It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.
It’s insane to me that maybe every bank I use requires SMS 2FA, but random services I use support apps.
It's inexcusable.
I really agree with it, but that’s probably their rationale.
Yes, a digital OTP generator is more susceptible in theory to theft or duplication than a hardware token.
Yes, the benefits of digital OTP are great compared to password only, more secure than SMS, and trivial to implement.
SMS-OTP, with all its downsides, allows attaching a message of who you're paying how much to the actual code.
Personally I don't put TOTP tokens into my password manager and keep a dedicated app for it, just in case my password manager is pwned.
I'd probably keep a TOTP app if I actually brought my cell with my everywhere but I really don't feel like it; if I'm heading to a cafe to work for a bit I might need to access something and can't be bothered to bring two devices.
Plus, people increasingly access stuff from cell phones, so it's not a guarantee of "something you have" anymore. And no shot we're convincing everyone to start carrying some kind of hardware token.
You have to remember that cybersecurity is driven by what is secure so much as what is compliant, and increasingly so.
And for the vast majority of people, sms is much easier to backup and restore than totp because there is an infrastructure to help them do so.
I registered it about 13 years ago. I didn't transfer it from a landline/cell phone, it was picked from a list of Google Voice numbers available in my area code. I've never had Fi.
Here's an example response (subscriber name redacted):
{
"data": {
"name": "LASTNAME, FIRSTNAME",
"line_provider": "Google/Bandwidth.com (SVR)",
"carrier": "Bandwidth.com",
"line_type": "landline"
}
}I was wondering about that, because I can't get google voice because I have google fi, so clearly it's using the same bank of numbers, but maybe once they are fi, they are ported to T-mobile instead of their own CLEC.
There are a few popular companies that blacklist VoIP numbers, but most don't. Even Chase, which historically blocked Google Voice, started allowing it a couple years ago.
It never ceases to surprise me how much American banks always seem to lag behind with regards to payment tech. My (european) bank started sending hardware TOTP tokens to whoever requested one like a decade ago. They've since switched to phone app MFA.