U.S. FCC says new rules will curb SIM swapping
arstechnica.com
arstechnica.com
They disable SMSes altogether for 48 hrs when a new sim is given. This gives enough time for a victim to go to a physical location to resolve the issue. It doesn’t solve it 100% but definitely introduces enough friction to put a dent in the efficiency of the attackers.
The current setup feels akin to the longstanding problem of companies using social security and driving license numbers for authentication. Only the industry speedran the creation of this new problem, so they should be expected to get rid of it just as quick.
(e.g., anyone could create a service that someone could use, which would allow them to request a 2fa code to be issued over SMS at any time after enrolling it via the OTP pairing process)
Your phone number should not be your gateway to essential services like banking, investments, or even personal life. The madness has to _fucking_ stop.
So something that indicates there’s a real person there paying a bill. Plenty of room for innovation here but my suspicion would be that it be a function of a credit bureau.
No, the reason is that your phone number effectively functions as your personal ID, lacking of any other good alternative.
AT&T required me to go to a retail store with government-issued ID and provide the last 4 digits of my SSN. I then had to answer some questions that were clearly provided by a credit bureau; all of them were some version of "which of these 5 addresses have you lived at before?"
This was concerning because I'd think that for most people, with a bit of digging, it's not that hard to get a list of previous addresses. But sim swapping should probably be at least as difficult as obtaining a replacement passport or drivers license.
Passwordless, whatever it's called this week.
Also, passkeys don't provide a way to perform non-Internet authentication. Like when you call your bank or they call you, you cannot use a passkey to authenticate each other purely over the phone, you need to be online. While this is surely technically possible to do over the phone (or postal pigeons -- j/k), it's not even on a radar and is extremely unlikely to ever happen in any foreseeable future.
Now they're going more phone based which feels like a step back to me (but more convenient of course... though I hate the kind that makes you film a colored qr code from your pc monitor: doesn't work in mobile browser since phone camera can't look at its own screen, and makes you look like photographing your pc screen)
The system is 2FA with either your phone or a hardware dongle proving your identity. It is strongly authenticating you as a person, that is precisely identified (but the services are only getting a token, but it can also validate your person-number - think SSN in US context).
It is quite harsh in device security, recently failing on beta versions of Android - on top of afaik always failing on rooted devices...
The phone version also requires you to scan a continuously changing qr-code twice to proceed, which is shown when you need to identify yourself (in an I-frame). This is to ensure you are "physically" present where you are being authenticated (i.e. to block of some phone scams).
Works pretty well and is reasonable secure, whilst still having some flaws..
In the future, I believe this system will work in some/all of the EU due to the coming eIDAS legislation...
So overall, I think passkeys are a good alternative to SMS :)
I agree with you 100%, I wish we went for much secure way. Unfortunately UX friction and pre-established ideas will make it way harder to roll out to the general public.
If a person can't handle 2fa, do they really need to be using online services that are important enough to warrant using 2fa? I imagine the world will advance and this will become easier over time, but for now single player security across wires is complicated.
I do not see how the eldery in the US would need more explanations than in the EU.
I'm another person who hates having to do 2FA via phone all the time, I am overseas a lot and it can pose serious problems for account access. I found out today that Authy even has a Linux client - hopefully this is the beginning of my life getting a lot easier.
You'll have to name a few first.
I know the comment you replied to said "most", but that's not a declaration that any countries have actually solved the issue. It's more that some countries are just too small/isolated to see certain crimes, so it's easier to say "most" than "all".
If you give your phone number to Google, they will pressure you to enable SMS MFA and SMS account recovery. So your phone number becomes the weakest link into your account, which is pretty bad considering the state of sim swapping.
Google and other companies should make this clear to users. You should never have both SMS MFA and SMS account recovery enabled. If you must, only ever enable one. Ideally, neither.
Because every company on the planet forces me to provide my phone number to auth me with SMS, I now need to pay for roaming to use this god-awful method of authentication I never signed up for. On top of the local sim card I still need to buy, because roaming is often throttled to unusable speeds.
But it gets better. If I break my phone, I can currently move my physical sim into a new device in a matter of seconds. No problem. But with Apple removing the physical sim, soon I’m going to be forced to switch to eSIM.
eSIM is marketed as more practical, yet in reality it is anything but. I’ve been following forums for many telcos in the UK and Australia to understand the problems people face with eSIM.
First of all, if it is even possible to provision a new eSIM, most telcos lock this behind SMS 2FA. So if you break your phone, you can’t log in to provision a new eSIM. Also, usually this needs to done using an app, which is often only available in the telco’s region. So if you live between countries, you’re again out of luck. Some telcos require you to visit a physical store to move an eSIM to a new device. Some telcos won’t provision a new eSIM electronically, requiring you to use a physical cardboard QR kit. And some telcos can only activate a new eSIM when the device is connected directly to their network, so even if you somehow managed to jump through all these hoops, you still wouldn’t be able to activate a new eSIM abroad.
So if you break your phone overseas, you either need to live without banking and a range of other services, or book an immediate flight back to your home country just to provision a new eSIM.
Calling this madness is an understatement. Any company forcing MFA must allow users to pick from a range of open standards.
I have these services connected to a Google Voice number.
I might try a couple of things:
1. Call Capital One customer service and yell at them.
2. Go visit them in person somewhere and yell at them. Bring a phone that rings when they dial the number.
3. Register a carrier number with them, and then, behind Capital One's back, port that number to your Google Voice account.
> They wouldn’t let me activate a card with one.
You can activate a card by just going to the URL printed on the sticker attached to the card. No need to use any phone number.
I’m sure I could have figured it out eventually but once their proprietary id scanner rejected my passport I gave up and closed my account.