TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Can We Stop Pretending SMS Is Secure Now?

221 点作者 parsecs大约 4 年前

16 条评论

switch007大约 4 年前
Can we stop pretending that the faux concern for the security of our accounts by tech giants was anything other than an excuse to harvest our phone numbers?<p>Twitter for example let&#x27;s you sign up without a number but it then suddenly detects &quot;suspicious activity&quot; and demands your number. Many other sites enforce it or heavily nag you in the name of security.
评论 #26490313 未加载
评论 #26489626 未加载
评论 #26489369 未加载
m_eiman大约 4 年前
Having username+password+sms is strictly safer than having username+password.<p>To require the attacker to know your phone number and do costly and&#x2F;or time consuming things to get access to it means moving from &quot;script kiddie re-using username+password from leaked user databases&quot; to &quot;targeted attacks&quot;.<p>Sure, it&#x27;s not Safe(tm), but it&#x27;s a big step up from just username+password.
评论 #26488955 未加载
评论 #26489218 未加载
评论 #26489698 未加载
评论 #26490965 未加载
评论 #26495761 未加载
评论 #26489483 未加载
pmlnr大约 4 年前
Nobody ever pretended SMS is secure, but it&#x27;s also the only thing that actually arrives on a phone in many rural areas of the world.
评论 #26489242 未加载
评论 #26496263 未加载
评论 #26493595 未加载
评论 #26489303 未加载
llimos大约 4 年前
I&#x27;ve seen a few threads like this in the last few days. From where I&#x27;m standing, it seems to be a US-only issue.<p>Can anyone please confirm that in a country that does not allow porting numbers without a code being sent to said number, and does not allow interceptions of the type described in the article, that using SMS for MFA is, in fact, secure?
评论 #26488777 未加载
评论 #26489057 未加载
评论 #26488603 未加载
评论 #26489290 未加载
评论 #26488788 未加载
bosswipe大约 4 年前
This attack is enabled by VoIP, which is also responsible for callerID spoofing which has led to the tormenting of millions of people daily with phone spam. The gains from VoIP have absolutely not been worth the loss of trust in what was a reliable communication network. I continue to be unimpressed with &quot;deregulation and free markets&quot;, in practice it usually means sharks feasting on confused consumers.
billpg大约 4 年前
I once had to send a fax that included a letter-head to authorize a domain transfer. Because fraudsters can&#x27;t reproduce letter-head, I guess?
评论 #26491255 未加载
afrcnc大约 4 年前
Can we stop submitting Krebs articles and just submit the source instead? Such as this: <a href="https:&#x2F;&#x2F;lucky225.medium.com&#x2F;its-time-to-stop-using-sms-for-anything-203c41361c80" rel="nofollow">https:&#x2F;&#x2F;lucky225.medium.com&#x2F;its-time-to-stop-using-sms-for-a...</a>
评论 #26492600 未加载
评论 #26493288 未加载
payne92大约 4 年前
Security is relative, NOT absolute.<p>Involving SMS in the authentication process raises the bar significantly for script kiddie attacks using password databases. It also forces a larger and more detailed forensic trail for any attack.
评论 #26493678 未加载
dzdt大约 4 年前
How about we recognize that SMS should be secure and make it so?<p>If the FCC would require mobile providers to add crypto features to SMS that prevent spoofing, would it not be possible to do so?
tyingq大约 4 年前
Interesting. I knew about SIM swaps, but this <i>&quot;off-net text enablement&quot;</i> is new to me. I did know about text-enabled VoiP numbers, but assumed you had to own the DID first. Coupled with the notes about reseller programs with blanket authorizations, it does sound like SMS is truly useless for 2FA.
ryanlol大约 4 年前
Just wait until he learns that all you need to intercept an email is a forged LOA!
评论 #26486018 未加载
评论 #26488350 未加载
评论 #26486736 未加载
评论 #26488206 未加载
评论 #26487579 未加载
评论 #26488857 未加载
apexalpha大约 4 年前
Having 2fa with SMS is still better than no 2fa at all.<p>Sure, TOPT would be far better, but reading this article I&#x27;m more concerned with how easy it is to get access to someone&#x27;s SMS&#x2F;VoiceMail than anything else.
评论 #26490924 未加载
评论 #26496412 未加载
hansel_der大约 4 年前
can we stop pretending electronic communication involving of-the-shelf components is secure?<p>i guess the pandemic has left us with little choice but meeting in person is still the only way to have a private conversation and i guess this won&#x27;t change in the near future given the state of society.
评论 #26489421 未加载
gregwebs大约 4 年前
Does using Google Voice for SMS resolve all security concerns?
评论 #26489413 未加载
LordAtlas大约 4 年前
It&#x27;s rather strange that in 2021, a prominent security research like Brian Krebs doesn&#x27;t have a mobile-friendly website.
wealthyyy大约 4 年前
Mr Krebs, Please do your due diligence. The attack vector only works for Landlines, VOIP, Toll-free.<p>Upstream agreements already block Mobile carriers.<p>Further, SMS from Short Codes are blocked by default. You can only receive SMS from long-numbers. Eg Wicker ..
评论 #26489003 未加载
评论 #26493460 未加载
评论 #26488829 未加载
评论 #26488792 未加载