It's time to stop using SMS (2021)
lucky225.medium.com
lucky225.medium.com
SMS is not perfect for security. But SMS is better security than no 2FA at all, and for many (most?) situations, more-secure alternatives aren't viable. The deprecation of Authy or loss of keys has left me permanently locked out of a few accounts. YubiKey and similar aren't ubiquitous enough or usable enough for many users. I've experienced these problems personally and I'm likely in the most technical 1% of users you're likely to encounter. SMS is ubiquitous and users understand it, and is secure enough for many situations.
If you're running a service that requires a high level of security, fine, force users to use TOTP/HOTP or something, but be aware you're going to be excluding some users and adding to your support costs by doing that.
A password, with email reset is better. My email has two factors of authentication, rather than whatever my phone provider requires as proof.
Sure, but my answer to that is simply, don't trust users' SMS more than their password. You should require two factors of authentication to change settings on any authentication factor (i.e. SMS and email to change password, password and email to change SMS).
Notably, email is arguably less secure than SMS.
(I can't read much more than that, Medium won't let me)
LifeHack: Dont setup a MANGA account with a phone number. Leave phone# for banking and other important logins.
Maybe for some users, but to many like me, this is an annoying assumption for a service provider to make. If I'm forced into adding an insecure method like SMS, I feel that it needlessly weakens my overall security posture. With effort and diligence, it's possible to manage a single strong password securely, but there is absolutely nothing I can do to use SMS securely, so the degree of security I can aim for is limited.
I think the right approach should be to allow the user to opt into such insecure methods, but to never force them to lower accept a lower standard.
The problem is that you can't force users to use a decently strong unique password. You can force them to set up SMS 2FA (with very minor exceptions of people without SMS access). Moving the base bar from credential stuffing to SIM swapping is a huge upgrade for big services.
unique is the key word. you can certainly force users to use a decently strong password, but not keep them from using the same password at every other website.
The cyber criminals that want to log in to my Microsoft account just don't live anywhere near me and don't have fake companies with SS7 access.
In Europe I have never heard any stories about SIM swaps, so I do not believe that they have high chances of success, like it is said to happen in USA.
Therefore, at least here I find SMS as a 2FA more convenient than the alternatives and I believe that it is secure enough for most uses.
I've been under the impression a lot of scary articles about it are talking about single-factor recovery methods that use SMS, such as password reset systems.
I also think it's weird how e-mail never seems to be counted as a form of 2FA. If everyone used e-mail as 2FA, then I'd only need to secure my e-mail account.
If my passwords are saved locally in my computer, isn't the computer "something I have"? Holding a phone number in a complex system of telephony is the most weird "something you have" you could come up with.
Hmmm... is THIS the vectors people are considering when they make these things? I mean, it makes sense, but it does put it a whole different perspective.
Am I correct to think that these aren't real problems if you use passphrases instead of some cliched password?
Because you can steal my phone and get through the lock screen to access all my stuff with the passkey, but you can't get my master password out of brain lest you put a probe in it.
1. https://blog.google/technology/safety-security/the-beginning...
Now they have potential access to all accounts where you use 2FA.
For example, to break into John's account at bank dot com you need to know:
1. John's username. 2. John's password. 3. The code the bank sends to John's SMS.
I guess for a lot of extremely important things the username is public information, so that one is easy to get, but you still need the password besides the SMS.
Where are these bad actors getting the users' passwords from?
It seems you already need to have a leaked password for this SMS attack to mean anything, which I assume isn't something that happens very often. From how often I heard about SMS 2FA being bad, it sounds like it's worse at locking your account than 1FA, and that's what doesn't make sense to me.
It’s time to stop using SMS for security - https://news.ycombinator.com/item?id=26469738 - March 2021 (147 comments)
I can use a temporary email for a quick test, or even create a dedicated email for your service that includes two-factor authentication (2FA) for extra security. I might opt for a privacy service like DuckDuckGo or Apple's "Hide My Email."
A phone number, which requires being attached to a passport/ID? I'd rather stop using your service than trust you with that data.
By the way, don't use Twilio. You can get a phone number from someone like BulkVS or Anveo Direct for literally $0.06/month.
Walked into an Oxxo. Bought a sim card for like $3, Ticketmaster happily let me use it. Good job, guys.
Idk, I get why it's the way it is but it's asinine and annoying as hell.
Why don't more apps do that?
By contrast I feel like SMS 2FA increasingly is not an option, or at least not the default.
Almost no sites I interact with outside of big tech offer TOTP or FIDO2, which is a real shame.
With email, if an attacker gains access to my email account she can remotely de-auth my mobile device's email client, reset my password for service X, and sign in to service X without my knowledge (assuming I don't notice my email client has stopped working).
With SMS, if they gain access to my email account, I at least get the notice of the attempted login via SMS and can take appropriate action.
I prefer it anyway since I have multiple accounts and they’re not all gmail.
Reliability. It's extremely hard to accidentally break a SIM card. If you drop or drown your phone it may easily become inoperable, but the SIM will be still OK and ready to work in other device.
Availability. If you somehow destroy your SIM it is reasonably easy to get a replacement. Properely and securely backing up an app-based authenticator is difficult. Enrolling multiple authenticators is cumbersome and sometimes not possible at all. Migrating to new device is as easy as it gets.
Attack discovery. If you are being sim-swapped, you will notice immediately as your phone stops working. If someone is eavesdroppoing your SMS OTP you will notice as you will receive unsolicited authentication attempts.
Attack scope. The attack must be targeted as it is much more costly to do it in larger scale.
Attack mitigation. You can take back your stolen SIM as opposed to leaked keys.
I'm not saying SMS is best solution, but it is good enough in many aspects. Other solutions are best in one aspect and much worse in others. SMS strikes the right balance IMO and can be rasonably secure when used as second factor. (Not first and only!)