It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS.
I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one handy, but I haven't read a text or made a phone call in a long while.
It needs to die. NOW. Outlaw SMS!
It sounds like you're incredulous that even banks are being insecure, but history has shown that you can expect banks to be roughly last in terms of competent and secure IT. I trust my Walmart.com account info to be safer than my bank info.
I doubt that most of the people that complain about SMS live in rural areas. It seems to be more of a US thing. The country is so large that unless you live in a city you just won't be able to get data reliably. This leaves SMS as the only form of phone communication that isn't a voice call.
Even installing and using a TOTP app, and configuring it to work with an online login, is a hurdle that a non-negligible number of users cannot pass.
It's better than nothing.
Maybe Starlink will be able to provide a mobile phone service that only offers a data connection one day, and that will be the "disruption" the mobile industry needs.
Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?
The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff.
They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if they wanted to), so when a call comes into your provider (mobile or land line) it comes with all the metadata fields (sender, etc) populated, and your provider just passes that along without any verification.
This was less of a problem with there was a reasonably limited number of phone companies (a few per country) and they were all large enterprises..
Now with the rise of Twilio and tons of other pay-as-you-go companies that can hook into the global phone network to send calls and messages, and MVNOs (virtual phone companies that sit on top of the incumbent ones), there are too many players to track and in the name of convenience (and cost-savings) we haven't kept up with the verification part of the chain.
Why not?
They don't pass on all metadata, that's part of the problem. If a call originates in $foreign_country, the sender gets to spoof it as a local call (sometimes they even use your own phone number). Are you really telling me there's no way to tell the difference between an off-shore call and a local one. It seems if this were true that billing is impossible, yet somehow the origin gets billed (though admittedly that might only be the immediate upstream, but usually this will be enough to disambiguate a scam call).
Phone companies make money from scammers. It doesn't seem to be a technical bar, rather a financial disinclination that stops phone companies from robust action.
I'll give you one simple example of the magnitude of this. In Ontario & Quebec, Canada, in the 1920s, there were almost 800 local phone companies operating, and "The Bell Telephone Company of Canada" was the long-distance provider that connected all those companies together. Even back then they handled almost 3M long distance calls per day (from roughly ~500,000 phones).
Over time, Bell bought up all those local independent companies and merged their records, customers, infrastructure, operations, etc..
That's Ontario and Quebec only, 2 provinces out of 10.
Fast forward like 60 years and in Canada local/regional phone companies in various parts of the country were still a thing in the early 1980s, and even now we still have distinct phone companies for some of our provinces.
And this is just one country that has less than 40M people. Now repeat this process in the US, and other parts of the world, going back almost a century, and you can start to understand the complexity we're dealing with here.
The insanity of these merged and glued-together tech stacks would make most people faint.
Obviously they're not all still running on super old tech, but if you look at any major incumbent telco's DCs you will commonly find switching systems from as far back as the 1960s that have been wrapped in layer after layer of "modernization" but are still there routing calls and running old code.
I know you believe what you are saying is "simple enough", and it probably should be, but sadly it's not.
And while you're right to say it's a cost thing, it is also a technical problem in that it would require massive coordination both internally within telcos but also between companies that are competitors to each other, and aren't naturally inclined to work together in the first place.
It’s been a long time since I dabbled with Asterisk (IP PBX), IIRC, by default the call forwarding/redirection function uses metadata from the original incoming call. Let’s say, you’ve programmed your PBX that after 30 seconds of incoming call ringing, you want to redirect/forward the call (that is to make a new leg, and then connect them together) to your mobile phone number. I’m pretty sure, on your mobile phone you’d want to see the original caller’s number for incoming call, not the PBX’s phone number.
I'm curious to see if it rolls out as smoothly as we hope.
Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.
SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while.
I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbers originating within one country)
"known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what kind of attacks you're thinking of, but it's not the opportunistic kind of thing that a common thief will do without technical research and planning it out. If you know how to do it, you can probably find better jobs than this. It also doesn't scale well because you can only use it on people whose bank login you've already cracked in the first place.
I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" step that doesn't actually slow down any attacker more dedicated than a passing whim, but makes people feel good about whoever is using it, when there are better options that don't have the problems of SMS.
Yes, it doesn't scale well to bulk attacking, but most of my interactions are with people who take reasonable precautions like keeping their machines patched, not installing random crap from the internet, and generally avoiding other fun ways people get swept up in low-hanging fruit campaigns.
SMS 2FA is better than no 2FA at all, it's just frustrating to watch many companies deploy it and go home when there are better options, some of which solely also require a phone.
edited to correct my statement: I originally said "SMS 2FA is better than no 2FA at all in a number of cases", but no, I'm pretty confident it's strictly better, even with all my laments about it.
SMS works with every conceivable phone, even most landlines if need be, users don't have to install a separate authenticator app, which may require a Google/iCloud password (now where did I put that post-it note?), that takes up space that may be scarce on low-end phones and that may not even be compatible with very old phones, leaving affected people in a really unsatisfactory spot.
Then they need to set up codes for every login, figure out how to switch back and forth between apps and how to copy codes, which is not very discoverable at least in Google Authenticator – most people seem to memorize and type instead, cumbersome.
Hardware tokens are even worse, people misplace those a lot and unless you are a bank with a mature process for issuing these, setup is probably even more of a hassle.
All of this may be big deal if you (also) target less technical people and want them to use your product when they have the option not to.
With SMS, all the user needs is a phone number. Pretty much everyone is familiar with that, most will readily share it, too. iOS will even extract codes and show them on top of the keyboard, just wait a second or two and tap the code, done. It's about as painless and frictionless as it can reasonably be, with apparently relatively inconsequential security drawbacks – given it's supposedly trivial to fake SMS, there don't seem to be a lot of people doing so at scale. Maybe a breach like this one will finally change that? Remains to be seen.
For now I can totally see why one might stick with SMS as a second factor.
If they wish to use Apple then that is their own choice, but on Android it's quite trivial to download Red Hat's open source authenticator app[1] from f-droid (the website, you don't even have to install the store if you don't want that). It's quite bare bones on graphics and features, doing only what you need it to (the f-droid build is 0.5MB, frankly still large for what it does but consider that it's like half of a single photo).
And if people don't have a phone with support for apps, then you can still fall back to SMS. Doesn't mean you need to force everyone down to that level.
Fun fact: my grandpa can't use SMS either, your solution is not as universal as you make it seem. He never has been able to due to sight issues (it's not an age thing, though it doesn't help if you're close to illiterate and now need to start to learn how to use solutions for sight-impaired people due to this information age having onset). Does that mean we cannot support anything better than sending a letter, which is accessible to him as well? Can't we have the better solution as well as the accessible one?
[1] https://f-droid.org/en/packages/org.fedorahosted.freeotp/
> With SMS, all the user needs is a phone number.
No no, you got that backwards. All Facebook needs is your phone number, or whoever it is that pinky promises to only use your phone number for security. I get what you're saying about everyone having a phone number that you can identify them by, but that is also the issue: everyone has typically a very very limited amount of phone numbers (and typically linked to a government ID) whereas a throwaway email is easy to make and each TOTP code is throwaway by design. I think there's something to say for supporting this.
That's even less intuitive than using the default app store. That's a whole new slew of concepts you need to grok (you can download an app from the web and install it without an app store; what is this fdroid thing? is this a virus? what do these dialogs mean?), plus training people to do this without also giving them the knowledge when and why this is safe isn't exactly helpful, but that's a lot to ask from a simple sign-up flow for a hypothetical niche app built by a hypothetical two-person team.
> And if people don't have a phone with support for apps, then you can still fall back to SMS.
You can, but that adds to the complexity and support burden and probably also costs you users due to sign up friction.
> Fun fact: my grandpa can't use SMS either, your solution is not as universal as you make it seem. He never has been able to due to sight issues (it's not an age thing, though it doesn't help if you're close to illiterate and now need to start to learn how to use solutions for sight-impaired people due to this information age having onset).
That's an interesting case. I'd like to think there would be a fallback for people like him, but I guess, in the vast majority of cases, he'd just be left out. The current state of inclusivity in tech is abysmal, though I've seen vision-impaired and deaf people get around their devices surprisingly well; it's still an embarrassment that this industry won't do better. It's hard to get this right when it should be hard to break this, but current frameworks and paradigms don't prioritize this. It's shameful IMO.
I do think SMS is a lot more accessible than authenticator apps and the like, even though that still will not work for everyone.
> Can't we have the better solution as well as the accessible one?
I'm not saying you can't or shouldn't offer the best solution you can. By all means give me Yubikey support and several fallbacks. But I can see quite well how not everyone might want or be able to.
> No no, you got that backwards. All Facebook needs is your phone number, or whoever it is that pinky promises to only use your phone number for security.
Facebook definitely should get rid of SMS factors. If anyone has the resources to do much better, it would be them and the other giants. Not sure how they handle that, though. They'd still collect phone numbers in any case, but they'd happily image people's internal organs if they could, so that is a separate issue.
Apart from that people seem to be quite happy to use their phone number for signup if it makes signup quicker and less annoying. Even if the primary flow is email and alternatives are hidden in another tab, phone number still tends to get used a lot, in my limited experience. Same with Facebook/Google login.
Plus, for most people ai guess it isn't as black and white; in quite a few cases I've given my phone number even if signing up via email, because it helps a lot if people can just call me in case of issues (e.g. the restaurant is out of my extra topping).
That said, I'm all for offering as much choice as possible, and I'm not happy with the inflationary use of phone numbers as the only way to sign up, and I'm all for Yubikey support in every app, and it's disappointing that OS/browser vendors don't make this easier and more convenient, and if anyone wants to let me have as many anonymous phone numbers as I need, I'm very interested.
But, still, I can totally see why a resource-strapped product/dev team might come to the conclusion that SMS second factors are sufficient for now.
I do agree with you there. To be clear, while I think the problem is of a smaller magnitude, I do agree with your general point. Other alternatives like very simple TOTP tokens additionally don't require a phone number and so you don't have this stupid "add your phone number now, we'll use it only for security, pinky swear!" prompts.
Heck, there could even be an argument that SMS OTP is now illegal with GDPR unless the user gives explicit consent. You can't use user data (PII) if it's not with consent, for a legitimate purpose, to fulfill a contract, for the user's own good, to comply with law enforcement, and I'm probably forgetting one or two reasons. Now that it's clear that stuff like TOTP is a better alternative, there is no reason to process people's phone number anymore for this purpose, making it impossible for you to send that SMS OTP. (Of course, you'd have to convince a judge that TOTP is better than SMS before we actually get case law on this specific use of a phone number so... *mumbles something about nine-tenths of the law*.)
Look up M-Pesa[1]. Which is a hugely successful, mobile phone based payment system in multiple countries.
In Kenya alone, where it started, it had 17Million subscribers. In 2011, that was.
In India, for every card transaction, for every DMAT transaction, for every password/PIN change SMS is used as 2FA. It is also mandated to require SMS 2FA for every one of these cases.
If my bank has any means to use TOTP/Yubikey, it is absolutely not made obvious, led alone clear or even possible.
Unfortunately, quickly looking, [1] suggests at least one of the listed services for sending arbitrarily forged SMS messages explicitly works in India, so it seems like this is still true for you. :(
[1] - https://www.usethistip.com/5-websites-to-send-anonymous-or-f...
Another problem with Android could be that the operating system might not have enough control over the SIM-Card/Modem to spoof phone numbers.
I have heard about people using some services to send/call from spoofed numbers though
(Btw a Google search for "Hushsms" results in shady/cancerous app stores that all seem to mirror each other. Where is the official website/thread?)
I kinda assumed this was a widespread modus operandi, apparently it's not?
Never trust any information from SMS, or from a telephone call (or email) - both SMS and CallerID can both be trivially spoofed, and frequently are.
If they have e.g. found out what bank you use, they can make the number look like it came from your bank ("See, this number is listed on the back of your card" is a common approach)
If you get a call or SMS requiring followup, then look/ask for a reference number and a publicly listed number you can call back on - _and verify this number is listed on the organisation website before calling_, ideally on a telephone you know they can't "hold the line open" on (less of a problem now people mostly don't have landlines). It's okay to "engage" with a caller as long as you are careful to not give up any personal information - especially in cases where it's a bank they should be fine with you refusing security until you can call back.
Don't ever relay information between channels e.g. if you _think_ you are talking to the bank, don't relay the contents of a 2-factor SMS you get, even if they say they are "sending" one to you. There have been cases where scammers have called the bank at the same time as calling the mark, so that when the scamee called the bank on a different line the bank verified that "they" were on another line.
In reflection, it's kind of crazy the things you have to be suspicious/paranoid and aware of, I'm not surprised that even competent/intelligent people get scammed, it often seems that the infrastructure that we rely on for trust is even flimsier than you could imagine.
Probably there are more extreme cases where these general rules aren't enough but probably unless you are a big CEO or something you are below the targeting threshold (see e.g. https://nakedsecurity.sophos.com/2019/09/05/scammers-deepfak... which will probably only become easier over time). A healthy skepticism about complicated workflows is probably helpful.
It's not really new data, it's just scam SMS I've received in the past has never shown any sign of knowing anything other than my phone number. Now you can buy phone numbers and pull personalisation data unrestricted from your copy of Facebook's database for each of them. I'm sure sophisticated scammers already were, but now everyone will.
This is why facebook can say to advertisers, "We mostly have young people using our service. So please put your money on our company"
And yes using account of 60-70 year old always receives less ads :D
Suppose you can get a list of people studying there, their names, and their phone-numbers. Faking this SMS and putting a payment that goes to you instead of uni would be a nice way to earn about 2000 euros per student who falls for it.
They don't email this information? They don't put it on an online notification system? I have no idea why SMS seems like the logical option for this.
That doesn’t justify the security implications of doing this...
I have considered faking the SMS message, with the payment link saying "imagine this wasn't a warning message but an actual payment request, please tell the university this is unsafe". But sending that kind of mass SMS is not easy, nor is finding the correct phone numbers.
With a correlated leak like this, it's super easy for me to find your profile, see who you are, what you look like, even from just your profile picture I could potentially see you have a daughter yourself, so I can target your mother that something happened to her granddaughter and you, which would make her pay up even faster possibly.
> This huge leak has definitely killed the
> SMS text messaging service.
So with this breach, one now must use WhatsApp for messaging contacts? That is rather convenient for Facebook.As someone who has much friction already convincing people to use SMS with me instead of the WhatsApp account that I've never had (nor a Facebook account), making SMS even more problematic is great for Facebook. Many people assume bad intentions or some other undesirable status when telling them that I don't have WhatsApp and that I'm not willing to install it.