Companies embracing SMS for account logins should be blamed for SIM-swap attacks
keydiscussions.com
keydiscussions.com
If the argument is that phone number can always be recovered from real world identity, link the damn authenticator app to SMS instead of having to hand out your phone number to every company in the world.
Someone would need to physically take your laptop, unlock it, and get your account passwords before they could use your yubikey to login to accounts.
Would that be what passkeys would be?
Durability: If you drop your smartphone, there's a pretty good chance you'll shatter the screen and buy a new one. You can play tennis with a Yubikey and it'll be fine. You can run it through the washing machine and it'll be fine.
Longevity: Laptops and smartphones generally only have a 3-5 year lifespan due to battery degradation, and many people will want to swap it for one with more storage or whatever anyways. A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites.
Portability: I have a smartphone, a work laptop, a home laptop, and a home desktop. My Yubikey has USB and NFC, so it can trivially be used with all of them. Individually enrolling each device would be a nightmare, and having the credentials sync is a bad idea from a security perspective.
Security: If your device gets compromised, it's pretty much game over: the attacker can now log in to all your accounts, any time they want. With a Yubikey I have to physically insert it and tap the button for each login - which is relatively rare because active sessions don't tend to expire. This means I would have to actively participate in a mass compromise of my accounts, making it way more likely to be noticed.
The point of passkeys that the key is kept inside a separate secure computer running secure blobs, so user codes can't touch it. That sounds sketchy but contactless payments using similar embedded secure computer has been fine so this should be too.
But I do recognize that really is a legitimate question and it feels like Yubi would benefit from running more outreach / promotion programs with schools and companies. I never felt like I could justify spending $50 just to try it out(especially when it doesn’t have support in a lot of sites), but then they partnered with Cloudflare to sell up to 5 per person at $10 each. It was a no-brainer to try it at that price and I haven’t looked back
RSA keypads were an example. Absolutely free. Hung on keychains. Work well in that it was "secure" and worked, but an absolute nightmare for the banks to manage. UX was equally terrible (sure Yubikey isn't that).
The only way to mass introduce it is require multiple key entites to push and collaborate like your bank + phone provider to push it out for free.
Yubi keys are a logistical nightmare for my parents. SMS is not. For my parents, sticking to something in the phone is good.
Using a yubikey says, specifically, that if I lose this little device and the bypass codes, that I have presumably stored on encrypted storage in a way that doesn't require the yubikey to access, then I want it to either be impossible or exceedingly difficult to recover access to this account.
Very few people actually want that, and if yubikeys become widespread, there will be a wave of people having tantrums because their yubikey is lost and the account is unrecoverable.
If it isn't extremely difficult to recover an account in the absence of a yubikey and the loss of the bypass codes generated on enrollment, then there's no point to them.
I've run a b2c website. There is a shocking percent of internet users -- I'd estimate 20% -- that cannot reliably tell you their email address (5% that literally can't, and another 15 that can't reliably). Those users having yubikeys would be an utter disaster.
My email address is firstname.midddlename@<wellknownemailprovder>.com
I get a dozen emails a week from companies and government agencies trying to reach people with the same first + middle name combination from around the world. People seem to think they automatically get an email address with their name provisioned or something and they just sign up for accounts and services using that combo.
The bigger problem is that a large number of sites don't implement MFA properly, and don't allow you to enroll multiple MFA devices. This really could only be fixed with regulation that clearly defined MFA, so there would be consequences for improperly implementing it.
In the politest way possible, I question whether you've interacted with the modal user.
edit: I can try to dig up the article, but here's the precis: 5-ish years ago, google briefly changed their search results ranking. Lots of people were logging into facebook by searching facebook, instead of typing facebook.com, then following the top result. Some other site briefly was the top result when searching for google. That site got a wave of users submitting help requests because they couldn't log in with their facebook credentials, and accusations of subterfuge or wrongdoing because their accounts were deleted. I think it was pinterest, but I may not remember correctly. Either way, it looked nothing like facebook and didn't use blue.
That's what a significant fraction of internet users are like.
$5 in the US is roughly equivalent to $20 in my country, when you adjust for purchasing power parity. We have over 70 million people who use Facebook and Youtube daily.
If rich Americans won't pay $20 for a Yubi key (and they are currently $25) why should we be expected to?
May own anecdote is that I almost never receive spam sms despite having nothing in place beyond whatever my service provider does.
Spam mails make it through two+ layers of filters (service provider + my own) more often than I get spam SMS, and I have to trawl the wasteland that is the spam box once in a while to ensure important mails have not been missclassified.
SMS 2FA predates cell phones. First SMS 2FA was AT&T in 1996 using pagers.
The first draft of the RFC for TOTP was written in 2008. Google Authenticator came out in 2010.
I knew someone who worked for a bank in the late 80’s - early 90’s, and I distinctly remember them having a little keychain dongle that generated one-time codes every (30? 60?) seconds for secure remote login.
The product may have been an RSA SecurID, or something else. Branding aside, it’s the same concept as modern TOTP. The main novelty of the TOTP RFC was standardizing the setup / secret sharing process and algo.
Weird, all the carriers I used either have free international roaming (at least for receiving text), or have wifi calling which allows me to use my phone as if I'm on the home network anywhere with an internet connection.
And though the one I used before did, I usually have a cheaper local SIM in my phone for data use when I'm traveling, and I'm not swapping SIMs just to authenticate to some company that hates its customers.
Many people don't have free international roaming, in fact mine only has roaming for US (I'm in Canada) and for zero roaming options available outside of North America.
Receiving calls isn't necessarily free when roaming.
I'm pretty sure it's illegal for an EU network to charge for receiving a standard SMS or MMS - even while roaming.
I can therefore receive an SMS OTP in any country and won't pay a penny.
False
Note that the law in Brazil forbid telecoms from charging to receive phone calls or messages, even when roaming. But I guess the regulations don't extend to foreign users that are on international roaming, or companies do it anyway counting that the person will only find out after returning home and won't know how to fight it. Authorities are not set up as well to receive complaints from non-residents.
(Perhaps this is just dread since I use it for the same purpose)
Google Voice is a total mess, and as a “free” consumer service that Google has shown little interest in maintaining and supporting, you don’t get any kind of support or help whatsoever.
My sincere advice (if you’re a free Voice user) would be to delink your Google Voice number from all critical services. Get a real phone number for which you have the ability to get customer support.
Google Voice is probably my favorite Google service... I have looked at alternatives many times in the past and have never found anything that compares that isn't super expensive (and usually not as good). I really hope Google keeps it. But I am prepared to migrate if Google shuts it down (and I really hope they provide a seamless number porting experience if they ever do...).
You can trust google they will let you use forever and won't block your account anytime without warning though.
Their own internal teams as well as game studios didn't know about Stadia's end until the day it happened, what makes you think they'll treat you better with an unpaid service?
The going argument is, WhatsApp if your number gets unused for 90 days doesn't let you reset password or something so its all fine.
Then its a matter of submitting a written application with the bank to change your mobile number so its all fine
Doesn’t using your password manager as TOTP code generator reduce the number of factors back to 1?
If the attacker got a list of passwords from a leak and your password was on it, the 2nd factor provided by the TOTP will still save you.
So, it just depends on your threat vectors. I’d rather people I support keep unique passwords alongside TOTP in a manager they’ll actually use than skip or use SMS TOTP because of a vague concern about targeted hacking of their manager.
Are there other threats that TOTP-in-password-manager can protect against that the randomized passwords don't already?
tbh the UX problem of 2fa for "I use random passwords and am not vulnerable to credential stuffing" users is a pretty big reason to stick TOTPs in your password manager.
Security is always a series of trade-offs, and 2fa brings some hideous trade-offs in many sites (well over half only allow one at a time, for example, and then you lose access permanently). TOTP with a standard like this lets you choose, rather than the site choosing for you.
Right, and if an attacker can dump password hashes they can likely dump TOTP seeds as well. With that level of database access the attacker may be able to steal all your info from the impacted service, so talking about the password may even be a distraction since all your data is already stolen.
TOTP + something like 1P moves this from happy-monday-an-infra-engineer-left-time-to-rotate-100-accounts to something you can just do periodically as you like.
I don't know anyone who buy a second smartphoe to make it sure 2FA is on a separate device.
The problem is that the vault file can be copied, which means this is now "something you and your attacker have". Even worse, it's not just the (probably encrypted) vault file: if your computer ever gets compromised, it is trivial to wait until you unlock the vault, at which point they can extract the now-plaintext TOTP secrets.
The way I understand it, the "something you have" factor is something which is intrinsically only a single item: either you have it, or you do not. If it can be copied, one of the copies could be compromised without you noticing - and because it's a copy you wouldn't even be able to revoke it without changing your own token too.
If that happens, nothing will save you. The malware can just grab your session tokens whenever you log in, then do whatever it pleases.
That post request is processed by my own Google apps Script to send it to my own telegram bot.
When I travel where my phone will not work in that country, my wifi connected devices get OTP right away, in about 5 seconds.
My favorite is it's often paired with "passwordless" trash lol.
Why can't I just give my whole fucking credential out in 1 action. What's this nonsense where I have to enter my username, THEN wait for the page to load, THEN click "send verification email" or "send code", then half the time they want to SMS me and have me enter another code lmao.
I can’t speak to all of them, but many sites that require (only) a username first have enterprise SSO integrations.
The enterprise buying the service (understandably) doesn’t want its employees to type in both username and password on a 3rd party site, especially since the SSO process will handle auth after the username is entered.
I know of one site with both username and password on the first page, and has enterprise SSO. Login will automatically fail if you enter anything in the password field when logging in with an SSO-enabled username. But that doesn’t stop copy-pasted credentials from being transmitted to their server, which is something enterprise customers want to avoid
> [...] pay for international roaming [...]
I don't remember ever having to pay to receive SMS abroad. Is that a common feature with the plans where you live? (I mostly have experience with pre-paid plans from Asia, Australia and Europe.)
It’s absurd that for ultimate identity, currently services tend to rely on email, google account, or SMS, all of which are some combination of insecure, at risk of banning you on a whim, hard to recover, or prone to spam since they don’t verify real life identity.
1) Phones can be lost or stolen
2) People move country
3) SMS attacks
4) Phone numbers get reused
5) Users must maintain a paid phone plan
For the love of science, DO NOT tie accounts to phone numbers!!!-- edit --
I updated the first line to clarify that I'm not talking about one-off notifications etc.
I was on a 2 week camping trip and a nasty storm rolled through my home state. Power went out for 5 days and I wouldn't have known if it wasn't for the SMS notifications. I immediately cleared out my fridge and freezer when I got back.
I can agree it's unacceptable for security while also disagreeing with this statement.
Anything tied to material account actions shouldn't have anything to do with SMS.
Flight delays or notifications of works in your area etc won't lead to account takeovers or denying access to your account - but the way many companies use SMS can potentially lead to this.
This way if the phone is compromised your email is still there.
As far as convenience goes it is convenient in actual practice as an end user. I’m sure even if 1% have this issue that’s billions who are not. It’s cheap and it’s convenient. Your phone gets the message and autofills.
You don’t need to switch apps to check email or something. And your account will always be recoverable as long as your email isn’t compromised. If you lose your email I mean that sucks. But that happens anyway and it’s why people should rotate passwords and set up MFA.
Security can never be 100%. That’s just a fools errand. It should be convenient enough and secure enough that it works for as many people as possible.
Literally everyone else outside of HN doesn’t even care or understand. They don’t need to. Just use the apps to do your thing and move on.
Let the nerds handle the backend.
I often see couple’s using each other’s phones and knowing each other’s passcodes. I’m not sure I could ever trust someone that much. I don’t think I’d even give my passcode to my own mother, and she’s never given me a reason not to trust her.
The worst part about it all is that it’s not opt-in. They just randomly start using SMS as 2FA. If I were to change phone numbers, I’m not sure what I’d even do. How can I change to a new number without control of the old number to get into my account? What happens if I miss one, because they randomly decide to use 2FA on an account I didn’t think to update? It’s a really bad system all around.
2) Roaming. Often free to receive texts abroad.
3) True
4) True, but it’s easy to keep it active assuming you at least have data on it
5) True, but it can cost peanuts with the right setup. I’m holding onto my European and Thai SIM cards with less than $5/year. My Google Voice number is free since 2009.
I agree I’d just prefer using Authenticator and Passkeys, but let’s not lie about the advantages of SMS.
The answer in all these cases is having more than one option enabled. I just recently tested my Google and Apple login simulating a loss of phone and computer. It was tough but there are options (e.g. Apple lets a friend be your full 2FA, so you can even recover encrypted data)
There is an insightful tweet [1] in Spanish that is translated as follows:
""" Well guys, the payoneer mystery is solved.
#PayoneerHacked
- The attacker compromised the gatway SMS used to send the 2fa to Movistar customers (the platforms use this to sneak the cost) - The attacker saw 2fa messages passing from Payonerr to a Movistar phone number but had the problem of not knowing the email of the Payoneer user to change the password and make the transactions. - The attacker, to discover what email was behind each phone, set up a phishing site to try to take ONLY THE EMAIL from there and with the email + the phone + the 2fa that accessed the compromised SMS gateway in real time, he was able to change the password, access the account and send money since I kept reading the 2fa that arrived on the Movistar phones. - That's why the victims saw several real SMS with 2fa coming during the night that emptied their account. - Even if Payoneer customers had fallen for phishing, they would only have had one 2fa stolen, and not all that is needed to log in, add an account and transfer. This need makes it evident that the commitment to the SMS gateway existed.
- The victims of this scam lost their money because the last mile of the security stack was compromised.
Be careful, because Facebook, Twitter and others share the same gateways to save money on SMS.
Here I leave a screenshot of the SMS that arrived during the early hours of the morning to a victim and that the victim was never able to share in any phishing and that were necessary to empty them.
(whatever you read in the media... fruit, lots of salad and little sauce. here's the post)
Thanks to everyone who cooperated. """
[1] https://twitter.com/julitolopez/status/1748440685743587811
Anecdotally, I'm annoyed every time I have to log into a Google account using phone verification, because I have to stand up from my desk and find my phone (which sometimes is in a different room) in order to receive the call/message with the code.
TOTP is much more convenient in comparison. I don't have to stand up from my desk, because I store the codes in KeePassXC.
https://www.google.com/account/about/passkeys/
https://blog.google/technology/safety-security/passkeys-defa...
Sites that support Passkeys: https://passkeys.directory/
Its implementations specific I'm sure, hwoever its not as straight forward as one would hope.
It sure does, which these horrible sites could easily verify by invoking the single line of JavaScript [1] to learn as much, instead of assuming "Firefox -> must be unsupported". Absolutely infuriating.
[1] https://gist.github.com/miguelmota/ad833d2e6f024a7189f803664...
Everything I read about Passkeys says this scenario is 100% impossible, as it's based on biometrics and no longer using a text string that can get lost, but I'm still nervous AF. I've had to do the "reset a password that's behind 2FA" dance before and it makes me want to crawl in a hole and die - super duper scary.
Somebody tell me to chill out.
More realistically, what if Google decides to disable my account, and holds my passkey database hostage (which they can, by design)?
My passkeys are shared with family members in iCloud (where they are synced to) for bus factor. I don’t recommend using Google for any consumer services if you can avoid it, especially syncing your password/passkey database, as there is zero support if something goes wrong.
I’ve submitted comments to this effect to the FTC, and I’d encourage others to as well. Email (where all roads currently lead) should not be your identity in the 21st century, and losing a device or Big Tech account shouldn’t permanently banish you from digital account access.
Some relevant comments I've written on the topic in this thread: https://news.ycombinator.com/item?id=38691082 | https://news.ycombinator.com/item?id=38691156
I haven't been able to log into my primary Google account for many years because while I have the username, the password and the recovery email address (and all the emails are forwarded to me), I no longer have the phone number associated with the account, so clearly I'm trying to break in.
Even have the audacity to send me an email with “someone tried to log in with your username and password!” Yeah, that was me clowns. :-p
Out of nowhere, they locked me out of my account, then they asked for my phone number, and I had to put in a code received through SMS. But that was not enough, because then they asked for a national ID card (the gall!). Of course I did not send it.
However, I kept trying to log in with the password and SMS code for a couple of days hoping that the ID requirement faded away, and now they say that I "have reached the maximum number of attempts. Please try again at a later date.". Well, duh.
So, now I have a ghost LinkedIn account with my face and my data that I can't even delete.
I'm seriously thinking about asking a bunch of people to mass report my account for racial hate speech or something so that at least it gets deleted.
This is where being an EU resident would be handy.
Of course, using it as a weapon against your competitors is the unsaid reason for these operations...
Facebook once balked and demanded my driver's license scan to keep using the account for security purposes or no more login for you. I called their bluff and abandoned the account. A few months later I tried again and suddenly the driver's license wasn't needed anymore. Then I stopped using it for YEARS until they sent me a single email with a link, which LOGGED ME IN to the dormant account without asking for a password on a new PC that had never used facebook before. I actually don't even remember the password at this point but it is still logged in!
When I got back to civilization, I turned off Google 2FA, and will never turn it back on, at least for personal accounts. I would rather drop my usage of their services than deal with their account login bullshit.
Shame on you google.
Randomly losing account availability like this is completely unacceptable for critical services like the ones they provide.
I think my best action is to use one of the sim-swap services myself to intercept the SMS to the guy who owns the number now.
How does the "without stress of losing it" part work?
Some have even done this after initially allowing me to sign up using it, changing their policy sometime after I've signed up, and I usually only notice when I end up locked out of my account.
Fortunately it's mostly been store apps or payment services that I can just avoid going forward, since they clearly don't value my business, but I'm concerned that one day, my bank will do the same and just lock me out of my account.
Viber did this to me. My Viber account is from 2012. I only found out when I switched phones.
My experience may not apply to you, but it is still a risk, IMO, to rely on the “free” Google Voice.
I also seriously doubt that blocking VoIP numbers is anything other than companies making their own lives marginally easier (because VoIP numbers can be used by people generating multiple trial accounts in case they're used as a (bad) "proof of personhood").
But that Romanian SIM card I bought at a roadside kiosk on a boozy weekend in Timisoara without any ID is fine?
- everyone has a phone
- most people rarely change their numbers (if ever)
- many people are more likely to give out their phone number than their social security number
they couldn't care less about the security of your account or the fact that it's a valid number you control. they want the number that will uniquely identify you and already resides in the db of whichever adtech company bids the highest for your data.
and
> Much of the ire relating to SIM-swap attacks has, understandably, been directed at carriers. Indeed, carriers do a terrible job of securing customers’ phone numbers, and may be liable for that shortcoming. But here’s the thing: carriers’ security has always been bad, it has even been legislated into being bad, and other companies have still chosen to build mission-critical systems on top of that weak link.
and
> Despite offering poor security, SMS offers a nearly frictionless way to sign up new customers (think of Uber's onboarding) and handle password resets, and companies felt they had to match competitors' adoption of this technique.
This last bit was unfortunately overwritten in a Wordpress post update, and I added it back.
Hmm.. sure? They have different threat profile. Don't think it is more secure.
With email, you can lock that down with robust 2FA (Google Authenticator/Authy/etc) and crooks have no straightforward way of defeating that.
This is how it plays out year after year and why SIM-swap gangs are so prevalent.
When it comes to good UX it’s important to clarify whose goals it’s best for: compromise security for convenience and adoption of an app?
Or setting up the user to succeed more.
SMS is a lazy form of 2Fa. it reminds one of the descriptions of sms being an open postcard.
Theatre and pageantry have limited value where it sets users up for much worse
I live in a part of the world where, on occasion, governments decide to regulate such things.
Great! Not everyone has that! I do but if I could only implement one type of 2FA I'd probably still pick SMS.
Smart phones are obviously phones and have biometrics. What you're left with is comparing the number of people with non-smart phones (~31 million in the U.S.) to the number of people without smartphones but who have biometric tablets, Windows Hello-enabled computers, PIV cards, etc.
In my social circle, the people who don't have smart phones are:
- People with disabilities that make reading from a small screen or texting a lot impractical.
- People who work in harsh environments who want something more rugged than a device made out of glass.
- People wary of the distraction of carrying around an entertainment device.
All of these people except one also have an iPad (especially the first group, as the larger screens help a lot). The one who doesn't does have a Dell XPS 13.
I would also wager the number of people with dumb phones are close (but not as close) to those having computers without any biometric capabilities (and if they have them, they’re not set up).
I switched this off by choosing the wrong answer to some vague prompt and could never figure out how to re-enable it. Assuming it's like the many iOS settings that can be reverted only by resetting the phone to factory defaults.
BTW, the setting to enable or disable this seems to be under Settings->Passwords->Password Options->AutoFill Passwords and Passkeys. Turning it off and on may also work (as these things tend to behave across devices and operating systems).
Why don't we just issue everyone PIV smart cards?
Particle Image Velocimetry?
Penis in Vagina?
Pentium 4?
Edit: Hah! Personal Identity Verification!
It's not something where a private entity can sell a solution, you need a more solid root of trust for verifying actual identities, like many other countries do, but that's not going to happen in USA any time soon.
My in-laws lived in an area with poor cell reception too. Whenever I'd go there, I couldn't use SMS either.
Both of those places had good Internet service. Any time SMS was required, my UX was terrible. Hooray for anyone who supported TOTP, email, or any other form of 2FA.
I work for an identity provider and we have a number of folks who want us to support this, almost always from a UX perspective.
I think that there also needs to be some onus on the phone providers, as suggested above. With the continued push to have the phone number as a global identifier (offline and online), we need our telco providers to require more to change phone numbers.
No, we need to push back on this user-hostile trend, not stick on yet more band-aids.
Phone numbers are country-specific, impossible to own in any meaningful way for private individuals (unlike e.g. domain names), and add an unnecessary point of failure.
Edit: also, do both pay in this case? The telcom and the service?
Edit: I am swapping users with you, sorry for the confusing reply. I'm thinking telcom employee, you user of the app that got swapped (I think, apologies if I am wrong)
The reality is TOTP despite any issues, is far more secure and available than SMS, security for obvious reasons but also availability, you can have your TOTP token accessible everywhere (say in your password manager) but if you can’t receive an SMS because you lost your phone or maybe traveling, then you are in a tough position, maybe even locked out completely. I personally even back up the TOTP tokens so I can reuse them without being tied to specific platform/app (I am looking at you Authy!)
The US government should step up it's game.
An individual's identity financial transactions should NOT be determined by holding an account at one of 4 mega-corporations.
We should work towards something in this direction: https://e-estonia.com/solutions/e-identity/id-card/
This is analogous to the argument that government shouldn't be involved in "the free market", when the market is actually defined by the laws that regulate it.
Let's just call this the "Texas Delusion"...
Governments can be changed by democratic processes, corporate decision making is completely inaccessible to the public.
Do people really think life would be better if goggle just ran everything?
Also, another valid point is that often times it’s hard to tell what’s a legitimate SNS message and what’s phishing. Their phone numbers are always gibberish and sometimes change between requests.
Oh, yeah, fantastic UX.
I've had my phone and credit cards stolen while traveling abroad (such a hard-to-imagine scenario, innit?), and was consequently locked out of all important services.
Very good UX: being left without a phone and access to bank account and email and most messengers at the same time (thankfully, Skype isn't one of them).
Double props to CitiBank for requiring SMS authentication to change the phone number on the account.
But it caught on because asking people to install an app is a massive ask. Not to mention, people never save those recovery codes.
Sure, you can use Authy and back up your codes but that’s pretty much squarely in the “for technical people” camp.
So at the end of the day, SMS is the only real solution for your average normal person. Let’s get cellular carriers to make SIM swapping harder.
I did this to get my Etrade account TOTP from Symantec into Authy.
New Google Auth takes a second or 5 to show accounts. I use old apk because that one shows accounts in a millisecond.
My TOTP app password is one of the few that don't go into the password manager. Might as well make 'em compromise each separately.
So say a site accidentally logs auth attempts, and someone finds the log. Sure, they know your username + password now, but they don't know a good current TOTP value. And TOTP values are supposed to be one-time-use, so even if they catch it quick it'll be invalid very fast.
Its better than not having TOTP, but not quite as secure as it could be. Theoretically its still something you know and something you have in that its something you "know", the static password, and something you "have", the rolling TOTP generator.
On a mobile device you might be a bit limited in how "distant" you can keep the two, since the vendor is typically almighty in that scenario. But in general, you have options and you might as well avoid keeping both eggs in the same basket.
But, there are still other attacks that this setup protects against.
Two-factor isn't "two device", two factor is two factors of authentication, where factors are generally:
* something you know (password) * something you have (key handshake, totp generator) * something you are (biometrics)
Storing your TOTP secrets next to your hard passwords is putting eggs in the same basket, I agree. But I'd prefer someone do this than just forego adding TOTP or multi-factor entirely.
And in the end, even if you used two different apps on your phone you're still putting all your eggs in the same basket, which is a trade off tons of people are going to do. Even a lot of very security-conscious users will end up with some TOTP app and a separate password manager, chances are both apps will be installed on the same device. If that device gets thoroughly compromised there's potential for both apps to be attacked and compromised.
If your OS vendor shipping malicious code is a realistic threat to you, or at least attackers being able to impersonate your OS vendor, you're probably going to end up getting compromised even if you split it out into two apps. You'd probably just want to avoid TOTP entirely and move to physical hardware cryptographic tokens.
That's the two factors right there.
I've got the Google apps in a sandbox, so I think if they pushed such a thing they could only spy on my logins with them.
Not that I have supreme faith in GrapheneOS to keep google in its box on a device that google made, but I do hope that it represents enough friction that I get excluded as an outlier from whatever abuses occur.
SMS are fortunately both expensive enough there to make them uneconomical for banks to use them as an OTP factor, and have been found too insecure for payment authentication by themselves, requiring a second factor.
This has practically lead to banks offering something more secure and/or ergonomic, e.g. bank-specific authenticator apps (which often work without internet, and always work without cell signal, e.g. when traveling internationally), hardware authenticators, WebAuthN etc.
> Let’s get cellular carriers to make SIM swapping harder.
No, let's get financial companies to step up their game and offer something not liable to both security breaches and locking out users (when traveling, losing access to their number etc.)
My bank even made it a paid service, which I fully support – SMS is extremely overpriced.
Companies embracing password login should be blamed for sticky note thefts.
Companies embracing email 2FA should be blamed for email account theft.
I dont know if this holds up hey. We see this time and again. An entity that does not break the law, makes itself available to the law, and its customers get hit by a criminal entity that does not follow the law. Because we cant snap our fingers and demand the government make thieving criminals double or triple illegal, people reach for a largely innocent party and want to make their lives worse.
Take a deep deep breath and let it go. Theres no unharmful level of punishing the innocent on behalf of the guilty.
This is going to sound wild and crazy but the people swapping the sim should be blamed for the sim swapping attack. What? Blame the criminal? I know its a bold stance but its correct.
You cant control a sim swap attack.
The idea of "blame" (with some handwaving) carries weight in court and sways juries. And companies are getting sued for big sums over negligence regarding SIM-swaps, like here https://www.techmeme.com/190723/p15#a190723p15
The difference between SMS 2FA and the examples you mentioned is that the former is literally impossible to use securely because there is (AFAICT) no (American) consumer mobile provider that implements proper safeguards against unauthorized SIM swaps and similar. Any company implementing SMS 2FA ought to know this, and any company knowingly implementing a deeply flawed 2FA system and selling it to consumers as "more secure" ought to be held liable when it fails. And the sooner SMS 2FA dies, the sooner the same old websites that implement SMS 2FA and nothing else will be forced to implement something that's actually secure.
The persevere practice has been established as 'strong login'.
That said number portability is a really deep well. And theres utility in keeping it somewhat liquid for the many many many people it benefits rather than making it terrible for everyone to prevent a number of attacks.
The following are very similar but separate goals:
1. proof of account ownership (person attempting action has ownership of account)
2. limiting accounts created by non-legitimate users
SMS is a very effective for (2) because few people are going to have access to 100 different phone numbers. Having a cell phone number also typically involves a personal process that requires things like your address, passport, SSN, etc. There are hoops to jump through for this. Companies rely on SMS because they can outsource the KYC process to cell phone companies. They are not doing this to have the most optimal or secure solution for proof of account ownership.
People who continue to complain about this clearly has never had to make this type of auth decision for a company involved in regulated or financial services.
They can always reset the password on their end, given proof of identity (if the account matters).
Indeed, caring in any way about users of your product or service is merely a liability and a cost center.
Then, I guess, the account on that German home automation online forum was maybe not that important, after all.
Let's demand more of tech companies who have the means to do proper security , instead of bling user mistakes.
I have an apartment, a vacation home, a chicken coop, a shed with old tools, a car, a bank deposit box.
Do all of those things absolutely require a Post-Blockchain-Ready™ SuperDuperLock 3000© with the patented Forensic Upgrade Crypto Key™ technology?
Not really. Some security vs. accessibility/usability trade-offs need to be made.
Somebody stealing the contents of my bank deposit box? Okay, that would suck.
Somebody breaking into the shed and stealing that old broken Toyota diff lock actuator I *swear* I'm going to fix at some point and maybe a shovel? Please.
This is why I think there might be a security floor for critical applications, but it should be the user's choice if they really want full 2FA+ with smartphones, biometry, and social security number verification for their random account on once-a-month-visited social network for cats.
By the same logic, you could justify companies tracking their users and selling their personal information: It makes money, and making money is an important part of running a business!
There's a plethora of sms verification providers where you can pay a trivial amount (eg. 50 cents) per verification, and have tens/hundreds of phone numbers available. This isn't stopping anyone who's mildly determined.
But that's the point: If you're really determined, nothing's gonna stop you.
How much on the freedom vs. restriction scale do you want to get pushed to the right for "security" before it's too much? Or is it okay, because it's not inconvenient to you?
Like sure, if I could, I'd make SMS disappear, but really, I'd settle for just punishing those companies so lazy they can't roll out any non-SMS support.
SMS as a primary (or frankly even as a second factor) is fraught. But as comments in this thread call out, they can be incredibly smooth UX for end users on mobile devices.
And in fact, for some user bases, far and away more ubiquitous than emails. There are many populations that just don't have email to serve as a primary factor, but do have phone numbers.
So it's a nuanced topic. Everyone, both users and developers, need to have eyes wide open to the danger and protect against it.
And let's not forget the telecoms, they need to recognize that the phone number serves as a primary login factor and treat it more carefully. That might mean in person or stronger identification requirements on changes.
If we know that some used car dealers rip people off, is the fix to stop buying used cars?
Then how do we fix the problem that carriers do not protect our phone numbers from being ported?
We sue them. In most if not all states it is relatively easy to file a small claims case. For some reason most people do not consider this. Maybe someone could provide an example filing. Courts should and must provide relief to common citizens when they are aggrieved.
If this is indeed a common problem it should be documented and fixed.
Yes, this is a known problem and, no, shrugging off the issue to the lawyers is not appropriate. Candidly it's downright irresponsible if not criminal.
Good luck getting those SMS codes. And good luck getting the US carrier to not shut off your plan if you travel for longer than a few months.
I never had problems with getting SMS around the world with roaming. It just works.
(I've had that problem domestically, due to having laptop internet with no wifi password, though.)
On my desktop I can do username, password and YubiKey.
But iOS is username, password and text, or Face ID and text.
Disabling text means disabling disabling 2FA.
Ridiculous.
Multiple banks I use still use SMS as primary 2FA. Kind of sad.
SMS based authentication is explicitly insecure and not allowed.
Tech companies saw cell phone companies had a juicy piece of PII they wanted and SMS was kind of easy to use and common so they did what tech companies do best: They dumped the hard part onto to some one else, then accused them of being out of touch and archaic when they failed to carry the tech companies water for them.
Its completely understandable that the average person THINKS that sms is secure, everyone depends on their phones, uses it for very personal, private and sensitive business calls. even without tech companies using it for auth it would be exploited, just not as much. Unfortunately it would just take an incredible amount of cooperation, expense and growing pains to properly secure the telecom network. They are extremely interconnected legacy systems that are designed with the assumption there is no security besides trust. that being said they could improve things a whole lot more if they were able to verify their customers better on support calls or at least had higher security options you could enroll in. So they didnt put people who cared about security with the ones who cant even keep track of their own account numbers.
Personally without governments coming together to implement a digital "secure" citizen identification system (also very scary) probably the best we can hope for and i think google now allows is after its verified by phone remove it as a authentication and recovery option and setup multiple hardware security keys/passkeys. ya people will still be idiots and use sms even when there are better options but at least some of us can be secure.
Your phone number is your identity. You can receive or send money only through your phone if the SIM is installed and validated by sending an SMS.
Getting a replacement SIM card requires physical verification using Aadhar (Identity service) with One Time Password validation (Email/SMS). Once the new SIM is active, you will not receive any SMS for the first 24 hours after getting a replacement SIM card. This is to reduce the attack surface of SIM Swap attacks.
How do they get away with this in practice? Can't the carrier phone the number for the SIM or txt to attempt to confirm the owner? Or send you an email or postal letter with a code? Or make you go to the store to show ID?
And if you claim to have no access to the above, send a txt/email/letter alert that you have 5 days to reply to before the switch happens?
Do any carriers advertise themselves as having strong security against SIM-swap attacks as a unique selling point?
I don’t know if it’s government law or phone company laziness getting in the way of SIM security, but giving up on SIM security seems nonsensical and silly. Fix SIM porting security.
That's what the providers around me do, but I think it's because one of them got sued a while back and we only have about 3 providers pretending to be 10 different companies (aka fake competition).
But it's primarily a US problem, and they have a lot of ID problems, like using their SSN as "passwords", and other stuff that would be impossible anywhere else (like illegal immigrants getting jobs at large companies and enrolling their kids in schools without anyone verifying who they are).
Step 2: Sob story about how you lost your cell phone.
Step 3: Fake ID / Social engineering.
The five day wait would work well, though it doesn't protect against "I stole the phone and I yanked the SIM or looked at the push notification" attacks.
1. A phone number is a useful piece of information to have on a customer (to sell to someone or whatever).
2. Some (most?) people are too dumb to manage passwords/TOTP and shouldn't be allowed to use a computer. As a result, everyone suffers and is forced to use broken SMS 2FA that can be SIM-swapped.
3. Companies want to stop bots and use phone numbers for that, even if it's a non-issue for bot operators in practice. A little inconvenience, sure, but it doesn't change the bigger picture in any way.
But if you've bothered to have somewhat secure email it sure would be nice to use that instead, and not worry about the 50,000 retail and support staff at telcos who can grab your sms account based on a convincing phone call.
So, please, I beg of you login developers, offer email wherever you use sms now.
But it won’t happen, that phone number is NEEDED to be tied to your identity for a lot of reasons, that’s why banks (where most people have their real identity) are still requiring a phone number.
Services that do SMS delivery of OTP may want to consider delivery over Signal or WhatsApp when available as they add this additional security.
I've also thought about building an OAuth provider (like sign-in with Google) that does Signal-like phone number verification and lock PINs. This reduced some spam concerns, as it's harder to create burner phone numbers than email addresses. A centralized OAuth service would make it easier than having every web app need their own SMS phone verification integration.
Adding an Authenticator app much better.
I don't want to use Google Auth because I have absolutely no trust is this company and how unreliable they are with their products.
I currently use Authy but it's free, offered by a company (Twilio) and I can't really see what their endgame is here. So they could drop the service one morning because it's not useful for their main business anymore. They already announced dropping their desktop apps.
Say in another way : is there a security company somewhere selling a 2FA app and in which it's easier to put trust?
Sure Bitwarden can provide TOTP, but then I still need to put MFA on my Bitwarden account itself.
only because we allow telco rent-seeking on phone numbers.
I really don't understand how phone numbers became so accepted as an identity confirmation.
What if phone companies simply responded to requests to port numbers by calling and texting the phone number and requesting permission? If permission is denied, have the police check on both sides if the argument on who should have that phone number.
Additionally, whilst people rave about 2FA apps, not many people talk about an approach to recovering your 2FA app account if you lose your device or anything else.
Doesn't have to name applications, but explain the process and common pitfalls people find themselves in when switching to app based 2FA and how to prevent them.
The position of the post is just rigid absolutism that has no chance of surviving the real world, and it's not at all clear that the author actually has any expertise in the subject.
It should be completely obvious that password + SMS 2FA is better than just a password. And while the industry has been trying hard to get people to move away from SMS 2FA (yes, the industry would actually like that, despite the author's conspiracy theories), it is slow going. TOTP has horrible ergonomics and doesn't permit passing side-channel information about what exactly is being authorized. Emails get caught in spam filters. Push-notification style app authentication is secure, but a lot of people will refuse to install your app unless you're like their bank.
Yes, SMS isn't the best form of 2FA for a bunch of reasons. Sim-swaps honestly aren't one of those reasons. But they are the form that you can actually get people to use, and succeed in using.
Ah, but what about single-factor SMS, you say (unlike the author, who doesn't seem to understand the difference). Again, consider the alternatives. If you don't allow for account recovery over SMS, what is your account recovery story? Human customer service will just be socially engineered as easily as the mobile operator was. TOTP seeds, recovery codes, etc can be irrecoverably lost. Phones with authentication apps can be stolen and fail to be bootrapped again. Email accounts or IDP accounts can be lost to hijackers, and are also frequently lost when people change jobs, graduate, etc. Security questions can be stolen and brute-forced.
SMS has a unique property that makes it invaluable as a recovery factor: it's a globally accessible communications channel that can be bootstrapped from just your real-world identity even if lost.
That said, allowing SMS for account recovery does carry some security risks. They can be managed or mitigated by e.g. require a cooling down period, during which the account owner is notified about the recovery attempt and can cancel it. But like everything in this space, those mitigations are also tradeoffs. Which tradeoffs are the right ones depends a lot on what the account is for, there's no one-size fits all.
My email is more secure than my phone. This is shown to be evident on a monthly or bimonthly basis, despite insistence from sms proponents that it's the only feasible oh and also secure way. Bollocks.
Every single time, it basically boils down to the truth - SMS auth is circumvental, recoverable, whatever you want to call it. And there's ample evidence of that being used for account takeovers.
I honestly don't understand how this remains a discussion.
If the author's point had been that there should be a non-SMS option, I would not have commented. But that wasn't their point. They thought it should be removed as an option from everyone. It's just an amateurish idea, completely ignoring the real world and the tradeoffs.
Allowing sim swap without any sort of verification is the issue. You cannot just sim swap in countries outside of America.
Also don’t keep money in your wallet because badguys can pickpocket you.
Also don’t use computers because badguys can steal your passwords.
Turns out the problem is Carriers are dogshit and don’t protect their customers.
Now that said: in the EU (well in France at least), the biggest operators are teaming up and coming up with an interesting system called "SIM Verify" which is specifically crafted to make the life of SIM-swappers sad [1].
Basically companies relying on SMS can verify if a SIM card has been recently swapped and then act accordingly (like, for example, not allowing a password reset by SMS 30 minutes after a card has been SIM swapped).
I'm not saying it's a panacea, but it's a start (and it's all compliant with the EU's GDPR).
That is pointless in the days of eSIM, and even before that it would result in a lot of trouble as a lot of countries don't require people to register a new residence at some government entity that can act as a source of truth.