Let's Ban SMS 2FA
lorendb.dev
lorendb.dev
“There are two factors, but the second factor is something a determined actor can get around by SIM swapping.”
But there are still two factors and SMS 2FA handles disaster recovery much better than the listed alternatives for most people.
This argument strikes me as kind of like - “a determined actor can get around a deadbolt pretty easily, so the standard for homes should be a vault door and fines if you leave a hide-a-key rock anywhere near your house.”
Is it low though? I'm not sure my parents could figure out how to use an authenticator app.
I'd rather just have a whole list of allowable factors and the opportunity to configure one or more of them depending on my personal risk tolerance.
An authenticator app just has the codes and the sites. SMS has the codes, all the previous codes, all of your other SMSs. Plus the messages come from a 5 digit phone number that has a similar format to the 6-digit code you're supposed to enter. The whole system is byzantine IMO and the authenticator app has a much simpler flow. But, you know, I recognize that not everyone may experience it the same way.
I'm generally curious if people think there's a simplicity to the SMS approach other than just familiarity with something that's awkward.
The real problem IMO is not that it's hard to use an authenticator app, it's that the authenticator app provides an actual secret. There's less of a backdoor, so customers can lock themselves out. The downside of the backdoor is it's a security risk. The upside is that managing private keys is a nightmare and nobody wants to force their customers to actually manage private keys.
I imagine even if it were easier, you would see low adoption, because “I’ve never been robbed but I have locked myself out, does this mean I can’t call a locksmith anymore?” Would be top of people’s minds.
If you wouldn't advocate banning deadbolt locks just because vault doors are better, why advocate banning SMS 2FA?
I don't know that I'd go so far as saying that a ban is the right thing, but something is needed.
If im giving my phone number and a second factor to verify me, I don’t want it repurposed as a single factor backdoor. Too often companies dont advertise that it’s a backdoor into the account, or the feature gets added after they collect the info.
usually not. The problem with SMS 2fa is that once a company can do it is almost always easy to social engineer them into resetting the password based on only being able to pass the SMS 2fa... which is a big problem because SMS 2fa has no security against a moderately committed attacker.
The only way you can protect yourself is to refuse to give online services a phone number.
In short: offer SMS 2FA, and indeed push users reasonably firmly¹ into adding SMS recovery at the least because for almost all users that’s the right balance of convenience and security, but certainly don’t limit it to SMS, offering better methods like U2F and TOTP.
(Disclosure: I was employed by Fastmail for a few years, but these decisions had been made long before I got there.)
—⁂—
¹ When you set up 2FA, it forces you to add a recovery phone number, except that you can skip that by holding down Ctrl or something, undocumented but support will tell you if you complain about having to do it; or, after creation, you can just remove it again. So yeah, “reasonably firmly”.
Banning SMS 2FA is the wrong approach, because it is better than no 2FA and every cell phone supports it, out of the box.
What should be mandated is (a) giving users choice of a non-SMS 2FA method (probably just pick one for a standard, e.g. TOTP) & (b) allowing users to explicitly disable SMS 2FA on their account.
As a least common denominator, SMS is fair. But there should be an option to do better, securely, if a user wishes.
I dispute that position. Almost universally "SMS 2FA" can be used as single factor "recovery" and it is unambiguously less secure than a single simple well selected password.
Not all accounts need the same level of security or protection. SMS 2FA can be a very reasonable option depending on the accounts. No law can make that kind of a decision in a reasonable way. So the law has to be toothless (if it leaves too much leeway) or it will remove a valid option from people.
The usability and the availability of other 2FA are not on par with SMS. The gap is not trivial as the author makes it sound like. Account recovery problem is a very difficult one to fix cleanly for all types of accounts. SMS is still a useful option.
Sim swap attack is multiple orders of magnitude more difficult than credential stuffing. It's not close to the most important attack vector for majority of people. It certainly is not worth legislating a solution for specifically. There are reasonable practical solutions for people who want protection against SMS as 2fa from sim hijacking - e.g. many cell phone providers support 2fa or pin to protect it from the sim attack in most scenarios. It's a much cheaper solution for the society than banning SMS 2fa.
If you want to advance this argument, explore how customer service would evolve with a different method, or how user experience could be improved with passkeys. It's not a technology problem.
This is news to me. I worked in the wireless industry and our phones were encrypted and this was in the 90's, albeit GSM encryption which is weak by todays standard and also routing over SS7 which is not encrypted but that is a different set of problems. Are we saying that we have gone backwards and phones are no longer encrypted or is this specific to people using LTE-over-wifi and the people at risk are in a coffee shop? That sounds like a LTE-over-wifi problem that needs to be addressed if so. A mitigating control could be a trivial update to cell phone's to prefer LTE over wifi for text messaging or to disable texting over wifi until the protocols have been fixed to properly accommodate shared wifi. LTE over wifi uses a VPN so I am not sure what is going on here. If this is a real issue then lets address that issue. Either way I do not use shared Wifi. I have more of an issue of text messages being routed through Google by default which is extremely problematic in that it brings both SS7 weaknesses and advertising company vulnerabilities.
Perhaps I am the odd one out here and my reply won't apply to anyone else on HN. I know I am not alone however as many in my community share my beliefs and methodologies. I do not use passkeys and will not as my devices are ephemeral. If anything my dependency on cell phones and data-persisting devices will be diminished sooner than later. I tried out smart phones and I hate them. I am going back to a dumb flip phone. Hardware tokens are also problematic as most companies do not want to spend the money on either the hardware or the support costs to maintain them. For desktops I iPXE or sometimes USB boot a default image and then copy down a few config files. Honestly I just don't log into things over my phone and will not. Nothing is that important and almost everyone I do business with I can either walk into their brick-and-mortor business or I can use a desktop PC with a secure password manager at my leisure. I honestly prefer to walk into a business so that all the employees know me and will know if someone is up to no good. All but one bank account is read-only from the internet and I keep very little in that one account and outgoing ACH transfers are blocked.
Relatedly, I have to manually maintain a text file of all of the sites I've used my Yubikeys on so that if I lose one I know where-all I have to rotate to a new one.
A friend's Mom's Facebook account was recently hacked. They didn't have 2FA set. Hacker changed her email address in the Meta account. Meta did not notify her via email of the email address change. She did not use fb for a couple of months and had no idea this had happened. Then she began receiving calls from cousins and relatives saying their account was hacked after receiving a link in a message from her.
I would've advised her to use SMS 2FA. A lot of non-technical folks from an older generation don't even bother with email.
You just lost 30% of your customers.
> It isn’t that hard to fix
You're highly underestimating the immense difficulty of convincing the entire human population to do something that engineers consider trivial.
And even if I assume all the premises are true and roll with it, shouldn't password based logins be "banned" first? And we all know that's infeasible.
Only businesses that trade away their human rights for limited liability by incorporating should be covered by such legislation, if anyone.
Instead of suggesting that we put in place legislation banning it (?!), perhaps the author should come up with an alternative solution that provides improved security with the same or better convenience for end users and the organizations using it.
The current system of having access to a SIM card or knowing your mother’s maiden name is ridiculous.
Let's ban mobile/proprietary devices and related apps, soft-token included. We have smartcards since decades, we have physical OTP tokens, there is no reasons to allow someone else spying on intrinsically insecure platforms for logins.