATM. Classic 2FA spirit: something you have (the card) + something you know (PIN code).
The point is, people don't have problems with physical security keys. Programmers do (and hardware vendors) do, which means no standards and clunky UI.
Physical U2F keys get in the way of all-digital flows. They also need to interact with all kinds of non-dedicated devices, something they do a less than stellar job of. Bluetooth and NFC keys are young, setup process isn’t great and reliability seems to vary; USB keys require a USB port which might be occupied by other things or available only in another physically incompatible shape.
The keys aren't the problem, the engineers are. In this day and age, every device should have a digital keyhole (NFC, whatever) - and it should not take more than "insert or hold X next to Y".
Re: "physical process": something tells me you didn't type this message telepathically. UX is a physical process, and 99.99% of the time, it's doing something with your hands anyway. (Alexa/Siri/OK Google are a different beast).
If every other phone can have a fingerprint scanner, it can have something for actual keys too.
Moreover, imagine this: your devices could have built-in hardware keys that you can register with your bank/etc should you desire that convenience.
Still proper 2FA: your phone number is just an account, which is at the whim of your service provider, but your device is something you have.
It's a bit of an "eggs in one basket" situation, but given that people tend to use the same password everywhere, I see it as strictly a step up since it's much less likely for your password manager to be compromised (targeted attack in most cases) than for a site to be hacked.
Once everyone is using password managers consistently, then we can start to talk about TOTP and other 2FA tools, and at first only use it to secure the password manager.
Once we solve the password manager problem, most other problems go away. You don't need to reset passwords if you have it in your password database (your computer won't forget it). You don't have to come up with passwords that match some arbitrary set of requirements, you let your computer do that. If you get recovery codes, stick them next to your passwords in your password manager. If there's a breach, your password manager can likely tell you which accounts are affected, and you can just change those instead of every site that you use that password on.
So yeah, 2FA is nice, but improving how people use the first factor is far more important and actually makes peoples' lives easier.
Breakable != useless.
It's not about your password. It's about social engineering. Bad guys call their buddies at some mobile phone co. and get your number switched for a few minutes, then they call your bank and get them to change your password which they do because they trust SMS 2FA which now goes to the bad guys, and then they take your money, and you find out much later. Password quality has zero to do with any of this.
(The other use of SMS which is somewhat legitimate is as a cost gate to create new accounts. Generally creating a new SMS receiving phone number costs someone more than a new email, so if you want to crudely limit creation of large numbers of accounts by individual users, it can be an option.)
In many other part of the world, Switching Sim ( SIM Swapping ) requires to show proof of identification, as well as written form and signature.
And any CS accessing customer information are instantly logged, there is no way paying $1000 dollar to change or SIM Swap without going through the proper procedure, ( Should there be one ) and they will be fired for any misconduct.
SMS might not be the best solution to security, but for average Joe, that is near 4 billion of Smartphone users they are better than nothing.
May be had Apple created their own MVNO this problem could be solved.
Forgot your password - reset your password - get an SMS
When there is no second factor involved, it's not 2FA despite people calling it that.
They send to your email.. They use TOTP. They use Oauth, etc, etc. What other things accounts go back to either your SIM or someone stealing your phone, SIM and all?
Even U2F will fall down this hole soon since everyone wants to implement it on phones! Will the attestation certs for phones say multipurpose device that is probably involved in other factors?
Telcos don't get paid to securely provide SIMs. They make hardly any claims regarding the security of your calls, text messages, etc.
So it is rather odd to hold telcos reponsible for the failure of some security mechanism they where never part of.
The fact something is important to you, and you failed to negotiate that in your contract, doesn't mean that the company providing the service is somehow required to take that into account.
If you order food in a restaurant and someone takes the food from the waiter before you can have it, what would you want the restaurant to do?
It's like going to a fast food restaurant and later complaining that the meat is of low quality.
If I entrust my email to Google, them having corrupt employees who give my email to other people would be a serious issue, for security, privacy and a myriad of other reasons. This is exactly what's happening at phone companies.
Telcos have a very poor service for the extortionate prices they charge. At some point your phone number is tied to your identity and should be secured as such (ah but nobody cares about that right?)
By the same logic, no company should ever be held responsible for harm to users of their products caused by product defects: after all, they never made any claims regarding their products being safe to use.
Of course, no phone contract says anything about securing SIMs (for the purpose of authentication). So it cannot be a defect.
Safe to use is often in relation to bodily harm, which doesn't apply in this case. Outside any specific law, if you use an unencrypted text messaging service between subscribers for authetication purposes, then you are on your own.
In this case, the actual harm is caused by the companies that decided to use text messaging for authentication purpose without verifying that the underlying service is fit for porpose (or having a contract with telcos that explicitly lists this purpose).
Of course, nobody is going after twitter to recover damanges from them.
It is known that there are security issues with ss7 specifically [0][1][2] and the global telecom network was, it seems, never secured. I would conjecture that there are some other problems with mobile phones[3] some that we are not aware of.
I also am in lock step with your claim that this should not be surprising.
Telcos are indeed not paid for security. The security of the telephone network must not be counted on. In fact, military and government business must often be executed on special non-public phone exchanges or SIPRnet. Telcos do not offer any security guarantees, and are rather obstinate toward any demands such as this. Negotiating a more secure service is impossible.
>So it is rather odd to hold telcos reponsible for the failure of some security mechanism they where never part of.
It is certainly not odd. If the general public wakes up and their assigned phone numbers are meaningless, all of their customers will be unhappy, it simply wouldn't pass the sniff test of a 6-year-old.
However, there is positively no incentive for anybody to shop for security in this space. Few living people believe or can even fathom that there could be a problem with using their phones in this manner. Despite the public fraud[2] that has been enabled by the Telco's apparent lack of any security engineering, the market is not providing any security mechanisms for this, I would imagine in part due to the concessions on interoperability made during the development of these global telco protocols.
There (appears to have been) zero work done for the security of this critical system. Customers do not recognize any possible threats, telcos have no interest in improving their networks in this regard, the US government has developed a nickel allergy towards telco regulation in the 30 or 40 years following the 'Bell conclusion. Finally telco's don't care to change, and if they did there would be decades long disputes regarding implimentation.
No, it is wholly unsurprising to find an entrenched, obstinate partner in this field.
[0] https://www.schneier.com/blog/archives/2014/12/ss7_vulnerabi...
[1] https://simjacker.com/downloads/technicalpapers/AdaptiveMobi...
[2] https://arstechnica.com/information-technology/2017/05/thiev...
[3] https://www.schneier.com/blog/archives/2016/09/leaked_stingr...
An argument can be made that this hassle is worth it for security concerns (which is what they often tend to be sold as) but personally I find it less reasonable for preventing against SIM swap hacks when there are many alternatives to SMS 2FA.
getting a new card is not the same as swapping
I have some rope at home. The manufacturers specify it's blue, 8mm, polypropylene and for 'general use' but they don't say anything about its strength. Cost about $5.
If I lift something with it and it breaks, is it the rope's fault, or my fault for selecting the wrong rope?
SMS is the same way - is sim jacking the telco's fault, or is a company using SMS 2FA as dumb as lifting a piano with my $5 rope?
Minimum wage employees don’t give a shit. Always exploited.
I think the only reason they haven't is because they don't want the customer service headache that running & supporting a network generates.
Bad signals, stolen phones, billing etc. Urgh.
The protocol/network used for international SMS (SS7) is supposedly very insecure and can be used to hijack messages.
https://simjacker.com/downloads/technicalpapers/AdaptiveMobi...
Is it safe? I don't know. Doesn't seem to be a widely used standard. Haven't found technical details. Only a mention of "cryptography" in the marketing material. So yeah, I don't really feel much safer.
-- You can't provision more than one security key. I want to provision a backup key.
-- You must have TOTP or text-message 2FA enabled in order to use a security key. But the very reason I want to use a security key is because I don't want to trust my phone!
Maybe they're too lazy to do the work?
They're actively trying to discourage good practice?
There aren't any good excuses.
Hashicorp vault has something like this to generate a root token. You can split your unseal key according to shamirs secret sharing. You can bring together a specified number of unseal key shards and generate a new root token with them. The app had endpoints to manage all this. You could create your own app with your own endpoints with similar functionality.
I don't think there are cryptographic primitives to give you this easily, without some trust logic baked into the app layer.
Do you have an example of such a system? I would be curious to read about the motivating use case.
IMO TOTP or even U2F have serious over the shoulder and grabby partner kinds of problems compared even to needing to type with semiprivacy.
Technically, in PAM, etc you could always add multiple rules.. But mostly this devolves into RBAC with separate roles so 1 type of admin does each step, but an absent admin is replaceable with another of the same type.
I tried to push a change/publish approach over a more traditional RBAC approach once, but it didn't fly.
To use TOTP then Alice and Bob have to contribute their shares to something, that something has to combine the shares to recover the key, and then generate the TOTP code for the current time, which it sends to S (or sends back to Alice and/or Bob who sends it to the server?), which knows the seed and generates the code for the current time, and checks to see if they match.
The question then is what handles the share combining? You'd need some sort of intermediate party that just receives shares and computes the TOTP code for sending to the server (directly or indirectly). Alice and Bob have to trust that this party will not keep the shares or keep the recovered code because then the entity could generate the TOTP code at will in the future without Alice or Bob's input.
It would probably make more sense to just have the server keep separate TOTP seeds for Alice and Bob, and authorizing requires Alice and Bob to both send their separate TOTP codes to the server.
Where things like secret sharing shine is when you have a secret that that S is not suppose to know persistently. For example, we use it at work for a database with sensitive data. The data is encrypted, with the key in non-paged RAM. When the server starts, a couple shareholders enter their shares, which reconstructs the key. If someone were to steal the server itself they would not get the key.
After that, I tried several examples from the man online man page [1], copying/pasting from Firefox to a terminal. Many of them failed, with errors like "oathtool: hex decoding of secret key failed".
To save others time...get your examples for copy/paste by doing "man oathtool" in another terminal and copying from there. The online manual has the dashes in arguments like "--totp" and "-w" rendered as Unicode minus signs (U+2212). Command line arguments need good old fashioned dash (U+002D).
There's an email address at the bottom of the page for reporting bugs, but my email client didn't like it. Sure enough, there are dashes in the email address which on the web page are Unicode minus signs, so had to grab it from the man page to send off the mail.
There are desktop and phone apps for it, which works great with nfc yubikeys on mobile.
There's plenty of others obviously, phishing is an infinite sea of crazy ideas, but that's a few huge ones gone.
The reason Security Keys (ie WebAuthn/U2F) doesn't get phished in this scenario is that the human's worthless opinion about whether this is the correct site isn't used by these technologies. Your WebAuthn credentials submitted to the utterly convincing phishing site fake-bank.example don't work for your real-bank.example login and the phishing fails.
Add TOTP, add security key, then delete the TOTP token from your phone.
At that point, the only copy of the TOTP secret is stored on Twitter's servers.
https://support.1password.com/one-time-passwords/#use-your-o...
As for limitation of one key, I use my Yubikeys with TOTP as well, so for services that don't support more than one security key, I store the same TOTP private key on both my security keys and get around it.
USB-C works fine with the Yubico authenticator app, IME. Using a Yubikey 5c.
Haven't used the lighting one, as I don't have an iPhone. Probably fine.
The one annoyance is that there's no USB-C + NFC key yet.
Edit: on my old phone I also used a USB-OTG (Micro-B male to A female) adapter with a normal Yubikey4, which worked (but was an ugly kludge).
That's an interesting threat model that I don't hear very often. Can you expand on what threats you're trying to protect against? If you ever sign in to Twitter on your phone, you're trusting your phone with your Twitter account at least to some degree.
The main thing security keys protect against that TOTP doesn't is phishing.
And even if you are already signed in to everything and think you won't ever need to sign in on your phone again, the malware can force a logout of something, and you won't be able to know if it was just some software update or expiration that signed you out. So you'll sign in again, and the malware will intercept your security key.
I almost never use Twitter on my phone, and if I switched Twitter to depend on my Yubikey, I would stop using Twitter on my phone completely.
Is remote desktop compromise less likely than remote phone compromise? Phones tend to sandbox each app, so a single malicious or compromised app cannot take over your phone. Desktops on the other hand allow any app to do essentially anything on your computer. Accidentally open a malicious email attachment and you're done for. Generally I consider machine/phone compromise outside of my threat model.
Is security key theft less likely than phone theft? Also, phones generally require a password or fingerprint or face to unlock, while security keys generally do not (Yubico announced a fingerprint-protected one 18 days ago, but it's not available yet).
I bring my phone with me in lots of circumstances where I don't bring my security key, so yeah I think it's more likely to be lost/stolen.
Also, TOTP has a MITM problem that U2F/Webauthn doesn't have.
I personally think the reason they require both to set up a security key is a user recovery issue. TOTP is highly reproducible and a security key is not. You can't back up your private key (by design). You just have to buy several and store them separately. I can encrypt my seed, put it in a QR code, and print as many copies as I want at no cost. If my backup Yubikey fails, I'm toast if I need recovery.
So I spend money buying burner sims. I can. But normal people can't. They use phone numbers more than IP addresses to uniquely identify people. Never use apps if you can use a website!
And screw these companies that are sneakily hostile against their own user base.
If you can actually submit a support ticket, get them to agree that a phone number is not required (like it says on their website), and to reply when that's done, you'll get your account unlocked after a few days. (usually)
2010-2019 has been the smart phone decade and now it's coming to an end. I'm celebrating by letting my cell service expire. My smart phones leak way too much data. I'll be using my too-smart phones like an ipad, making and receiving calls and texts only when I'm connected to WiFi at home.
I don't agree to any TOS with tinder and I really doubt they "delete all my information" when I delete the account like it says.
In fact my guess is they just leave your profile active if it's popular to encourage other people to "match" with you.
I wouldn’t go to the extent of saying they don’t do it, but I think it’s very unlikely due to the nature of their service. It’s different of, say, Facebook, that can do it without anyone knowing. If I got into a relationship and close my Tinder account but they kept it alive, a single friend can find it and tell my partner. If this happens too often word will spread that something shady is going on.
The whole login security ecosystem across the web is in a state of high entropy flux. Some websites still don't offer 2FA, some only do text, some demand text, some don't even offer text, some offer authenticator apps, some force specific authenticator apps, some offer hardware tokens, some allow only a single hardware token, ... The U2F hardware tokens themselves are only compatible with some of your devices due to the variety in ports, etc.
And a typical person will have to have an account with ~100 different places that they want to use with continuity across multiple devices.
Re U2F keys: I think I would prefer a security model where I provision a U2F key based on some master secret stored in a "secure" but accessible way, i.e paper. Then I could create a new key with the same secret when I loose or break the first one.
Having two U2F fobs seems almost like having two different locks on all your doors, setup so that only one is needed to open the door.
But for security you should still have at least two U2F security keys using different master secrets (if you lose one security key, you can deactivate it without deactivating the other).
I implemented 2FA server and frontend support at some point and it's stupidly easy to do. It's arguably a lot easier to do than building SMS based 2FA because you don't need the integration with SMS. All you do is show a QR code, store the shared secret, and then run a simple algorithm to verify the current code and timestamp line up with what the user typed when they login. The algorithm for generating codes compatible with Google Authenticator, Authy, etc. is available in OSS form for several languages. Same for QR code generation. The rest is bog standard UX work and a bit of DB plumbing.
You could already disable SMS 2FA after enabling TOTP, but removing your phone number completely used to disable 2FA.
Now I wrote to their support after reading this and I am very interested in their response.
I think if they go on trying to force me I will just delete the account. This is the only thing that helps those companies to understand their users needs when they have problems listening or seeing them on their own, I'm afraid.
If you log into your account and turn off SMS-based 2FA it also turns off TOTP-based 2FA!! Fortunately I wanted to switch to a different authenticator anyway (twitter buried their TOTP tokens deep within the android app).
Now, it could be nothing, but I came to a personal realization just how valuable a telephone number could be for such a well-positioned company to do a deep-dive into a person's background just by using their mobile number as the key to tie additional records to the user's identity. Or their activities before, during, and after a company's conference.
To answer your question, I believe that Facebook wants the (mobile) telephone number of their users to facilitate any number of additional uses, and "account security" is one actual use that lets it slide under the radar of most people. Clever! (Or depending on your POV on privacy and personal security, unfortunate!)
Most companies ask a customer for a telephone number in their forms and in their applications. Actually, just about any context where the customer's mobile device is not the item of attention. This was my first encounter with a company that specifically requested a mobile telephone number in their application. This unusually specific request illuminated some interesting possibilities in my mind.
If you experience circa 2014 has been different, actually, that's great! I'd like to see and compare some similar event applications around that same time period. (Still, it was the possibilities for the uses of a mobile number that really flagged my interest as well as the relevance to this conversation, not the rarity today of companies specifically requesting a mobile number.)
Did they use those exact words? Sounds strange to me as most American English speakers would say “phone number” or “cell phone number”, and both are used pretty much synonymously (because in practice they basically are) for a long time. More formal forms (government forms) might ask for something like “daytime phone number”. In particular I haven’t seen the word “telephone” in ages.
They weren't asking for home number, work number, and mobile number. Or as you mentioned: daytime number, evening number. It was more along the lines of: Name, Address, Mobile Number, Company Name, Job Title, etc. They specifically wanted a mobile number and no other type of number.
Were they wanting a mobile number so they could more easily research an applicant using their internal tools? Only they would know. But it drew my attention to the possibilities and the importance of obtaining a mobile number.
Back to OP's question, part of the reason a mobile number is required to create a Facebook account may be to help tie different types of records together. Of course, as mentioned, there are other reasons, such as security. Users will understand and provide a mobile number for that reason alone.
In business settings it’s still pretty common to ask for a cell though, or so I thought.
I ported my primary phone number into Twilio years ago. Most apps/websites have no problem with a `voip` number type. But some systems, including Twitter, have refused to accept it.
It's extremely common in the USA since most people in the usa have phone plans that include unlimited MMS and SMS, third-party chat apps like WhatsApp never became ubiquitous here as a result of that basic functionality being available through the phone.
I think most people here use either Messenger or iMessage, the latter being the case in my circle of friends.
I use Google Voice and my family uses group text to coordinate things like dinner. I only knew about dinner because my wife gets the group texts.
GVoice eventually fixed the group text problem, but I don't get all the messages and I get them out of order. I also get other group texts with important info that I wasn't getting before.
I have no idea how many other group texts I'm missing out on that I might actually want to be a part of or was missing out on. Everyone assumes that group text works with all recipients all the time, and since it has no way of telling the sender it failed to deliver, no one ever follows up.
A few years ago I was frustrated about paying CA$100/month for my phone plan in Canada for unlimited talk/text and a few gigs of data a month. I realized I only needed the data.
I wrote an app that directs phone calls straight to voicemail and then emails the missed calls and voicemail transcription and mp3s. SMS messages are sent to email and email replies get sent back as SMS. I made this a product at https://ringer.io.
I also picked up two CA$15/month data only SIMs (3GB each) from Fido.
So now I could only receive voicemail and I would use Google Hangouts Dialer to make traditional phone calls, which was very rare. I have to admit it was awesome not having the ability to receive a phone call.
I used WhatsApp day-to-day for texting and video calls.
Eventually the need to receive calls kicked up a notch so I switched my number over to https://openphone.co for US$10/month. They are on Twilio as well so it was a painless port (ie: one API call).
The OpenPhone app is "good enough" for me. If I had to talk a lot using traditional phone calls I would pay for a dedicated talk/text plan.
But I'm happy paying CA$30/month for 6GB of data and US$10/month for the phone/text line.
EDIT
Looks like a bug. Deleting the phone number gives no such warning, and 2FA continues to work.
A 2FA system that requires me to give a phone number is a 2FA system that I won't use. I'm not about to give my phone number out to most companies, and I'm too lazy to go get a burner phone just to set up 2FA.
I get the account unlocked after a few days if I pester support about it. (which is not easy either)
All this and I only need the damn thing for my data analysis course.
SMS based 2FA is a farce, I look forward to it going extinct.
[1] https://www.paypal.com/us/smarthelp/article/faq4057
[2] https://transferwise.com/help/12/managing-your-profile/29321...
You can't realistically "back up" cheap Security Keys, their whole design is predicated on your being unable to extract the secret inside them which makes them work.