You don’t need SMS-2FA
blog.cmpxchg8b.com
blog.cmpxchg8b.com
Also 2FA can stop phishing attacks cold as well, simply by using links instead of codes. So really the author should be using their time to advocate for that.
> When a service enables SMS-2FA, an attacker can simply move to a different service. This means that a new attack isn’t necessary, just a new service.
If you implement 2FA you do it to protect the user account on your service, not all services.
"Password hashing and salting is useless. When a service enables password hashing and salting, an attacker can simply move to a different service that stores passwords in plain text. This means that a new attack isn’t necessary, just a new service."
But I do not use it because of risk of getting 2FA compromised :/
However, telecom hacks are often more involved, and take more effort to pull off. If I'm a high value target, it's not a big hurdle. If I'm a low value target, I might not be worth it.
While telcos may eventually fix the broken protocols, it's likely to be decades before that has rolled out widely.
In the meantime attackers are going to automate telecom hacks.. why not?
That said, for simple services sending a single use password by email or SMS is quite easy :) My hairdresser does so for reservations, and it's working out fine.. Nobody cares of that account is hacked anyways.
A lot of telecom hacks are social engineering, which often leaves an audit trail, and is hard to automate (if they're using the same text to speech engine that makes spam calls, good luck!)
Stealing SMS messages, maybe less so.. but from what I hear the protocol is largely trust based, so it's unclear that it couldn't be.
That said, eventually telcoms will be forced to fix this. I'm just guessing it'll take another decade or two.. it's not like robocalls were trivially fixed when they became annoying.
> SIM swapping attacks are a legitimate concern, but if that was the only problem with SMS-2FA, my opinion is that would not be enough to dismiss it.
The takeaway from the attempts to eradicate "Are you sure[...]?" has been to just do the thing the user said to do, but make it easy to undo rather than double checking. It would be interesting to see how that philosophy could be applied as an alternative to 2FA.
EDIT: Boy, the replies that this comment spawned sure say something about HN. I count one (muxl's) that has any sense of self-awareness. Do you really believe that I don't understand the "purpose of 2FA"? Come on. Be more charitable.
https://news.ycombinator.com/newsguidelines.html
EDIT2: It's a little weird that folks who start out with the goal of being intellectually lazy are willing to put so much effort into it.
The problem with taking an "undo" philosophy here is that it's very hard (impossible?) to undo the transfer of information which is what attackers are after in many breaches.
But if someone logs in to access my files without authorisation... they've got them now. I can't click undo on them having read my private emails, or whatever the 2FA/other security was protecting.
Yes. Nothing you wrote leads me to believe you do understand the purpose of 2fa. You can complain all you like, but to me, and apparently others, it seems that you don't from what you wrote. If what you write is misleading to so many people then perhaps rather than complaining about people mis-interpreting what you wrote you might re-visit the thing you wrote.
A: The colour black is white.
B: That's ridiculous.
A: I entirely understand the difference between the colour black and white, "Be more charitable".
If a specific 2FA implementation is not out-of-band, that would make it useless as a 2FA and it would be as you describe.
I can't think of a way to "undo" in this scenario without some settlement pattern. You can do whatever you want, but it doesn't "commit" until some settlement clears. In this case, still leading back to some kind of "Are you sure[...]" question, except to review in batch, like someone reviewing a bank statement.
Some people like reviewing in batch, some progressively, depending upon their individual perception of the cognitive load involved for them.
Tough to economically prevent spoofing though, when you start dropping aspects of authentication, integrity and non-repudiation. I suspect we can't substantially move that "Are you sure[...]" question's boundary until wearables become implants like a neural lace-grade implant.
Or are you arguing purely in the sense of SMS and Email based 2FA?
So insightful things get interpreted as incompetent ramblings. So we're left with virtue signaling. It's a terrible culture.
"jasonpeacock 1 day ago [–]
He's arguing not just against SMS-2FA, but against 2FA itself, and his simple solution is to "just use a strong password". The author completely misses the point about the value of 2FA itself. I agree SMS-2FA is not good, but that doesn't mean 2FA is worthless.
reply"
There are legit arguments against SMS (the cell phone provider's customer support and the SS7 are weak points) and badly implemented 2FA, but 2FA definitely has security value add.
I once ran IT for a small startup (As part of a large portfolio as Ops director), none of the employees put any thought into password security, or cared, no matter whether I set them up with 1password, gave them training sessions, etc.
And apparently that is the case for all banks in the EU
I did my taxes this weekend, and to get to the bank tax statement, I first got 5 SMSs
Everything was much better with iTANs. Paper TANs were perfect for me. Someone could hack my Android 4 phone, but no one can hack a piece of paper
I actually thought that SMS as 2nd factor for Banking is not allowed in EU anymore.
All the serious banks that I know of offer asynchronous password tokens (like Digipass), since not everyone trusts those mobile apps, or they simply don't own a smartphone. They don't advertise it too much, since it is easier for the bank to get everyone to use an app, but most of them offer it. If they don't, you should consider changing your bank.
Heh. You might as well drop the password and have a 'send the login link to my email" button then.
Why is saving the password in your web browser or any application on your machine - that can also be hacked - considered secure? You're just offering an attacker one single attack point that will yield all your passwords if compromised...
What about people using multiple machines? Should we sync our password store across all our devices, so there is just one server storing them that can be attacked?
And last question, for the SMS-2FA crowd: why would I want my login to depend on my phone number working?
So you consider SSH (which normally relies on a private key stored locally) insecure?
(Sure, the SSH key can be further protected with a passphrase, but so can the browser database of passwords. On a modern Mac, it requires unlocking with touch ID.)
A touch id protected secret store may be secure, and you lose access to your secrets if your laptop/phone gets stolen or breaks down? Or do you back it up to another store protected by different authentication that you have to store?
Looks like you cannot win to me.
The only advantage of generated complex passwords is that they'd be harder to brute force if the server has their password database stolen.
Edit: and being forced to depend on a working phone for authentication.
The point of the article was that there is no downside if your password is unique. They will have your data on that particular site. The rest of the sites are just as secure as they were.
There is no depth here...
For this reason I'd guess that many companies use SMS-2FA as an excuse to collect and confirm your mobile number.
TL;DR getting a text message every time someone logs in as you is going mean you're much more aware of what's happening with your accounts. Having that text message contain credentials means if it wasn't you logging in (and hence you weren't expecting an SMS) then the login fails.
EDIT: Password managers are great and I'm all for promoting them probably more than 2FA even. The difference between a password manager and 2FA is that a password manager does literally nothing given that your password is known. In that same situation 2FA still does do something and so this appears to be a false dichotomy.