I think it’s a baby step. I see other threads under the parent comment recommend banning SMS 2FA altogether. Surely this would be a step back. I suspect most people and companies would think, “well, I guess we won’t do 2FA anymore” rather than, “I guess we will use a proper Authenticator instead”.
I disagree. I can safely store a long, complex, and unique password. I cannot prevent anyone from social engineering my cell phone service provider and doing a SIM swap.
What if someone stole my phone and I'm unable to instantly get a replacement? I don't want to be locked out of my account either.
But additionally, a big issue is reliability of the 2FA mechanism. Especially when your service provider is overseas, or you're roaming, the SMSes may simply not arrive in time.
Much SMS 2FA in the world is used not for your security but to solve the difficult problem of spam/scam/sockpuppet accounts.
Of course it is labeled as being for your security but it's not about that at all.
Bad actors are relentless and forcing them to burn a SIM chip any SIM chip to participate at least slows down the onslaught.
But this turns the 2FA into 1FA, and that "1" is just an SMS.
Using SMS as a second factor is great, using it as an only one, is not.
If someone hacks eg linkedin (again), and gets all the passwords, they can just hack literally millions of accounts on other services just because of password reuse. SMS 2FA prevents that very effectively.
But I agree that companies use things made to deal with "issue A" to deal with "issue B", even if the thing is totally inappropriate for "issue B". I've heard from people that some places in USA use SSN, date of birth, mothers maiden name, etc. to authenticate and verify the user (instead of doing stuff in person with an ID card)... most of those things are (almost) impossible to change, and once someone knows them, you're fscked. Same with fingerprints as means of authentication... once someone makes a mould, you're done, because they can use them, and you can't change them.
Sure, but the fact that an explanation exists is unlikely to be of help if you get your account compromised by this.
> If someone hacks eg linkedin (again), and gets all the passwords, they can just hack literally millions of accounts on other services just because of password reuse. SMS 2FA prevents that very effectively.
Hacking a specific service is much harder than simjacking. Use an alternate method of 2FA (a FIDO2 USB key would be best).
If you have someones linkedin email+password, how is it hard to "hack" into their facebook account, if they use the same email+password combo there?
Moving the goalposts until only your argument is valid is nice if you like to be tautologically correct, but is not very useful.
The specification for WebAuthn (and presumably U2F but that's legacy and shouldn't be used for green field deployments) explicitly tells Relying Parties (that'd be the web site you're enrolling with) to allow multiple authenticators to be enrolled†
They are keys after all, so it probably feels reasonable to have a key you're carrying and one spare at home. Maybe if you lose your keys a lot, buy three just in case.
Unless you've got a FIDO2 device (not just FIDO) enrolled for usernameless authentication, the device doesn't even know who you are. So if you lost it on the train, or at a crowded event, relax, even if somebody found it intact and is curious the device can't help them log in as you since it doesn't even tell its new owner who you are. In fact it actually works perfectly well for them too, to secure their Facebook or whatever, in this way it's more like if you lose a quarter than if you lose your car keys.
† Now somebody will point out that AWS doesn't do this, and somehow this fact will be a justification for why an entire technology is bad, rather than yet another shortcoming of AWS...
If both are actually being used then an attack has to compromise the password and the SMS, which is going to be harder than just the password.
Combine this with the time Facebook started using the mobile phone number for more than just 2FA (suggesting friends IIRC), and there is a decent argument for preferring plain password over enabling SMS 2FA.
I'd buy these complaints much more easily if people actually mentioned this stuff when TOTP comes up. But they don't.
The only meaningful jump in security is when moving to a yubikey or equivalent.
SMS 2FA is shitty for unrelated reasons.