It’s time to stop using SMS for security
lucky225.medium.com
lucky225.medium.com
I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale?
At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”.
I’d love a parable of how using SMS as part of a layered security verification is somehow unacceptably vulnerable.
I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc.
Of course that's several orders of magnitudes harder to do than just finding a leaked password somewhere, so it's still nice to have SMS as 2FA compared to nothing. It'll stop the mass bots.
And even if nothing goes wrong, it can take up to a day for the number to port in the US. That's a day without being about to login to anyplace that requires SMS 2FA.
A TOTP app on my phone, on the other hand, works fine regardless of whether or not my phone number currently works with the SIM in that phone.
Phone numbers in general are insecure. There is no enforced verification system - people can receive calls from their own phone number, and people can fake the presented numbers. There is such a significant amount of spam callers as well. The FCC doesnt care.
The entire phone system in the U.S. needs to be remade with security, but powers that be really don't want that.
Also same attack vector used to get access to Jack Dorsey's Twitter account I believe.
Pro: SMS 2FA is better than just passwords. In practise 2FA is primarily a hedge against credential surfing, with its other security properties more theoretical than practical, and it mostly works good enough for that use case. (Perfect is the enemy of good)
Con: there's lots of attacks related to social engineering the telecom into transfering your phone number. Real people have been compromised this way albeit this attack is pretty targeted.
There is also some concerns about evesdropping/mitm attacks. This is pretty unrealistic in my mind. If you're an on-path attacker for someone's cell phone convo that implies you have direct access to the victim, so the victim is pretty screwed regardless.
So in the end its a usability vs security tradeoff. Its a pretty close tradeoff so its not exactly a slam dunk in either direction.
Email is hardly beter than sms, and we do password resets over email.
By contrast email can be made arbitrarily secure nowadays via e.g. DANE/STS-MTA, and it's entirely up to an email provider how secure mailbox access is.
Saying that "email is hardly better than SMS" when the former can be secured via DNSSEC/DANE and where the mailbox can only be accessed by me over an SSH tunnel is truly laughable. In fact since sites which demand phone numbers seem to have some completely baseless idea that the phone number is somehow more "secure" than email, often adding a phone number will enable phone number-based recovery methods which therefore actually reduce account security.
Being an on-path attacker against SMTP is not a realistic threat model for most users.
Thats basically fantasy territory for an average user. If you consider the real world" abundant phishing, etc. then you will realise that in practice there is very little daylight between them.
Email is certainly far more secure. Consider the steps an attacker would need to do to be able to intercept an email being sent from the service being accessed (say, your bank) to your email server provider.
That's from the point of view of somebody trying a denial of service attack target at some user, right?
Imo, if people used passwords correctly, all common 2fa solutions other than yubikeys would be useless.
SMS isn’t used as an additional layer but the only necessary layer to “recover” an account.
As bad as passwords, savvy users can use a password manager and generate unique high-entropy passwords, but if the web site is forcing SMS on you, you lose all that security and now have to rely on vulnerable telco infra that is out of your control and was never built to facilitate authentication.
This has bitten me a few times, sometimes in desperate situations. Like when I've needed to log in to Airbnb to message a host, transfer some cash from my bank account, access my frequent flyer account, etc. Far too many sites don't provide 2FA over email, or through an app like Google Authenticator - they can only do it over SMS.
Yeah, I know I could set up roaming. But it's an easy thing to forget, since I change phone numbers every couple of years (for both personal and work phones). And it's not always cheap.
It's also just a huge pain to have to go through and change every account I have, any time I change numbers. A lot of accounts that I only use occasionally are configured with one of my many old phone numbers, which don't work anymore. This usually involves a call to tech support to fix it.
All because I want to change my phone number, and I’m overseas.
Which I only need to change (or even have associated with my account at all) because they refuse to offer any other 2FA option.
Actually, the myGov thing was a real piece of work. They offer secret questions as a second factor that you can opt to use instead of SMS codes (and yes, secret questions are stupid), but when I did that, it silently unlinked my Australian Tax Office account. I tried to link it up again (a bit of a pain in its own right), and it told me that ATO has decided that it won’t let you link it up if you use secret questions as the second factor technique. Seriously. So I had to switch back. Oh yeah, they do also have a third option, an app of their own that can generate codes (not TOTP), but that app had something like 2 stars on Google Play Store, with many reviews saying it didn’t work at all, so I didn’t even bother trying that.
When I’m in Australia with my phone handy, SMS verification seems not too bad, but when out of the country and not roaming, it may vary between very inconvenient and completely debilitating.
It is a steaming hot pile of garbage where the government has yet again decided to not use a widely accepted standard.
But if you just need to login to myGov every few months to check something or do your tax return it works better then the SMS
(Just don't lose the phone it is installed on, because you can't link it to a new one without ringing and wading through security checks)
I really wish I could root it or install a new OS on it, but the former has failed and even with an unlocked bootloader the latter takes much too much effort if a prebuilt image isn’t available for your specific device, which roughly means “if you don’t have a flagship phone”.
That said if you're out of the country a lot and going the SMS auth route, I'd personally be more comfortable with a postpaid plan in AUS for the SIM as the telcos tend to take ID requirements more seriously for those then pre-paids and you're less likely to be socially engineered out of your number.
I said prepaid, but as I did it it’s actually postpaid but with an initial $10 prepayment required. Ah, good times back in 2014–2017, getting those bills for less than a dollar (commonly 12¢) every quarter. Then I moved to a tiny country town where an Optus tower a few hundred metres away became my best option for internet, 50/25Mbps and far more solid than any NBN anecdote I’ve heard.
Well, Android 5.1 was EOL in 2015, so you willingly bought an unsupported model. I'm not saying Android has any sensible long-term support (in fact, I spent the last weekend installing LineageOS because my 2018 phone doesn't have support anymore), but this instance is hardly Google's fault.
I think most people on HN are comfortable doing a bit of research to see when a device will stop receiving support, but I don't think that's reasonable to expect from everyone.
If I walk into a shop and buy a phone, new in the box, it seems pretty reasonable to assume that it's operating system will work with whatever apps I install from it's built in store, and that it will receive security patches for at least a few years. That seems to me like a pretty low bar, but it's absolutely not the case in the Android ecosystem.
In this case I think Android 5 was 2014, so almost 7 years old a this point.
Amaysim are pretty good, Though if you can convince them to add a security note to your account its worth it (Colleague of mine had his mobile number hijacked while on holiday and they used it to access a few of his online accounts)
Why didn't you use a sms to email forwarding app on a phone connected to a charger?
They are free on play store and work really well.
That one needs to do this to work around the limitations solidifies in my mind that SMS is a poor 2FA solution and should be discontinued.
If you're using a password manager and have a security model that includes trusting your own computer, you really don't want the snake oil. In fact with US bank accounts, "2FA" steps make your account less secure, because the security of your bank account ultimately relies on checking your transactions every 30 days - anything that gets in the way of easily logging in undermines that.
So much this, for Europe as well. Since PSD2, i cannot automatically check my bank account anymore, because of onerous and braindead 2FA requirements. And most banks do not offer a email-on-withdrawal function in any proper fashion, even their apps require regular reauthentication. But, since it is a braindead directive, you can install the 2FA app on the same phone as the bank app and have them talk to each other, thereby killing all the security benefit while still being annoying and non-automatic.
You can read and write messages from the comfy keyboard of your Windows/MacOS/Linux laptop, even if your phone is at the other side of the world, as long as both are connected to internet.
As someone who forgets his phone regularly at home, it's great.
Skype is an obvious choice, but there are many other providers.
Then you have a stable number and can read SMS via app web UI.
I switched to the same method a few years ago. It's useful even if you don't travel much, just to not tie 2FA to your phone and for not giving all those services your real number.
Both have failed to receive 2-factor messages from providers over the years. Very occasionally the Google Voice number is blocked explicitly by the provider as a VOIP number. It's just not a reliable 100% replacement for "real" SMS in my experience.
Google Voice is close to acceptable as a replacement, and it's my primary 2-factor number when it works, but it's not 100% for reasons outside of my control.
I've heard good things, can you port a cell number in or is it strictly voip? (I haven't done anything phreaking adjacent in ages)
https://support.twilio.com/hc/en-us/articles/223179348-Porti...
I used one of their existing pool of numbers.
For inbound short-code support, you have to contact support directly and agree to a legal T&C for them to enable it.
You presumably do have a "home" country in the sense of where your bank accounts are, get a cheap permanent sim/phone no with roaming, buy the tiniest phone you can off amazon and stick it in as your 2factor permanent number.
Yes, you have to keep that phone charged, but your problem is now permanently solved, it's how I did it.
To sum it, 2fa via sms gives only an illusion of safety.
https://www.itnews.com.au/news/telcos-declare-sms-unsafe-for...
Using phones is honestly a huge security issue
Then you have to worry about fraud, and whether telcos in <random country> have been hacked, or are corrupt, and are leaking messages to bad guys.
I've seen entire (small) countries drop out, too. Usually the way you find out about this is that support notices an uptick in users in <smallish country> complaining about not getting messages, or you notice that the entirety of some geography isn't successfully completing the transactions you tried to protect with SMS. Er, you did consult the (changing) prefix database and phone number parser to (semi) reliably determine a geography from a phone number, right? Isn't parsing phone numbers fun?
It's fractally terrible and expensive, and I haven't even talked about APIs yet.
This is only because the telephone cartels control the networks. The same is more or less true of Internet. Operators have advocated for anti-open-wifi laws across the globe so they can sell their internet access plans (xDSL/3G), when we could have free networking for all in all places.
Seriously though, why couldn't we have FREE privacy-friendly networking as a public service?
Here you have to buy access to certain frequency ranges(big money required). The bidding happens from time to time. Building the network infrastructure is not cheap either and requires specialists to work for you.
I'd rather buy that 4G from a company that can deliver it everywhere I go than move backwards in progress to use some random WIFI hosted by Joe that fights over the same frequency as John's across the road.
The "cartel" networks work pretty good tbh. They just have stagnated in everything else but networking.
Like Microsoft Authenticator. It wanted way too many permissions on my phone, and provided less security than my Yubikey authenticator. My yubikey provides a standard open OTP but requires the device to generate it (phone tap or plugin via USB to computer or phone).
Open standards are better. I don't want a different authenticator app for every website. It's so much simpler to use a single app.
Thanks for the heads up!
Still, the principle stands for a number of other sites. eg, Steam (using their app or email), Twitch (authy or bust), etc. I'd rather use an open standard than be limited to a custom or specific authenticator.
https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
I've had that happen on more than one site. Surely anyone who stole my password would just put in their own number?
One of my accounts requires a phone number to verify every single time I login. I have no clue why, and it accepts absolutely any phone number.
I have no clue what the purpose is aside from forcing me to give sensitive information to other people when my phone isn't available or I'm traveling (which I've been forced to do already).
SMS gets hatred especially in US because of how easy it is to socially engineer their way for SIM replacement or other SMS uses. Mostly because for unknown reason US has the absolute worst MNO in the world. In other places SMS replacement requires official forms to be filled as well as physical presence. It doesn't matter whether SMS is a form of 2FA of not, getting my SIM card without decent form of protection from Carrier is wrong in the first place.
And RCS doesn't seems / want / willing to replace SMS anytime soon. Carrier have little incentive to do so. It is backed by Google which means not everyone is on board including Apple. And GSMA has no intention to make a better SMS either.
Unfortunately yet another example of the US's poor regulation of telecoms receiver pays is another example.
SMS is not properly encrypted over the air, GSM and UMTS encryption is broken and often misconfigured anyways. There is no way to check and no guarantee that a SMS will be transmitted in a safe encryption protocol, i.e. no way to force LTE. And given the level of brokenness in GSM and UMTS, I wouldn't rely too much on LTE or 5G crypto being worth anything. End-to-end encryption isn't provided anyways.
Also, phone numbers are not terribly secure either. The control protocol for mobile networks, SS7, is a steaming heap of excrement without any consideration for security. There are numerous ways to redirect SMS and calls into the hands of criminals, which have been demonstrated over and over by researchers. Also, this is regularly being abused by the police, secret services and criminals. As a customer, you are completely at the mercy of the phone network to do the proper mitigation dance because SS7 is inherently broken and cannot be fixed, just maybe firewalled off (a little, but not too much...): https://attack.mitre.org/techniques/T1449/
Then there is a whole lot of social engineering cases to take over numbers and SIM cards which others have described nearby.
With 2FA via a proper app or even open protocols like TOTP, I can verify and trust much more of the auth flow. Properly done, I only need to trust the endpoints and (maybe, if used, with TOTP even that is unnecessary) the TLS connection. With SMS, I need to trust a whole lot of telcos between the endpoints, their firewalls, IDSs, (mis-)configurations, all their service providers and their employees not to fiddle with things. And actually, all of the aforementioned have repeatedly proven untrustworthy by using broken, outdated, and known-to-be-insecure technology.
It's been proven time and again that cyber criminals frequently target people using SMS 2FA to steal from them. Most implementations of 2FA might as well be 1FA. People might even use worse passwords when they think 2FA protects them.
I think the adoption of SMS as a "universal 2FA" was not worth it. We should've just gotten people used to the less easy but more secure methods. U2F bluetooth keyfob on my keychain would be good enough for my phone and PC. Remote access seems like the hardest nut to crack.
TL;DR: my mobile phone number (not the phone itself) was hacked, then my Twitter account. The attacker changed my Twitter handle from @simon to @simonsw9kww.
I eventually recovered my @simon twitter account, after several MONTHS and several emails and calls to twitter support and friends working at Twitter.
Is this enough for you?
[0]: https://simon.medium.com/mobile-twitter-hacked-please-help-2...
It's equivalent to taping your key to your back door. Sure, someone has to go to your back door first to see it, but then they're in.
This was ~15 years ago, but I doubt much has changed.
The article gives plenty of examples. Here they are as links:
https://www.vice.com/en/article/a37epb/t-mobile-alert-victim... https://www.vice.com/en/article/xyezmn/we-were-warned-about-... https://www.vice.com/en/article/mg7bd4/how-a-hacker-can-take... https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
The latest is the most severe, in summary - a gaping flaw in SMS lets hackers take over phone numbers in minutes by simply paying a company to reroute text messages.
So if you insert SMS 2FA in your security chain as a fallback authentication method, you're leaving it wide open to exploits and none of your other 2FA security like TOTP or tokens matters, because the attacker can just take over a customer/admin account using the SMS authentication to prove they are the user concerned then change those methods. In some cases you'll require an email as well, and in some you'll manage to send an email to that old email address before it can be changed, but many places don't, particularly mobile apps tend to rely on the phone number, and most people don't monitor every email address 24/7, so lots of damage can be done in a short period.
SMS really needs to be fixed and it's really debatable whether it adds security or subtracts security in the meantime, even in a layered approach.
In looking around, a few things became clear:
* the tech industry hates SMS
* there are some common social engineering and a few network level attacks that SMS allows
* it's widely deployed and supported
* it's a heck of a lot better than nothing
I think the title of the original article is a bit absurd. That's like saying "It's time to stop using passwords for security." Sure, you can say that, but your grandma will still have a sticky note of passwords next to her computer.Defense in depth without relying entirely on the user to secure their systems makes a lot of sense to me.
Ban SMS if you aren't worried about adoption of MFA (for example, because you are a corporation and can mandate TOTP). Otherwise find ways to work with it.
Ignoring security (not that we should), it's just a massive pain from a pragmatic point of view. As others note, right when an SMS MFA is triggered is most of the time when I can't receive an SMS, so everything breaks when I actually need access.
Much easier solutions exist today at more convenient adoption at scale, like email and TOTP.
With that said, people should fear any site/service that uses SMS for anything security related. SMS 2fa is a fairly common vector for compromise.
It can be nice for a "data feed" though. Like, getting an update on the status of your delivery driver. Though, this can also be really annoying when say... your old college starts spamming you with stuff... which I got to experience this weekend at 1am. :)
What i definitly dont need is being reachable and available 24/7 wherever i am
Conversely, the lack of such generous SMS allotments in most non-US countries drove widespread adoption of WhatsApp/Facebook Messenger/etc.
Banks all have their own 2FA apps.
- Clubhouse invite
- A security code from a trading exchange
- My mobile internet provider telling me I reached 80% of my monthly data budget
- A few codes to validate my phone number when creating new accounts on platforms
And that's basically it.
SMS works whether you're on iOS or Android, it works for the few users of classic phones, it works if you don't currently have mobile data, etc. It's not a secure method of communication and has other flaws, but it's the most reliable one if you don't know anything about the recipient. Whether they're using their beloved Siemens S35 or the latest Android flagship, they can receive a SMS.
Is this an american thing, like SSN identity theft?
Or checks... let's not forget checks...
If you actually want people to read your content, then don't put it on Medium. Not to mention that it's bloated as hell, requires JavaScript, burns batteries on mobile devices, and is full of loathesome spyware software.
Later...
"Oh no! The phone company is doing a terrible job of solving our identity issue!"
I've spent countless hours trying to explain them the issue in 2019 and gave up as nobody cared.
That being said, a certain class of SIM cards (SMS-only cards, without voice functionality) is exempt from most of these strict checks as far as I know, and there are other technical vulnerabilities that are probably just waiting to happen in Japan before they're taking seriously.
I'm a little bit surprised that Yahoo! Japan went for SMS as the only authentication method, since their one of the main sponsors of the FIDO Japan WG.
My covid project was an SMS news API completely controllable from your phone and delivers short news summaries on any topic scraped from across the web (www.zipnews.io). While fun and it has several paying customers, the SMS can be somewhat expensive to send. The strength is that everyone with a connected cell phone can access the API.
https://web.archive.org/web/20210316074533/https://lucky225....
If that mirror keeps hiding the text, blocking all inline scripts with uBlock Origin solved it for me.
There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it's not my day-to-day number.
You can work around that by using lesser-known providers. In the UK, Andrews & Arnold (https://www.aa.net.uk) provide UK mobile numbers which don't seem to be rejected by anything.
It might no longer be true as there was a Twilio support page that confirmed this behaviour but is now just a 404[0] (though you can see a mention of it on StackOverflow[1])
[0] https://support.twilio.com/hc/en-us/articles/223134367-Sendi... [1] https://stackoverflow.com/a/55852784
I feel equally threatened by a potentially weak bank app running on my phone all the time as I would my carrier giving away the keys to the castle.
Kraken (a cryptocurrency exchange) allows you to set up one TOTP token for regular logins, and another, separate one for withdrawals... obviously not as good as individual confirmations but still a heck of a lot better than SMS!
If your control your own receiving server then it would be hard for someone to intercept the message.
Its bad because 85% of the usecase of 2fa is people using bad passwords. If you use a bad password in one place, you probably are also doing so on your email.
Do writers on it know that you can only read 3 articles before you are required to create an account and login? (like pinterest)