[1] https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
[1] https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
In many other part of the world, Switching Sim ( SIM Swapping ) requires to show proof of identification, as well as written form and signature.
And any CS accessing customer information are instantly logged, there is no way paying $1000 dollar to change or SIM Swap without going through the proper procedure, ( Should there be one ) and they will be fired for any misconduct.
SMS might not be the best solution to security, but for average Joe, that is near 4 billion of Smartphone users they are better than nothing.
May be had Apple created their own MVNO this problem could be solved.
Forgot your password - reset your password - get an SMS
When there is no second factor involved, it's not 2FA despite people calling it that.
They send to your email.. They use TOTP. They use Oauth, etc, etc. What other things accounts go back to either your SIM or someone stealing your phone, SIM and all?
Even U2F will fall down this hole soon since everyone wants to implement it on phones! Will the attestation certs for phones say multipurpose device that is probably involved in other factors?
Telcos don't get paid to securely provide SIMs. They make hardly any claims regarding the security of your calls, text messages, etc.
So it is rather odd to hold telcos reponsible for the failure of some security mechanism they where never part of.
By the same logic, no company should ever be held responsible for harm to users of their products caused by product defects: after all, they never made any claims regarding their products being safe to use.
Of course, no phone contract says anything about securing SIMs (for the purpose of authentication). So it cannot be a defect.
Safe to use is often in relation to bodily harm, which doesn't apply in this case. Outside any specific law, if you use an unencrypted text messaging service between subscribers for authetication purposes, then you are on your own.
In this case, the actual harm is caused by the companies that decided to use text messaging for authentication purpose without verifying that the underlying service is fit for porpose (or having a contract with telcos that explicitly lists this purpose).
Of course, nobody is going after twitter to recover damanges from them.
Telcos have a very poor service for the extortionate prices they charge. At some point your phone number is tied to your identity and should be secured as such (ah but nobody cares about that right?)
The fact something is important to you, and you failed to negotiate that in your contract, doesn't mean that the company providing the service is somehow required to take that into account.
If you order food in a restaurant and someone takes the food from the waiter before you can have it, what would you want the restaurant to do?
It's like going to a fast food restaurant and later complaining that the meat is of low quality.
If I entrust my email to Google, them having corrupt employees who give my email to other people would be a serious issue, for security, privacy and a myriad of other reasons. This is exactly what's happening at phone companies.
It is known that there are security issues with ss7 specifically [0][1][2] and the global telecom network was, it seems, never secured. I would conjecture that there are some other problems with mobile phones[3] some that we are not aware of.
I also am in lock step with your claim that this should not be surprising.
Telcos are indeed not paid for security. The security of the telephone network must not be counted on. In fact, military and government business must often be executed on special non-public phone exchanges or SIPRnet. Telcos do not offer any security guarantees, and are rather obstinate toward any demands such as this. Negotiating a more secure service is impossible.
>So it is rather odd to hold telcos reponsible for the failure of some security mechanism they where never part of.
It is certainly not odd. If the general public wakes up and their assigned phone numbers are meaningless, all of their customers will be unhappy, it simply wouldn't pass the sniff test of a 6-year-old.
However, there is positively no incentive for anybody to shop for security in this space. Few living people believe or can even fathom that there could be a problem with using their phones in this manner. Despite the public fraud[2] that has been enabled by the Telco's apparent lack of any security engineering, the market is not providing any security mechanisms for this, I would imagine in part due to the concessions on interoperability made during the development of these global telco protocols.
There (appears to have been) zero work done for the security of this critical system. Customers do not recognize any possible threats, telcos have no interest in improving their networks in this regard, the US government has developed a nickel allergy towards telco regulation in the 30 or 40 years following the 'Bell conclusion. Finally telco's don't care to change, and if they did there would be decades long disputes regarding implimentation.
No, it is wholly unsurprising to find an entrenched, obstinate partner in this field.
[0] https://www.schneier.com/blog/archives/2014/12/ss7_vulnerabi...
[1] https://simjacker.com/downloads/technicalpapers/AdaptiveMobi...
[2] https://arstechnica.com/information-technology/2017/05/thiev...
[3] https://www.schneier.com/blog/archives/2016/09/leaked_stingr...
An argument can be made that this hassle is worth it for security concerns (which is what they often tend to be sold as) but personally I find it less reasonable for preventing against SIM swap hacks when there are many alternatives to SMS 2FA.
getting a new card is not the same as swapping
https://simjacker.com/downloads/technicalpapers/AdaptiveMobi...
Minimum wage employees don’t give a shit. Always exploited.
I have some rope at home. The manufacturers specify it's blue, 8mm, polypropylene and for 'general use' but they don't say anything about its strength. Cost about $5.
If I lift something with it and it breaks, is it the rope's fault, or my fault for selecting the wrong rope?
SMS is the same way - is sim jacking the telco's fault, or is a company using SMS 2FA as dumb as lifting a piano with my $5 rope?
I think the only reason they haven't is because they don't want the customer service headache that running & supporting a network generates.
Bad signals, stolen phones, billing etc. Urgh.
The protocol/network used for international SMS (SS7) is supposedly very insecure and can be used to hijack messages.
Is it safe? I don't know. Doesn't seem to be a widely used standard. Haven't found technical details. Only a mention of "cryptography" in the marketing material. So yeah, I don't really feel much safer.
More importantly, there simply isn’t a reason why TOTP, a superior actually secure 2nd factor that doesn’t rely on a third party, can’t be offered, unless you want to force the user to cough up their phone number so you can track them.
Don’t even get me started on physical security keys. I could hardly even convince myself to use one, let alone always having at least one backup. Imagine asking my mom to do that.
At the end of the day, the average Joe needs a recovery mechanism that’s not tied to their memory and doesn’t make their everyday interactions a pita. Phone number is just one step below government IDs (which people would be uncomfortable to supply for most sites) and the challenge response could be easily automated, making it ideal. It’s being ruined because of the incompetence of telecom operators.
I wonder if requiring physical appearance with government ID for a SIM change, and making fraudulent SIM issuance a fireable offense would drastically cut down on SIM jacking. (Before anyone points it out, I do envision fraudsters applying for telecom jobs just to do this.)
Now, I’m not arguing TOTP without recovery phone number shouldn’t be an option. I opt into it whenever possible.
Well, I haven't seen a single person who wouldn't have one. We use them for cars and houses, though.
And credit/debit cards, I bet you have them too. It's a physical security key to the ATM. Classic 2FA spirit: something you have (the card) + something you know (PIN code).
The point is, people don't have problems with physical security keys. Programmers do (and hardware vendors) do, which means no standards and clunky UI.
Physical U2F keys get in the way of all-digital flows. They also need to interact with all kinds of non-dedicated devices, something they do a less than stellar job of. Bluetooth and NFC keys are young, setup process isn’t great and reliability seems to vary; USB keys require a USB port which might be occupied by other things or available only in another physically incompatible shape.
The keys aren't the problem, the engineers are. In this day and age, every device should have a digital keyhole (NFC, whatever) - and it should not take more than "insert or hold X next to Y".
Re: "physical process": something tells me you didn't type this message telepathically. UX is a physical process, and 99.99% of the time, it's doing something with your hands anyway. (Alexa/Siri/OK Google are a different beast).
If every other phone can have a fingerprint scanner, it can have something for actual keys too.
Moreover, imagine this: your devices could have built-in hardware keys that you can register with your bank/etc should you desire that convenience.
Still proper 2FA: your phone number is just an account, which is at the whim of your service provider, but your device is something you have.
It's a bit of an "eggs in one basket" situation, but given that people tend to use the same password everywhere, I see it as strictly a step up since it's much less likely for your password manager to be compromised (targeted attack in most cases) than for a site to be hacked.
Once everyone is using password managers consistently, then we can start to talk about TOTP and other 2FA tools, and at first only use it to secure the password manager.
Once we solve the password manager problem, most other problems go away. You don't need to reset passwords if you have it in your password database (your computer won't forget it). You don't have to come up with passwords that match some arbitrary set of requirements, you let your computer do that. If you get recovery codes, stick them next to your passwords in your password manager. If there's a breach, your password manager can likely tell you which accounts are affected, and you can just change those instead of every site that you use that password on.
So yeah, 2FA is nice, but improving how people use the first factor is far more important and actually makes peoples' lives easier.
Just because the second factor can be compromised, doesn't make it useless. Pretty much any security mechanism can be breached, it's all about increasing the difficulty of an attack until it matches the value of what you are trying to protect. SMS 2FA protects you against untargeted attacks like credential stuffing, which is probably sufficient for 95% of people.
You must have not followed any SIM-jacking story, which is the point of this entire thread.
1. They don’t need your password because their goal is a password reset through your recovery phone, or recovery email address “secured” by a recovery phone.
2. They do social engineering on telecom employees (or outright buy them out for a pittance) to not only get access to your messages, but take over your entire link to your cellular network. You’re not involved in any of this.
TL;DR: the second factor makes you less secure, not more. It’s a downgrade from a secure password. It makes you defenseless.
Breakable != useless.
(The other use of SMS which is somewhat legitimate is as a cost gate to create new accounts. Generally creating a new SMS receiving phone number costs someone more than a new email, so if you want to crudely limit creation of large numbers of accounts by individual users, it can be an option.)
It's not about your password. It's about social engineering. Bad guys call their buddies at some mobile phone co. and get your number switched for a few minutes, then they call your bank and get them to change your password which they do because they trust SMS 2FA which now goes to the bad guys, and then they take your money, and you find out much later. Password quality has zero to do with any of this.