Great! Not everyone has that! I do but if I could only implement one type of 2FA I'd probably still pick SMS.
Smart phones are obviously phones and have biometrics. What you're left with is comparing the number of people with non-smart phones (~31 million in the U.S.) to the number of people without smartphones but who have biometric tablets, Windows Hello-enabled computers, PIV cards, etc.
In my social circle, the people who don't have smart phones are:
- People with disabilities that make reading from a small screen or texting a lot impractical.
- People who work in harsh environments who want something more rugged than a device made out of glass.
- People wary of the distraction of carrying around an entertainment device.
All of these people except one also have an iPad (especially the first group, as the larger screens help a lot). The one who doesn't does have a Dell XPS 13.
I would also wager the number of people with dumb phones are close (but not as close) to those having computers without any biometric capabilities (and if they have them, they’re not set up).
I switched this off by choosing the wrong answer to some vague prompt and could never figure out how to re-enable it. Assuming it's like the many iOS settings that can be reverted only by resetting the phone to factory defaults.
BTW, the setting to enable or disable this seems to be under Settings->Passwords->Password Options->AutoFill Passwords and Passkeys. Turning it off and on may also work (as these things tend to behave across devices and operating systems).
Why don't we just issue everyone PIV smart cards?
Particle Image Velocimetry?
Penis in Vagina?
Pentium 4?
Edit: Hah! Personal Identity Verification!
I work for an identity provider and we have a number of folks who want us to support this, almost always from a UX perspective.
I think that there also needs to be some onus on the phone providers, as suggested above. With the continued push to have the phone number as a global identifier (offline and online), we need our telco providers to require more to change phone numbers.
No, we need to push back on this user-hostile trend, not stick on yet more band-aids.
Phone numbers are country-specific, impossible to own in any meaningful way for private individuals (unlike e.g. domain names), and add an unnecessary point of failure.
and
> Much of the ire relating to SIM-swap attacks has, understandably, been directed at carriers. Indeed, carriers do a terrible job of securing customers’ phone numbers, and may be liable for that shortcoming. But here’s the thing: carriers’ security has always been bad, it has even been legislated into being bad, and other companies have still chosen to build mission-critical systems on top of that weak link.
and
> Despite offering poor security, SMS offers a nearly frictionless way to sign up new customers (think of Uber's onboarding) and handle password resets, and companies felt they had to match competitors' adoption of this technique.
This last bit was unfortunately overwritten in a Wordpress post update, and I added it back.
Hmm.. sure? They have different threat profile. Don't think it is more secure.
With email, you can lock that down with robust 2FA (Google Authenticator/Authy/etc) and crooks have no straightforward way of defeating that.
This is how it plays out year after year and why SIM-swap gangs are so prevalent.
Edit: also, do both pay in this case? The telcom and the service?
Edit: I am swapping users with you, sorry for the confusing reply. I'm thinking telcom employee, you user of the app that got swapped (I think, apologies if I am wrong)
The reality is TOTP despite any issues, is far more secure and available than SMS, security for obvious reasons but also availability, you can have your TOTP token accessible everywhere (say in your password manager) but if you can’t receive an SMS because you lost your phone or maybe traveling, then you are in a tough position, maybe even locked out completely. I personally even back up the TOTP tokens so I can reuse them without being tied to specific platform/app (I am looking at you Authy!)
When it comes to good UX it’s important to clarify whose goals it’s best for: compromise security for convenience and adoption of an app?
Or setting up the user to succeed more.
SMS is a lazy form of 2Fa. it reminds one of the descriptions of sms being an open postcard.
Theatre and pageantry have limited value where it sets users up for much worse
Also, another valid point is that often times it’s hard to tell what’s a legitimate SNS message and what’s phishing. Their phone numbers are always gibberish and sometimes change between requests.
It's not something where a private entity can sell a solution, you need a more solid root of trust for verifying actual identities, like many other countries do, but that's not going to happen in USA any time soon.
Oh, yeah, fantastic UX.
I've had my phone and credit cards stolen while traveling abroad (such a hard-to-imagine scenario, innit?), and was consequently locked out of all important services.
Very good UX: being left without a phone and access to bank account and email and most messengers at the same time (thankfully, Skype isn't one of them).
Double props to CitiBank for requiring SMS authentication to change the phone number on the account.
My in-laws lived in an area with poor cell reception too. Whenever I'd go there, I couldn't use SMS either.
Both of those places had good Internet service. Any time SMS was required, my UX was terrible. Hooray for anyone who supported TOTP, email, or any other form of 2FA.
I live in a part of the world where, on occasion, governments decide to regulate such things.
The US government should step up it's game.
An individual's identity financial transactions should NOT be determined by holding an account at one of 4 mega-corporations.
We should work towards something in this direction: https://e-estonia.com/solutions/e-identity/id-card/
This is analogous to the argument that government shouldn't be involved in "the free market", when the market is actually defined by the laws that regulate it.
Let's just call this the "Texas Delusion"...
Governments can be changed by democratic processes, corporate decision making is completely inaccessible to the public.
Do people really think life would be better if goggle just ran everything?