More traffic benefits the industry (since some sucker pays for it). There's no incentive for any of the entities that profit from this to stop it (unless it's too sell you a premium protection service).
More traffic benefits the industry (since some sucker pays for it). There's no incentive for any of the entities that profit from this to stop it (unless it's too sell you a premium protection service).
I’d say 7 years is plenty of time that folks really shouldn’t be using it.
https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo...
To name and shame: BNP in France. My personal account stayed on the app, but for my company account, it I only get SMS now.
I remember a story about a university in Lithuania also opting for either SMS or a proprietary 2FA app, but not allowing TOTP either: https://fsfe.org/news/2023/news-20230418-01.html
What's worse, all they had to do was enable a checkbox in the settings somewhere but they went on an embarrassingly long e-mail thread back and forth, not even willing to help the users.
So I think that in cases like that, it's definitely a good idea to call attention to the issue and tell more people about open technologies like that! Unfortunately, most people just won't care.
That said, TOTP is actually decent and I'm surprised that it's not supported everywhere, especially given how much shouting about SMS not being secure enough goes around.
SMS-OTP, despite its many other flaws, at least offers a trusted path to say “by sharing this code, you are paying x€ to y corp”.
Anecdotally, in the case of my bank, if I try to make a transfer, the SMS is something along the lines of "Are you trying to transfer 1234 €? If yes, enter the code 12345, or else call your representative asap".
One terrible point being that once you've entered the confirmation code, they consider the transaction as "strongly verified", so it's not that easy to roll it back. Fortunately, I've never had this happen to me so I don't know what that entails, but contesting a random unverified charge is as easy as clicking on the transaction list and then "dispute".
The problem isn't really interception in my view (even though SIM-jacking and porting attacks are scary enough!), but rather the high likelihood of phishing/UI confusion: With modern mobile OSes auto-filling transaction details, I'm not too sure if everybody is still reading the text accompanying the confirmation code.
It's quite possible for a fraud victim to be directed to amaz0n.com and tricked into entering an SMS-OTP confirmation code to confirm a purchase of €5.00, without noticing that the accompanying text actually says "only enter this code on BuyCryptoNoKycOrBacksies.com to confirm your purchase of €500".
But the problem is also only allowing SMS 2FA. Why not allow both and let people choose TOTP?
I have a feeling SMS 2FA is used as a cheap way to implement a rough social credit score. If you have a stable life and follow the rules, then you have continuous access to the same phone number. And only allowing SMS 2FA allows you to only deal with this population, and ignore populations that might have higher proportions of “costly” customers.
My country’s administration lets people e-sign PDFs that are accepted throughout the EU as legally binding/equivalent to a paper signature using only a static password and SMS-OTP.
(The system used to be based on PCKS#11-compatible smart cards, but nobody managed to use the software, so they switched to SMS…)
Indeed. I once worked on a system where we had SMS as one of the "last resorts". When someone used SMS as recovery, we'd disable withdrawals and fundings (it was some sort of wallet) as well as severely limit their daily limits. Until the account was fully restored again using normal, secure methods (Mail, KYC, etc).
We were hit by a similar "attack" where our "let us call you to start recovery" was abused by putting a toll-number there, and our system would then call this toll-number and we'd get rediculous bills. But putting in limitations helped a lot, so we did this for SMS too.
If I lose my phone I've lost all my various OTP authenticator apps - I don't think they are backed up to icloud
Note as well that you really don't want to rely on SMS if travelling internationally, which is a use case I hit reasonably frequently.
I understand the security aspect and realistically most people will have smartphones anyway, but forcing everyone into this surveillance duopoly, especially as Apple is overpriced and Google is ad company with stated mission of removing privacy, makes me pretty salty.
There should be a better way.
That's not correct. Many password managers have TOTP authentication features built in.
There's also increasing support for security keys (e.g. yubikey) with many websites.
Passkeys are also on the rise.
Another bank's employees used a physical RSA securid TOTP token (which was a bad idea since RSA hung onto the seeds and got hacked).
(TOTP can also be added to feature phones, it's fairly straightforward. There's open source java ME projects.)
Corporate clients with their competitor had been using MSDOS based banking software that came with a hardware token that ingested a challenge as flashes of light from the screen, which was pretty neat! It didn't read a debit card, the seed was just baked in.
Before banks started shipping physical tokens or card readers, they would send you a list of one time codes to approve transactions.
Note that Google also has the option to generate such codes (although you get 6, not 50 at a time), so you can get into your account even if your phone is stolen.
All of those worked in the age before smartphones.
Now, there's also passkey/U2F/FIDO2 based hardware keys you can provision yourself and buy from several vendors, like Yubikey or Token2.
There's plenty of reasons to be salty about the smartphone duopoly and surveillance economy, but for 2FA there's plenty of alternatives. And if you do use a smartphone, you could always use an open source authenticator app.
If I count correctly its checking 1) username/password; 2) currently holding my payment card; 3) card's pin
Even if I don't count owning reader itself as another point of security (since it can be obtained ie via social engineering and its a simple generic device) its at least 3-factor auth and its still the most secured ebanking from all banks I have. Annoying a bit to log into but this is one place I don't mind it at all. And no phone involved in any step, for which I am very glad (not having yet another thing to manage, keep updated, worry and chase cancellation when lost/stolen).
True – but using SMS-OTP signs over your life to your phone provider.
In any case, neither Big Tech nor Big Telco are my favorite candidates to be the guardian of my digital identity.
[1] Had them for years in an apartment where they have a local monopoly; speeds of 0.3 Mbit and latencies of 15 seconds – yes, 15000 milliseconds – during the pandemic were not unusual. The upgrade of the local node is scheduled for late 2024.
Did they then block a SIM transfer request to another phone provider?
In my country there are significant consumer protections around mobile phones.
That's a good point – we urgently need those same protections for e.g. things like email addresses or Google accounts.
But, yes, I do know people that are unable to port out their phone number: Sometimes it's a line on a contract in somebody else's name (minors, spouses etc.), sometimes it's a prepaid card not properly registered (although that's getting less common with the EU mandate to verify everybody's identity before activation).
Neither a phone number nor a Gmail address/Google/Facebook/... account is a good anchor of trust for digital identities.
Most places do not support Yubikey... so getting SMS on my Nokia 3310 is the best option for me.
SMS is the way to go.
SMS is the way to go until you need to sign in from somewhere you don't have cellular coverage.
TOTP is superior in almost every way. Failing that, sending a login link (or code) to the user's email address is more secure than SMS.
https://github.com/kwart/totp-me
https://github.com/baumschubser/hotpants
(Couldn't find one that supports QR codes, though I don't see why that would be hard to implement)
(Yeah, the UX could be better probably, but hey.)
What's your proposed solution again?
https://en.wikipedia.org/wiki/Time-based_one-time_password
edit: here's a cli tool for doing this: https://www.nongnu.org/oath-toolkit/oathtool.1.html
You cannot install a barebones TOTP app on your Nokia 3310 because it is closed source.
Most services don't offer third party TOTP because they are pressured into pushing their shitty proprietary apps.
But TOTP not only is more secure but it's completely offline. It's close to the best solution and totally exists right now
What's all this about SMS being insecure? I never heard of phone numbers being hijacked in my country (except in the case of physically stolen phones ofc). Is this another consequence of US making it so easy to steal an identity?
That is, if your vendors all agree on something.
> Seems you have limited experience un both subjects
Yes, also limited experience on identity theft. Care to comment on my suspicion?
There are of course examples of vendors that don't. I think Steam is one of them. And my bank.
Most of the new alternatives seem focused on pushing lock-in traps and are complicated for users to understand or use. If they're going to lose user tracking of the phone number they want something even worse to replace it, not something open like TOTP.