SMS is cancer to security and I won’t use any system that forces me to accept something so easy to exploit as proof of my consent.
SMS is cancer to security and I won’t use any system that forces me to accept something so easy to exploit as proof of my consent.
I never understood why SMS are preferred to OTPs generated offline using credit cards and a card reader, which were fairly popular.
Actually, EU regulations state SMS should be phased out, but banks largely ignore that. SIM cloning is fairly easy...
They clearly just don't see it as a realistic threat, on top of all the other security measures in place (for me it's a password, and also a memorable word that isn't typed on the keyboard, then SMS OTP). It's not a great defence of SMS but perfect is the enemy of good, and SMS is just about ok.
Most hacking stories I hear about seem to happen through social engineering, where people go to great lengths to authenticate themselves for someone over the phone.
One thing that is starting to take hold is banking apps, which once installed can be used to authenticate payment. Again not perfect but better than SMS, and users are increasingly likely to have them installed because of ease of use.
Most online services aren't so worried about a small number of users being SIM-swapped. They are worried about large numbers of users that reused their password across thousands of sites 5 of which had their database dumped.
SMS 2FA isn't about providing individual users a high level of security. It is about providing a baseline level of security for all users.
Some banks, like ING, already refuse to send OTPs by SMS and effectively require using an app. SMS is also bad from a user perspective as it turns your phone into a single point of failure. Also, if you are roaming abroad, SMS delivery is usually slow and unreliable. Imagine going to another country and being unable to validate a credit card transaction.
And I think the best answer is government issued digital identity and being able to use that to recover your access to the online services (of course up to you if you wish to make this connection).
And it included that annoying scanning a barcode on screen AND confirming € amount.
And the readers had 2 options. Sign and confirm (?). Why they couldn't incorporate this into the barcode?
It was all done because it definitely lowered mistakes and was more secure than card number and CVV to pay online.
I've been able to use Yubikey Authenticator for anything that said it wanted any of the above, and the awesome thing is you can plug the Yubikey into another device, install and open up Yubikey Authenicator on that device and it works just fine and has all of your services stored on the hardware key, making it easy to upgrade phones or plug they key into a desktop and not depend on a phone.
Another reason it's terrible is for business. Lots of businesses have an account that several people will need to access (yes, it's great to have multiple user support, but not all things do, or sometimes you need a 'bot user'). With something that supports real TOTP you can put that secret into 1password (or heck, scan the code into 7 different people's phone authenticator apps). With Authy you have to pick some random person's cell phone to tie that account to, and hope they don't go on vacation.
Or a rotten apple working at the store who is working together with the perpetrator
Once logged in, you need to enter that "second" password in order to get access to the TOTP codes and Authy will notify you of the new device connected.
The victim will be disconnected from the network, but there's no way in hell the first line of carrier support will detect any of this. You'll have to put your faith in the security monitoring of your carrier (the ones letting spoofed numbers in and out of the network, so good luck I guess). There's absolutely nothing you can do about this thread other than hope that your carrier is smart enough and that you're not important enough for a sophisticated fraudster to target.
As for cheaper threads, everyone who tweeted about owning a crypto exchange account with their phone number on display will probably lose their SIM at some point. SIM swapping is easy with a fake ID, and people within phone stores have been caught doing it from the inside.
SMS is insecure and often abused. Don't use it. Maybe also disable 2G on your phone while you're at it.