CISA: Do not use SMS as a second factor for authentication [pdf]
cisa.gov
cisa.gov
Most people are never going to be targeted by intercepts or even by SIM swaps, and would still be just as vulnerable to phishing if they switched to TOTP. If you want better protection, hardware authenticators and passkeys are the best options.
And there's no incentive for the carriers to care. Sure, they get yelled at by Congress and the FCC every now and again, but since they're all roughly in the same boat there's zero competitive advantage for them to invest the tens of millions of dollars+ it would take to build out their security capabilities. Their lobbying arm, the CTIA, is funded by tens of millions of dollars in short-code messaging fees and they have bought an iron grip on the FCC and relevant Congressional committees that ensures any enforcement effors are only a wrist slap. Consumers also largely don't seem to care.
So until something dramatic happens, you should assume that voice and messaging traffic flowing through the U.S. wireless carriers is completely exposed.
"Do not use SMS as a second factor for authentication." Why? The reason given is that SMS doesn't have end-to-end encryption. Gmail has had end-to-end encryption since December 2022, so I'm thinking that if I'm given a choice between having a verification code texted to me or emailed to me, I should choose the email option.
SMS is just not designed to be used as an authentication mechanism. We have more secure mechanisms now.
nobody cares about mine, but this could be deployed near a residence where someone’s password or website is breached unbeknownst to them yet.
that could be a situation where they got a sysadmin or CEO or public figure and think they can get even more passwords leaks or breaches out of the target.
my email would be a snooze fest as I don’t have a personal account and don’t mix personal with business. but I do have credentials to lots of other peoples stuff.
which, sometimes due to their own decisions, could be reset from my email I guess.
I don’t use SMS for any of it because I have a non USA phone number which nobody supports anyway.
I just wish it were trusted more, as the number of places that'll let me use it for 2FA is decreasing (but thankfully most of the places I've been Grandfathered in are still working with it).
I was today facing an issue with my BANK because they're locking me out of my account. The reason? I travel around the world and sometimes SMSs won't make it. Also, it's extremely easy to exploit. You can steal someone's phone number with just a bit of social engineering (at least in Europe's carriers). Also, you can steal a phone, remove the sim card, and it'll work anywhere (yes, you can password protect SIM cards, but not everybody does it).
Please don't take this too personally, but this attitude, which I see reasonably frequently, is mind-boggling to me.
The answer to "isn't <insert nearly any infosec> obvious?" is - obviously - no. In fact, lamenting aloud how obvious it is is a form of insecurity, because you are discouraging normal humans from asking questions or seeking advice.
Unless of course you are implicitly referring only to tech-savvy people, but the default audience for end-user infosec advice is all humans.
Even better when this gets into an audit checklist in 18-24 months and the security person can say "We will fail our next audit if we don't make this change"
seriously? It's going to take federal regulation to remove phones as "authentication" at this point. Incredibly stupid.
I feel strongly enough about this that I am comfortable calling such irresponsible communication immoral. I'm not saying normal people shouldn't use solutions that have this caveat, but they absolutely need the risk to be made crystal clear to them.
I’m not sure I’d have a good rebuttal for “Why would I use anything the Feds recommend?”