Microsoft urges users to stop using phone-based multi-factor authentication
zdnet.com
zdnet.com
When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment.
Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authentication attempt. It can be not only frustrating, but dangerous - I have accommodation scheduled and without the access to my home number I could be easily left on the streets in a foreign country.
And my last complaint -> SMS can arrive pretty late when you are in a foreign country. Sometimes too late that the authentication window is closed.
With roaming and rampant robot calls, phone numbers should basically be considered no more static than IPs.
There's a reason iMessage/WhatsApp took over from legacy SMS.
Yes, of course I can have a second phone or other solution. The point is that SMS-based auth is just worse than the alternatives.
https://docs.microsoft.com/en-us/azure/active-directory/user...
You can change your settings here: https://myaccount.microsoft.com
Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's easy to transfer from one to the other but that doesn't remove the single point of failure.
Solution is to have back up codes for each account.
But of course, keeping emergency codes is a good idea too.
It's worth also noting that Authy also has no official way to export your secrets, although there are workarounds: https://tij.me/blog/migrating-your-one-time-passwords-from-a...
Otherwise you’re going to lock a lot of people out of their accounts which is not acceptable.
Ultimately this typically ends up with a reset scheme that depends on phone numbers or email addresses which means the protection, which is as strong as the weakest link, is worthless.
If you work for an organization with their own PKI then there’s probably also an automated self service reset mechanism using a complicated process.