Using some kind of OTP authenticator app or device and __NOT__ SMS!
Using some kind of OTP authenticator app or device and __NOT__ SMS!
What SMS is terrible for is as a single point of account recovery. This is unfortunately how it is often used. "Multi factor authentication" in practice has become "Use any one of multiple available factors for authentication", which is awful.
So no, SMS is not perfectly good. it's crap and needs to die in a fire.
I know that frequencies are different in some parts.
A proper OTP app works offline, and more than one of them can exist for any given authentication, so you can have backups if your phone is stolen.
It's better than just having "secret" as your password, but not by nearly enough that you should feel particularly secure with it.
The issue with with all multi factor authentication is dealing with the likely situation that one of your users locks themselves out of their account and needs to have the factors reset so they can get back in. The secure way to deal with that would be to go, "Sorry, we don't know you and you've lost all your data. Goodbye!". But of course with important accounts that usually escalates pretty quickly with upset users hogging your helpdesk employees and not giving up that easily. So, most companies have help desks that are easily talked into "helping you". That's what they are incentivized to do. Companies with tight margins are the worst. Like most operators for example.
We desperately need to have better MFA options if we're going to require it from users.
Phone numbers, fair enough, but TOTP is an open standard and there are plenty of open source implementations for the client side. It’s also available in most password managers (I use 1passwords implementation).
“MFA can’t require me to run a binary on my phone” is a bit extreme. TOTP is fine.
Where I work a bunch of people had a cow about having to put a MFA app on their phones, but refused to take a work phone. Our remedy was to issue them PINs to allow after hours access to the building.
Every service of course has the option to print backup keys. Maintaining those (in secure offsite location) over years takes some effort.