Hopefully the whole esim and namely esim transfer initiative would end phone as second factor.
And yes, I know that options for 2FA are limited in general. But phone is not the best one.
Hopefully the whole esim and namely esim transfer initiative would end phone as second factor.
And yes, I know that options for 2FA are limited in general. But phone is not the best one.
Which is usually how SMS 2FA are stolen, and no one is liable for the consequences.
Which means SMS 2FA is pretty low security. Convenient for most, but secure? Hardly.
> And yes, I know that options for 2FA are limited in general. But phone is not the best one.
Phone doesn't just mean SMS. E.g. bank apps in the EU use MFA with the bank's app directly which you have to unlock with biometrics or PIN, after unlocking your phone.
Phones are the best one.
Why?
Because (almost) everyone has one within reach.
Security enthusiasts and believers constantly fail to understand why straight passwords and to a lesser extent phone 2FA never go away: All their proposed alternatives and solutions are inconvenient.
Most people couldn't give a rotten rat's undead arse about security, but they will kill for convenience. Passwords and phone 2FA win and keep winning because they are convenient with good enough security.
Every part of the industry that matters has been bitten by using phone numbers as a 2FA mechanism. It's why they're actually disappearing and are being phased out in favor of apps, OTP tokens, and email codes, depending on the amount of influence technical people wield at a given org.
And all of them are some form of jank or inconvenience.
Look, most people (myself included) don't give a fucking fuck about security. Our time lost to the kabuki theater of security is worth more than the so-called "security" we gain, and that's assuming whatever is being secured is even worth securing.
A determined attacker will ignore all that and just undermine everything with social engineering against a useful customer support tech anyway.
Unless your solution is as simple as entering a password and hitting a button, which is the digital equivalent to taking out a key and unlocking your front door, it is not going to see widespread acceptance. Make your fucking security solutions convenient, not secure. kthxbai.
Even cars did away with keys because turning the ignition is an inconvenience compared to just pushing a button.
What password?
I mentioned the NHS app I use in a different sub-thread, so let's try my (not very good, would not recommend but they offered decent credit balance interest) current account. I tap the app on my phone, I get a whirl of nonsense, and then:
"Verify that it's you" and I touch the fingerprint sensor on my Pixel 6.
And that's it. No passwords, no PINs, no SMS messages, no separate authenticator device
This is much more secure than real human passwords (it'll be an elliptic curve signed message, so similar to HTTPS) and much more convenient, and short of convincing me to literally send you my phone and my finger you can't trick me into giving you access.
Consider, for example, banking apps: because 2FA via app being near-universal these days, even the web page doesn't let you use your bank account without installing the bank's app. And banks are, after MAFIAA, the biggest proponents of remote hardware attestation schemes. Thanks to that, we're reaching the point that phones that aren't locked down by Apple or Google are going to become useless. Mod/rooting scene already all but evaporated because of it - rooting your phone means fighting half the apps, including your bank, making the whole exercise not worth it.
Google and Apple could turn modern phones into convenient-to-use security keys/FIDO passkeys.
Not only that, they also both provide the same underlying technology to 3rd party apps, because the core trick in WebAuthn uses a cryptographic hash of a DNS name, so if we put say a UUID minted by your app store in where the DNS name goes we get the same functionality, (logically collisions can happen, but they're astronomically unlikely) but customised for each phone vendor & each app.
So e.g. I tap the icon for the NHS app on my Pixel 6, it starts up to where it would want me to do nonsense with passwords and so on but nope, hold my thumb against the screen, biometric match inside the phone, therefore this is my phone, it has a FIDO-style proof that this phone, which enrolled via the laborious process with passwords and SMS and whatever, is mine and it says this is me. Now I can order routine prescription re-fills, they go in a queue, my doctor says yeah, tialaramex doesn't need to re-check those blood levels until summer, prescription approved, done.