SMS Multifactor Authentication in Antarctica
brr.fyi
brr.fyi
For a while, I had to enter a password and then get an SMS authentication code once every 24 hours to login to Teams. The problem is that cleared spaces don't allow any personal devices (there's no cellular service anyway with TEMPEST hardening) and the unclassified (NIPRNet) workstations are usually blocked from connecting to websites like Google Voice and some commercial webmail services. The authentication code would timeout after five minutes, and that didn't always leave enough time to exit building, get to my phone with cellular service somewhere, and then re-enter the building and return to my workstation with the authentication code. If you always worked at the same desk, you could set it up to make a voice call to that desk phone number for authentication, but I didn't always work at the same desk.
My own solution was to use my personal Google Voice number for the authentication code, have Google Voice forward those messages to my personal Gmail inbox, and then have Gmail forward those emails to my official DoD email inbox. (Our official email wasn't yet on O365 and only required our smart cards to login, which later became the method for O365 login, thankfully.)
A lot of financial institutions do not allow gv/voip numbers anymore. So, I've had to add one more layer to this, namely forwarding sms from phone to gv, which then goes to email. It looks like there aren't great solutions for forwarding sms to email directly on android, but there is an sms forwarder app on f-droid that works for forwarding to gv.
You can also do this with a Particle board or some other similar embedded device running code on bare metal instead of an Android phone. The advantage being that you won't fall victim to a Java crash or software update, and you can probably set up a watchdog reboot on it.
(Yes, I've done this.)
Appart from avalability, at least that's secure :)
I'm sorry, we don't want your fancy crypto, please accept this insecure SMS.
The answer is to be heroically productive, despite all these ridiculous obstacles, and then to use your reputation to build a base of opposition within your organization from which to fight these problems. If that sounds hard, exhausting, and thankless, then you have your answer for why these things don't get fixed.
It doesn't particularly matter who has the power to change it, but it's probably near to the top of the organizational structure.
>How do you make them feel pain?
The way I see it, either:
1. Teams is crucial and not being able to access it easily means eventually things that are important to the people at the top of the organization are missed or take too long. This is the pain you can make them feel. You presumably have your ass covered by raising your issues in writing earlier, so the blame ultimately doesn't rest with you.
or
2. Teams was never important, so not being able to access it easily turns out to not really be that much of an issue for anyone who has any kind of influence.
>you will not last long enough to make change
The person doing this is not trying to make change. Rather, the whole point is to stop insulating decision makers from the consequences of their decisions.
I'm reminded of the investing maxim that "markets can stay irrational longer than you can stay solvent." I'm a military officer who's not yet senior enough to be vested for retirement benefits, but senior enough to be within striking distance of vesting after 15+ years ("golden handcuffs"). The career model for officers is also "up or out" and every year counts (i.e. one needs to remain within the top 50% of performers who've also devoted the last 15+ years of their lives to this). If it takes the bureaucracy longer than a year to change something stupid, I need to be very thoughtful about what stupid things I choose to protest with disobedience. Furthermore, as someone who works in the IT part of the organization, saying that I can't figure out a way to stay logged into Teams would be an especially bad look. A significant part of my job at the time was helping non-IT people to find solutions for stupid IT problems while advocating for changes to the IT people above me.
I said "So you're forcing people to have a phone with a plan?"
"Yes."
On Microsoft 365, if you setup "forced MFA" on your organisation, then they additionally force users to add a phone number which can be used for account recovery.
I get why Microsoft wants to keep account recovery possible in this manner, but I am not someone who needs it, and there needs to be a way for me to make my account more secure where my phone company can't take over my account...
gave my number to bank to send me TOTPs, and then moved away literally dozens of thousand km away to find out that roaming is not enabled by default (had to buy a new sim card from new carrier), you have to visit office in-person, and on top of that, bank wouldn't send SMS to foreign numbers, so my card is good to cash out basically, forget the online payments
That said, I'm still vigilant for alternative login options when I see them because I assume sooner than later, some company will audit all customer numbers on file and realize mine has changed from `mobile` to `voip` like mentioned in the article.
I think the only ones still tied to my number are a credit card and a neobank, but I could theoretically live without those.
But I've been traveling around in the UK and I know you shouldn't take reception for granted. In Malvern, Worcestershire there's no reception in some parts of the city, and in Wales I only have reception in the cities.
We had a situation last week where we were setting up a tool, and I couldn't proceed because they required 2FA through SMS, not a great first impression.
This drives me crazy. I don't want my phone number to be a single point dependancy for such services.
Phone numbers are commonly used for this. I change mine monthly.
It’s taken me until now to have a personal TOTP process robust enough to want to move my stuff across. When I get back from my current travels, it makes sense to try to move as much as I can to my new, synced, backed-up, personal authenticator solution.
Additionally, you can also use Google Fi, which supports the same messages app, and syncing the messages and responses like Apple's iMessage, just by logging into your Google Account after a little setup. I believe it's also intercepted upstream, and isn't reliant on another device being powered on.
Disc: Googler, not on Messages.
I got a TOTP card from Bank of America like 10 years ago. Ended up screwing me a bit when I lost it and then couldn't make changes to my account... I personally kinda hate 2FA now.
Wondering if there's a similar list for European banks.
UPD: there's link to https://2fa.directory/int/#banking on the U.S. page
I would love to switch to a bank that supported TOTP.
It should be a case of inserting the SIM card, and use AT commands over serial to send/receive SMS.
Combine it with a watchdog timer and a remote-controlled power-plug and you can even power it off/on again remotely if it crashes.
I've got a work phone in front of me, all it's used for is getting 2FA prompts (SMS and Duo). Yet randomly I'll find it's rebooted for some update because the manufacturer has decided that I have to have it, and now I have to unlock it to launch Duo. I have disabled updates as much as I can, but it still gets some periodic updates.
I ran a bunch of Android tablets for a while, and their batteries swelled up over time because they sat on charge all the time.
Maybe if you can run a custom ROM to achieve some of this. But it's not an option for my 'work' phone, since the Manufacturer doesn't allow unlocking the boot rom.
My point is not all devices are equal, and I think if I was going somewhere remote I'd probably choose not to rely on a phone.
> 1 year uptime with no crashes or reboots
Android (whatever version) informs me that it's not charging fully for blah blah battery reasons ... which is to say, it is in some way smartly conditioning its own battery.
I can't say any more about it since this isn't my area of expertise but at least with these pixel 4a devices, these issues aren't present.
One of these could temporarily be plugged in on request - they could have just a few of them (at whoever is head of IT) for different carriers just for this situation.
https://explorersweb.com/starlink-in-antarctica/
McMurdo could run their own BTS and provide SMS access only to mobile phones if the desire and funding was available. This would give you a legit mobile network registration.
https://www.theverge.com/2022/10/6/23389641/ukama-open-sourc...
Are femtocells just as crappy as WiFi?
https://github.com/traccar/traccar-sms-gateway
https://news.ycombinator.com/item?id=28125074
I use a phone in a drawer for MFA codes and use this to access the OTPs remotely, with some minor PHP scripting for a simple web-accessible front-end.
If you took a random Android, put in a sim, uninstalled or disabled as many apps as possible, and left it screen off where it had a good view of local towers, you'd have pretty good battery life. It wouldn't be very exciting... but if it just needs to sit in a drawer (hopefully not a metal drawer, see reception issue) and forward a couple sms a week, it'd probably make it through at least one week.
If you go for a model that has a higher capacity battery as a feature, that'll help too.
For example, I’m using a domestic CAP-like system (dubbed Secoder in Germany) for several of my bank accounts. It exploits the fact that your ATM card is a trusted computer with a built-in digital signature/HMAC feature.
You have to spend 20 € for a small battery-powered device, which features a card reader, a display, a PIN pad and a camera. (There’s also a USB-based variant without batteries and camera.)
On each online transaction, you insert your card and point the camera at the QR-encoded challenge on your computer screen. The display then asks you to confirm recipient and amount, and if you do, it sends the whole thing to the ATM card, which then shows you the 2FA code based on HMAC.
CAP seems to have become a niche thing as everyone is preferring apps nowadays, and those are much cheaper to maintain. I still think the CAP system is superior to apps, because it’s offline, carrier-independent and easy to use.
[1]: https://en.wikipedia.org/wiki/Chip_Authentication_Program
Considering that they haven't deployed chip cards until mid-2010s it's unlikely that this even exists (and indeed this was not available on any US banks).
At least in my experience trying to find a Canadian bank with reasonable 2FA they were all either SMS or a custom app. So I just sucked it up and stuck with my current one because there was no choice.
What is it used for?
The QR code contains:
- the monetary amount,
- parts of the recipient’s account number (both helps thwart MITM attacks)
- and a random challenge (which helps prevent replay attacks.)
That’s for the wireless model. Wired CAP devices don’t have a camera since they can use USB.
It charges the battery to something like 85% until shortly before my alarm is set, or the expected time I'll unplug it if no alarm is set. There isn't a way to manually control this, beyond changing the alarm time.
However, the battery is still going strong after 5 years.
(I wish they'd make a decent compact successor. The latest "Compact" Xperia phone seems to be 2.5cm taller! https://www.gsmarena.com/sony_xperia_5_iv-11838.php 15.6cm vs 13cm)
I mean, many laptops spend 99% of their time on plugged in/docked, and that doesn't cause any battery problems.
This 'lookup' script that I wrote will properly identify your number as being owned by google voice:
/usr/local/bin/curl -s -X GET "https://lookups.twilio.com/v1/PhoneNumbers/$number?Type=carrier&Type=caller-name" -u $accountsid:$authtoken | /usr/local/bin/jq '.'
... given any phone number, I can see, using the twilio API, where the number currently terminates to and who "owns" it - including subscriber name (ie., your name).I'm glad it continues to work for you because it should and you should be able to use a gvoice number in this fashion but ... you've just gotten lucky so far.
Below is one of the emails I got from Chase:
``` Dear Customer,
Our records indicate that you may have recently changed your mobile service provider or mobile phone number. As a result, Chase services that use this mobile number (such as text banking, text alerts, Chase QuickPaySM etc.) may have been disabled.
```
Again, you DO NOT need a cell phone tower to send and receive SMS and phone calls. You can register your phone on its home network near a tower and go WiFi-only forever after.
“ One issue is that the protocol for wifi calling is notoriously opaque. Carriers frequently change the underlying infrastructure and protocol details.
Also, the protocol assumes terrestrial broadband with reasonable latency and bandwidth. At McMurdo, as of this writing, latency to terrestrial locations is in excess of 700 milliseconds. Usable bandwidth for any given end user can vary widely, down to a few dozen kilobits per second.
The protocol also doesn’t expose any useful diagnostic info to the end user in order to troubleshoot. You just have to cross your fingers that the magic “wifi calling” icon lights up.”
This is how it works on paper. You may have had success with this.
It does not work universally. It won't take long to find a bank / FAANG / service provider that refuses to accept anything but a bona fide mobile SIM talking to a base station.
How does a SMS sender know this? Is there some mechanism in SMS to only deliver if by certain criteria?
I recently went on an international trip where I turned off my regular cell plan and used a local SIM card. Was surprised at the amount of services I couldn't log into because I was avoiding connecting my regular number due to the high international rate.
Receiving international SMS while roaming is typically[1] free - just make sure to turn off data roaming and avoid using that SIM to make phone calls.
1. It should in theory always be free on every carrier, but I wouldn’t put it past some MVNOs to charge for it.
Yes, you can, and it’s much easier with eSIMs because they can be just be turned on and off through your phone settings as needed.
In this scenario you’re obviously trading redundancy for convenience - if you break your phone, you can’t just pull the eSIM out and pop it into another device. I keep a copy of my eSIM QR codes in 1password, but of course there are risks there too.
I’ve thought about using one a few times, when going travelling overseas for extended trips.
I'll be surprised about most Bluetooth keyboards don't use encryption.
And I feel like it's too panorid for me to worry about someone probing to your keyboard with an USRP or a HT-301.
CVE-2019-13055
CVE-2018-8117
CVE-2010-1184
Don't underestimate a determined adversary. Secondly, look for single points of failure and eliminate them as best you can. If someone gains access to your email, could they perform password resets?
Phishing victims are not categorically stupid.
Glad you asked ...
... and your comments children are not just wrong, but completely misunderstand the ecosystem they are discussing.
Mobile telephone 2FA is not for you. It's not to help you - it's not for your security. All of that is bullshit - and demonstrably so[1][2].
What is actually happening is that FAANGs, etc., have a brutal, unrelenting spam/scam problem which they have no idea how to solve.
Forcing every user to burn a phone number tied to a physical SIM card is their last-ditch attempt to throw enough sand in the gears and stay above water.
It sort of works.
It's very painful for end users, introduces all kinds of strange inconveniences and probably doesn't stop determined abusers ... but it seems to work better than anything else they've come up with thus far.
But make no mistake: It's not for you. It is not for your security or safety.
[1] Post-signup challenge to user - help us prove your identity by entering in a phone number you've never shown us before.
[2] Interestingly, very high value logins like brokerage and banking typically allow other forms of 2FA that don't involve burning a mobile number because those firms already have many other routes of identification and verification.
2FA schemes must always support TOTP.
Potentially, as an alternative, 2FA must not rely on SMS, as it is not secure.
[1] https://www.garmin.com/en-US/p/765374 (inReach Mini 2)
There's probably some interesting failure modes when trying to get a modern device to stay connected for months on end, without deciding to reboot for a security patch or similar, or taking an automated app update.
even other payment gateway have 5 minutes at least
I'd much rather have a reliable method of 2FA that works offline, on all of my devices and can only be hijacked from me or the service than use one that requires my phone to be nearby, working and having service and can also be hijacked by my phone company.
https://www.twilio.com/docs/glossary/what-is-dtmf
https://www.twilio.com/code-exchange/forward-sms-email
The downside to doing what I did is it basically removes 2fa. You are back to a single factor as the 2fa is now automated and that may not be appropriate for many use cases.