Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it's true that SMS-based authentication has its flaws, but it's far from useless/harmful in many contexts. The same strawman arguments used here would also find TOTP "wholly ineffective" which is an absurd conclusion.

A main goal of security engineering is to increase the difficulty level for attackers. SMS authentication has demonstrated its ability to do this in a highly accessible, albeit imperfect, manner. I feel that the author severely underestimates the practical difficulties of widely deploying "Unique Passwords and U2F".

I strongly disagree with the conclusion that "SMS-2FA is not only worthless, but harmful" and highly recommend consulting a security professional before entertaining any of the arguments or following any of the suggestions in this article. I don't like leaving negative comments, but this is at best borderline misinformation that has the potential to create severe consequences.

Some more context, if you want to consider a more balanced perspective: https://doublepulsar.com/infosecs-fantastic-fear-of-everythi...



Regarding the "SMS-2FA is not only worthless, but harmful" claim, it's true, but only in the sense that widespread "lazy" SMS 2FA deployments stifle U2F, which, I believe, should just be the standard across the board[1]. Of course SMS does help, just not as much or in as many attack scenarios (and is more of a UX pain too).

[1] The common HN objection which you alluded to is "but it's so hard!" It's really not. Passwords are hard! If only I could have back all the hours I've spent trying to help my grandparents remember their passwords. I have a U2F token plugged into the side of laptop and nothing could be easier than tapping it to get in. Implementation might be hard, but come on, that's our job.


I would argues SMS is worse than "nothing at all", as it moves the responsibility [unwillingly|unknowingly] to the person's carrier, who likely [demonstratively] are not hardened against attack.


Tavis Ormandy is definitely a security professional, he works for Project Zero.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: