• archchan@lemmy.ml
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    3
    ·
    1 hour ago

    I hate forced 2FA that you can’t disable anyway. I don’t want to waste time waiting for an insecure text, I don’t want to input an unencrypted code you sent to my email, I don’t want to click your damn notification that runs through Play Services, and no I’m not enrolling in passwordless auth. I don’t need to be babied into securing my accounts. Any account I do actively and willingly secure is already using TOTP. Let me put in my username and password, then kindly fuck off.

    • Charlatan@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      34 minutes ago

      Yeah. So you, myself, and some others are the exception to the rule. But, you can’t look at it that way because its a ‘lowest common denominator’ problem. The least secure of us means we are all only as secure. Others need to be hand held.

      It’s definitely time to raise all boats and drop SMS 2fa like a hot rock.

  • Cocodapuf@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    2 hours ago

    Since when was sms ever secure? My understanding is that messages are sent in the clear, meaning your carrier and the recipient’s carrier both have the opportunity to intercept messages.

    I mean that’s the message content, not the authentication, but still, sms is the opposite of secure, always has been.

    • brie@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 hour ago

      Not true. SMS is encrypted in 3G, LTE, 5G. Block cyphers like Kasumi and A/9 are used. SMS is reasonably secure, because it’s hard to infiltrate telecom systems like S7

      • Abnorc@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        40 minutes ago

        It’s hard, but not hard enough from what I’ve been able to gather. We should want something better IMO. I’m surprised that TOTP isn’t more common.

        • brie@programming.dev
          link
          fedilink
          English
          arrow-up
          2
          ·
          29 minutes ago

          S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.

  • Edieto12@lemmy.ca
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 hours ago

    id take email Authentication over sms Authentication if there was only them 2 let me use my 2facter app for the love of god plz i hate how banks use sms its like come on man

    • oldfart@lemm.ee
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      7 hours ago

      They will now push proprietary apps which steal your data, so you decide.

      In a sane world we would move to yubikeys or codes like Google authenticator, but we live in a post sane technological world

    • Routhinator@startrek.website
      link
      fedilink
      English
      arrow-up
      55
      arrow-down
      1
      ·
      13 hours ago

      The problem for me is that most Canadian Banks give you the choice of SMS or their shitty adware filled bank app that relies on Google Play Services and wont implement TOTP so I can use a true MFA app. And Im done with being forced to accept user policies I don’t agree with to do shit, and most of all done with Google Play Services on my device 😑

      • oldfart@lemm.ee
        link
        fedilink
        English
        arrow-up
        9
        ·
        7 hours ago

        My bank prides itself being the first in the country to support yubikeys for 2fa. I was so happy until i learned it’s just for logging in, transactions are still confirmed by SMS or their app. And security experts all say it’s better this way, using a regular 2fa solution would be insecure because you wouldn’t know what you’re confirming.

        There really is no hope.

          • oldfart@lemm.ee
            link
            fedilink
            English
            arrow-up
            4
            ·
            2 hours ago

            I’m not defending that madness, but that device doesn’t show who is the recipient. The argument was that this is protection against phishing sites pretending to be a bank, proxying your connection but sending it to a different recipient.

            Makes one wonder how much the user has to fuck up to end in such a scenario, and of it’s really worth transmitting everyone’s financial data in almost plain text over the air for this

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        9
        ·
        10 hours ago

        This is the main reason I switched to Fidelity here in the US. It’s a brokerage, but it does basic bank things, like checks, debit card, etc, and they support SymantecVIP, which works w/o Google Play Services. TOTP support really isn’t that hard, I don’t understand why banks are so slow in adopting it…

        • ipkpjersi@lemmy.ml
          link
          fedilink
          English
          arrow-up
          6
          ·
          8 hours ago

          The issue is, banks are only going to do what they’re required to do by law. The government is run by dinosaurs who don’t know what computers are, let alone what TOTP is.

          • sugar_in_your_tea@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            8
            ·
            8 hours ago

            No, they’re only going to do what they’re required to do by their insurance. The law is an option, but if insurance costs go way up if they don’t have proper MFA, they’ll get MFA.

          • sugar_in_your_tea@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            10 hours ago

            They’re fantastic. :)

            The only negative stories I’ve heard are from people who really push the boundaries, like people day trading and whatnot. If you’re a regular user looking for a bank alternative, you should be good.

            Just know their branches don’t really have any banking services, so you can’t go there to withdraw or deposit cash, get a cashier’s check, etc. I keep an account w/ a local institution and transfer money as needed for banking services.

        • Routhinator@startrek.website
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 hours ago

          Now you’ve got me wondering about this for Canada. Would be a pita to move mortgage and investments, but there must be a better way than the big banks.

      • HellsBelle@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        12
        ·
        13 hours ago

        Adding to this that my Canadian bank just updated their app and it doesn’t work with my older phone. So my only option is to use online services with SMS/call verification.

        It’s such a joy to know that my bank, who made $40.670 billion last year, takes care of every customer equally.

        • carpelbridgesyndrome@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          8 hours ago

          They support USB hardware tokens… but only for the website. Everything else is SMS which kinda defeats the point.

          Annoyingly, other than Vanguard, they are the only financial institution to support USB FIDO tokens

  • Uriel238 [all pronouns]@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    47
    arrow-down
    3
    ·
    edit-2
    14 hours ago

    Oh it turns out we needed NSA to do its actual fucking job after all rather than holding onto exploits for the surveillance state.

    Now — for the second time — we have an adversarial administration eager to weaponize government departments while Americans are vulnerable. Why? Because America is the good guys and would never abuse its extrajudicial powers (say, by detaining, rendering and torturing Americans with names similar to those of POIs.)

    We could have had twenty-four years of robust communications security developments if NSA didnt sell the public out like Judas.

      • Uriel238 [all pronouns]@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        3
        ·
        5 hours ago

        Extraordinary Rendition is the euphemism from the aughts from which the movie Rendition was titled. It means taking your detainee somewhere else, often across national borders, to a black site, usually to do things there for plausible deniability (e.g. we don’t torture in the United States )

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          4 hours ago

          Looks like I missed that movie, I’ll have to check it out.

          And I don’t think I’ve ever heard the term “rendering” used in that context, I guess we just used other terminology. Thanks!

  • umbrella@lemmy.ml
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    1
    ·
    15 hours ago

    of course it is. forced 2fa BY SMS OF ALL THINGS is one of the stupidest ideas

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      10 hours ago

      Even stupider is supporting hardware keys for MFA, but having SMS fallback which can’t be disabled (looking at you, Vanguard). I’d much rather have email as my second factor than SMS, and I literally abandoned a bank (Ally) for removing email as an alternative to SMS.

    • capital@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      12 hours ago

      I assume businesses only jumped at the chance to enable SMS 2FA to get their greedy little fingers on our phone numbers.

  • rarbg@lemmy.zip
    link
    fedilink
    English
    arrow-up
    58
    ·
    19 hours ago

    Oh man it sure would be nice if the feds had the power to regulate something like this /s

    • da_peda@lemmings.world
      link
      fedilink
      English
      arrow-up
      52
      arrow-down
      3
      ·
      17 hours ago

      They did. That’s the reason for this hack, they wanted Lawful Interception, they got their backdoor. It’s what professionals and privacy advocates said all along, if it exists it will be abused.

      • Encrypt-Keeper@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        edit-2
        11 hours ago

        This isn’t a hack in the way you’re thinking of, nor is it a product of government mandated interception, or a back door. The salt typhoon event you’re referring to is nothing more than the tip of the iceberg of a much bigger problem, which is abuse of the dated SS7 system we’ve known about for decades.

          • capital@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            ·
            12 hours ago

            Thanks for bringing receipts. In stark contrast to my experience on Reddit, Lemmings usually seem allergic to showing their work for some reason.

            • sugar_in_your_tea@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              6
              ·
              10 hours ago

              Yeah, I don’t get it. I go out of my way to provide sources even before being asked.

              What’s really frustrating is when others users criticize me for providing evidence that could be used to counter my claim. I’m not trying to win arguments, I’m trying to show my work so others can correct me if I missed something. I’m here to learn and educate, in that order, yet so many only seem interested in engaging in discussion that jives w/ their existing opinions. That was a problem on Reddit too, but at least someone would chime in w/ sources much of the time.

          • granolabar@kbin.melroy.org
            link
            fedilink
            arrow-up
            2
            ·
            3 hours ago

            The public broohaha surrounding that event makes me think Apple is providing a back door and this psyop was to make people comfortable trusting Apple.

            Just a theory though. But apple is all proprietary so nothing is stopping them from doing whatever they want or what ever FISA order said.

            • Screen_Shatter@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              3 hours ago

              I still don’t trust them, especially when they announced they were scanning images. I don’t really care their reasons for it, that’s intrusive. I can’t trust any closed source tech, no matter what they say.

  • someguy@pleroma.someotherguy.xyz
    link
    fedilink
    arrow-up
    197
    arrow-down
    1
    ·
    1 day ago

    @return2ozma @technology
    10 years ago, the Feds wanted backdoors to all of phones so they could read all of our text messages. Now, the Feds want everyone not to use software that has backdoors so the Chinese cannot read our phones. The Feds don’t want competition.

    • Screen_Shatter@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      10 hours ago

      SMS spoofing and SIM swapping have been around for ages. It was never secure and that’s always been known. The number of companies that rely on it despite sending me a zillion other fucking useless emails is too damn high! Email, or better yet, an authenticator app, are far more secure. Not perfect, but better.

      • shortwavesurfer@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        10 hours ago

        One big reason I’m hesitant to keep my money in banks is because banks think the best form of two-factor authentication is text message based 2FA and I’m like that’s barely any 2FA at all.

        • Screen_Shatter@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          9 hours ago

          My banks are like that too. Of course I can’t speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts.

          • shortwavesurfer@lemmy.zip
            link
            fedilink
            English
            arrow-up
            3
            ·
            9 hours ago

            I keep my money in Monero. That way, it’s me who has to be targeted instead of an institution. And if I fuck up and lose it, it’s my own damn fault.

            • Screen_Shatter@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              9 hours ago

              I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn’t there yet. Maybe someday… But having money distributed is still smart either way, so I have many baskets for my eggs.

  • phoneymouse@lemmy.world
    link
    fedilink
    English
    arrow-up
    27
    ·
    edit-2
    22 hours ago

    Thank god, give me my HMAC hash please.

    Nothing more terrifying than losing your phone number these days because of all the accounts tied to it via 2FA.