Slashdot Mirror


NIST Prepares To Ban SMS-Based Two-Factor Authentication (softpedia.com)

An anonymous reader writes: "The U.S. National Institute for Standards and Technology (NIST) has released the latest draft version of the Digital Authentication Guideline that contains language hinting at a future ban of SMS-based Two-Factor Authentication (2FA)," reports Softpedia. The NIST DAG draft argues that SMS-based two-factor authentication is an insecure process because the phone may not always be in possession of the phone number, and because in the case of VoIP connections, SMS messages may be intercepted and not delivered to the phone. The guideline recommends the usage of tokens and software cryptographic authenticators instead. Even biometrics authentication is considered safe, under one condition: "Biometrics SHALL be used with another authentication factor (something you know or something you have)," the guideline's draft reads. The NIST DAG draft reads in part: "If the out of band verification is to be made using a SMS message on a public mobile telephone network, the verifier SHALL verify that the pre-registered telephone number being used is actually associated with a mobile network and not with a VoIP (or other software-based) service. It then sends the SMS message to the pre-registered telephone number. Changing the pre-registered telephone number SHALL NOT be possible without two-factor authentication at the time of the change. OOB using SMS is deprecated, and will no longer be allowed in future releases of this guidance."

150 comments

  1. the phone may not always be in possession phone by Anonymous Coward · · Score: 3, Funny

    recursive function overflow

    1. Re:the phone may not always be in possession phone by Anonymous Coward · · Score: 0

      We can tell that BeauHD is very highly educated.

    2. Re:the phone may not always be in possession phone by gumbi+west · · Score: 1

      Yes, it also appears that biometrics are safe under either of two conditions--that you have another factor. Oddly they didn't specify which one. I would think that the biometrics would be the something you have (e.g. your voice, finger, or eye).

    3. Re:the phone may not always be in possession phone by __aaclcg7560 · · Score: 1

      daemon possession

    4. Re:the phone may not always be in possession phone by FatdogHaiku · · Score: 2

      So... if you printed it out you would get:
      The phone with a phone lives mainly in a tome*...

      *Assumes user has enough paper to print all recursions.

      --
      You have the right to remain sentient. If you give up the right to remain sentient, you will be elected to public office
    5. Re:the phone may not always be in possession phone by Killall+-9+Bash · · Score: 2

      I have been saying this for years. All biometrics (and smart cards, and RFID, etc) can offer is a false sense of security.

      Hackers can't steal your finger print or your eye, but they can steal the digital signature of it.

      --
      "Prediction: within 10 years, Windows will be a Linux distribution." Me, 7-6-2016
    6. Re:the phone may not always be in possession phone by Jason+Levine · · Score: 1

      Hasn't it been shown that you can take a fingerprint left by someone (say, on their phone) and use it to fool a fingerprint scanner? If someone can do this, they are, in essence, stealing your fingerprint. And once someone has that, good luck changing your "password."

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    7. Re:the phone may not always be in possession phone by Anonymous Coward · · Score: 0

      "We can tell that BeauHD is very highly educated."

      I'm not quite sure what BeauHD is being paid for. Certainly the basic Editing skills that go along with being an Editor are lacking. His earlier howler from today, "...whereas other glasses-less 3D displays carry cots in terms of image resolution...", still hasn't been corrected, so whoever his Boss is, isn't paying attention either.

      Captcha: drunkard
      Hmm...

    8. Re:the phone may not always be in possession phone by Blaskowicz · · Score: 1

      Smart cards offer access to cash on my bank account and cell phone identity and have been around doing these very same things since the 90s.
      I am sure it could go possibly very wrong, but so far some people must have done something good security-wise.

    9. Re:the phone may not always be in possession phone by AHuxley · · Score: 1

      Biometrics is just another big lump of code down a network that a brand hopes the consumer's hardware created and that no other party has, can recreate, or become, capture and use.
      Still the same networks, a consumer OS that is wide open, a few extra trusted chips sold to anyone and some data set created by a user of interest.
      A better way is for real world use would be https://en.wikipedia.org/wiki/...
      The change seems to be that the old idea was the that phone would be a text device that gets a message from a cell tower.
      The phone is now the device requesting and using both messages on the same device or the via same network.
      More data via a well understood biometric chip is just another set of data to capture, but for the user something they think is safer.
      Once such data is captured, is been traded or sold, a user is left with few ways to just alter or create their own trusted, unique future access.

      --
      Domestic spying is now "Benign Information Gathering"
    10. Re:the phone may not always be in possession phone by lgw · · Score: 2

      I'm not quite sure what BeauHD is being paid for.

      BeauHD is old and busted - two generations behind now. Clearly he needs to be upgraded first to Beau3D, then to Beau4K if we're to get good editing.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    11. Re:the phone may not always be in possession phone by ShanghaiBill · · Score: 1

      Hasn't it been shown that you can take a fingerprint left by someone (say, on their phone) and use it to fool a fingerprint scanner?

      It has been shown that this works for old, cheap or crappy fingerprint readers. Modern, state-of-the-art scanners can check for a pulse, or use other techniques to detect tampering. Anyway, the whole point of multi-factor is that each individual factor doesn't have to be perfect. Two layers that are each 90% secure are as good as one layer that is 99% secure.

    12. Re:the phone may not always be in possession phone by goose-incarnated · · Score: 4, Informative

      Hasn't it been shown that you can take a fingerprint left by someone (say, on their phone) and use it to fool a fingerprint scanner?

      It has been shown that this works for old, cheap or crappy fingerprint readers. Modern, state-of-the-art scanners can check for a pulse, or use other techniques to detect tampering. Anyway, the whole point of multi-factor is that each individual factor doesn't have to be perfect. Two layers that are each 90% secure are as good as one layer that is 99% secure.

      Biometrics are the worst factor; they reduce the efficacy of the other factors because they can never be changed while there will remain a nonzero number of devices that can be fooled (hence, they reduce the efficacy).

      The "modern state-of-the-art" that you refer to doesn't yet exist, but I'm sure that it will be secure when they install it in the future, in my flying car.

      --
      I'm a minority race. Save your vitriol for white people.
    13. Re:the phone may not always be in possession phone by Anonymous Coward · · Score: 0

      Before "HD" had more common modern connotations, it stood for "Harley Davidson", as in:
      Potatoe, potatoe, potatoe...
        (tee-hee)

    14. Re:the phone may not always be in possession phone by Opportunist · · Score: 1

      Unfortunately it's also pretty hard to change. If your fingerprint gets compromised, you can't simply change it as you would with a password.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    15. Re:the phone may not always be in possession phone by Anonymous Coward · · Score: 0

      I'm not quite sure what BeauHD is being paid for. Certainly the basic Editing skills that go along with being an Editor are lacking.

      This is Slashdot. You do realize that the requirements for being an "editor" here are the complete lack of editing skills? Bonuses are given for how many errors they intentionally or accidentally introduce while trying to cut and paste the article's summary from its (often third-hand) source.

    16. Re:the phone may not always be in possession phone by NigelTheFrog · · Score: 1

      Technically, most people (with the exception of clumsy carpenters) have 9 alternatives when it comes to fingerprints. Just stick to one until someone steals it, then switch. If [(average time it takes for someone to steal your biometric data) x 10] > (your remaining predicted lifespan), then you win!

    17. Re:the phone may not always be in possession phone by Anonymous Coward · · Score: 0

      It has been shown that this works for old, cheap or crappy fingerprint readers.

      All fingerprint readers can be fooled by simple DIY equipment:

      * Gather a good fingerprint from a glass or similiar.
      * To fool a crappy reader, just print it natural size on paper

      Better readers check for proper skin resistance and 3D structure, so:

      * Transfer the fingerprint to circuit board, using any of the DIY circuit board production methods. Conveniently, the height of copper traces matches the 3D structure of ridges on a finger.
      * Create a gelatine finger, press it against that circuit board to transfer the print. Dry it a bit, and it has the right 'skin resistance'.

      Even better fingerprint readers check for body temperature and possibly also pulse. So:

      * Warm the gelatine finger in your hand, to get the right temperature. This is easy to get right - hand temperature vary a lot anyway, readers must allow for that.

      * Pulse can be faked by embedding a piezoelectric buzzer in the gelatine. The simpler approach is to slice off the layer containing the fake fingerprint and wear it on your real finger - which hopefully has a pulse. This way, the temperature will be right too.

      Basically, if you can make a DIY circuit board, then you can make fake finger to fool any reader.

  2. Typo by Anonymous Coward · · Score: 1

    ...because the phone may not always be in possession of the phone...

    Do the editors not even read submissions anymore?

    1. Re:Typo by gweilo8888 · · Score: 4, Funny

      Do the editors not even read submissions anymore?

      You say that like they ever used to.

    2. Re: Typo by TimMD909 · · Score: 1

      Do the submissions not even read submissions anymore? FTFY

    3. Re:Typo by v1 · · Score: 1, Informative

      the editors don't read what the editors don't read.

      --
      I work for the Department of Redundancy Department.
    4. Re:Typo by goose-incarnated · · Score: 1

      ...because the phone may not always be in possession of the phone...

      Do the editors not even read submissions anymore?

      It's not a typo - it's proof by fight-club assertion :-)

      --
      I'm a minority race. Save your vitriol for white people.
    5. Re: Typo by Opportunist · · Score: 1

      Do submissions not even submit submissions anymore...

      Why do I have that odd feeling that our friend with the "app" fetish will be here in a minute?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    6. Re:Typo by Anonymous Coward · · Score: 0

      but who was dog?

  3. I heard you like phones by Edis+Krad · · Score: 4, Funny

    So I put a phone in your phone because the phone may not always be in possession of the phone

    1. Re:I heard you like phones by Anonymous Coward · · Score: 0

      So I put a Marklar in your Mraklar because the Marklar may not always be in possession of the Marklar

    2. Re:I heard you like phones by bosef1 · · Score: 1

      There is no Zuul... only phone.

    3. Re:I heard you like phones by Anonymous Coward · · Score: 0

      You Marklars always think your Marklar jokes about other Marklars are so funny, but that Marklar messed up.

    4. Re:I heard you like phones by uvajed_ekil · · Score: 1

      There is no Zuul... only phone.

      All your phones are belong to Zuul? Uh oh...

      --
      This is a hacked account, for which the owner can not be held responsible.
    5. Re:I heard you like phones by ChunderDownunder · · Score: 1

      Which is why Firefox OS failed; there was no XUL.

    6. Re:I heard you like phones by Anonymous Coward · · Score: 0

      My phone is a sovereign phone and does not need to follow your carrier-based laws.

    7. Re:I heard you like phones by Anonymous Coward · · Score: 0

      I thought all your phone are belong to us?

  4. the phone may not always be in possession of the by turkeydance · · Score: 0

    phone

  5. Better vs. Perfect by 1SQ · · Score: 1

    So we're throwing out the "better" in search for the "perfect?" Until tokens gain the ubiquity of phones (which seems unlikely), doing away with SMS-based two-factor authentication may just force many users back to the password-only era.

    1. Re:Better vs. Perfect by Anonymous Coward · · Score: 0

      A Gov't agency advocating less security? Say it ain't so!

    2. Re:Better vs. Perfect by Alan+Shutko · · Score: 2

      Not many organizations are required to follow NIST security standards. Those that do are in a better situation than most to switch to physical tokens or to software-based tokens of one sort or another. Note that "5.1.3.2. Out of Band Verifiers" does not deprecate sending a notification to a smartphone app that can then authenticate the user and provide a secondary authenticator.

    3. Re:Better vs. Perfect by GeekWithGuns · · Score: 2

      Context here - NIST is setting standards for government security. If you are running a government system or are the vendor selling to the government, this will apply to you. DoD and IRS shouldn't be using SMS 2-factor authentication for users of their systems. DoD is not really the problem here, since 2-factor to them is certificates on smart cards (CAC), but I wouldn't be surprised to see IRS using SMS based 2-factor for some kinds of password recovery.

      SMS based 2-factor for taxpayers accessing the IRS...that could be harder to replace.

      So Google and the rest of us don't have to abandon SMS for 2 factor, but I'm kinda in agreement with NIST - not the best idea due to the ability to intercept the authentication code.

      --
      [End of diatribe. We now return you to your regularly scheduled programming...] - Larry Wall in Configure from the perl
    4. Re:Better vs. Perfect by retchdog · · Score: 1

      Ability? Christ, it's practically a default. I configured my MacBook to handle my SMSes through message.app because it's much more comfortable and ergonomic. A few months later, I get two-factor SMS authentication as part of work. Yeah, not exactly two-factor.

      Using SMS for two-factor authentication is an anachronism, and I wouldn't mind the government stopping people from calling SMS "two-factor authentication", anymore than I mind when it stops people from selling industrial effluent as baby formula. It's just plain old fraud.

      --
      "They were pure niggers." – Noam Chomsky
    5. Re:Better vs. Perfect by Anonymous Coward · · Score: 0

      But industrial effluent's got what babies crave. Nestle is a good company.

    6. Re:Better vs. Perfect by darnkitten · · Score: 1

      I'm in the password-only era, you insensitive clod!

      Seriously. I live in a rural town without cell service. And with a lot of poor and elderly people who either can't afford or can't effectively use smart tech.

      Something these tech wonks never seem to think about.

    7. Re: Better vs. Perfect by Anonymous Coward · · Score: 0

      Still seems like two-factor to me. It's something you know (your password) and something you have (your laptop and/or phone). Some organizations use computer certificates as the second factor to do this very thing.

    8. Re:Better vs. Perfect by jrumney · · Score: 1

      Until tokens gain the ubiquity of phones (which seems unlikely)

      Since tokens can be generated by software on phones, even obscure and obsolete phones, tokens are already more[1] ubiquitous than phones.

      [1] hardware tokens can be taken into secure areas where mobile phones are banned.

    9. Re: Better vs. Perfect by Anonymous Coward · · Score: 0

      Or love on urban areas like Seattle that take hours to deliver an SMS message. I work in a fast growing neighborhood, and cellphones are just hopeless here.

    10. Re:Better vs. Perfect by Anonymous Coward · · Score: 0

      Paypal offers calling the phone# you have on your account (c.f a land line). Computer Lady says a code. You type said code into the (password reset) form.

    11. Re:Better vs. Perfect by Z00L00K · · Score: 1

      I can agree that SMS authentication is not really good now that most phones can be compromised. However the alternative of having biometrics is not good either since fingerprints can be cloned, and so can eye irises. Or you can go full "Demolition Man" on it too.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    12. Re: Better vs. Perfect by Z00L00K · · Score: 1

      And certificates can be cloned, so they aren't really good.

      A security token not connected physically to a computer and protected by a pin code is still the best alternative.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    13. Re:Better vs. Perfect by Z00L00K · · Score: 1

      The only disadvantage with a separate token is that you will have a lot of them. I have two today, one for my bank, one for work.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    14. Re:Better vs. Perfect by Anonymous Coward · · Score: 0

      Worse: to mothers' maiden names and social engineering.

    15. Re:Better vs. Perfect by Chrisq · · Score: 1

      So we're throwing out the "better" in search for the "perfect?" Until tokens gain the ubiquity of phones (which seems unlikely), doing away with SMS-based two-factor authentication may just force many users back to the password-only era.

      But then, what if you are not in possession of your token?

    16. Re: Better vs. Perfect by Anonymous Coward · · Score: 0

      until someone builds a virtual replica of the token.

    17. Re:Better vs. Perfect by Anonymous Coward · · Score: 0

      SMS codes can still be considered 2FA, even if it's not very good. In the absence of something better such as a security token, I'd rather have the SMS code than nothing at all. It does make it a bit harder for an attacker.

    18. Re:Better vs. Perfect by Anonymous Coward · · Score: 1

      Exactly. And not being in possession of your token is probably going to take longer for you to realize and report, than not being in possession of your phone.

    19. Re:Better vs. Perfect by TheRaven64 · · Score: 2

      You don't need Paypal to do this. You can send SMS to most landlines and the message will be read out by a computerised voice.

      --
      I am TheRaven on Soylent News
    20. Re:Better vs. Perfect by bluefoxlucid · · Score: 1

      Tokens are obtainable. They're afraid someone will obtain your phone, and advocate using another non-phone thing someone could obtain instead. It's weird.

    21. Re: Better vs. Perfect by retchdog · · Score: 1

      eh, fair enough. this is the defense the SMS auth providers would use. it's a fairly weak case imho, but yeah, it is not nothing.

      --
      "They were pure niggers." – Noam Chomsky
    22. Re:Better vs. Perfect by Rob+Riggs · · Score: 1

      So we're throwing out the "better" in search for the "perfect?" Until tokens gain the ubiquity of phones (which seems unlikely), doing away with SMS-based two-factor authentication may just force many users back to the password-only era.

      Two words: Google Authenticator.

      There is no excuse for using SMS for 2FA when you have TOTP with a well-documented interoperability standard in RFC 6238.

      --
      the growth in cynicism and rebellion has not been without cause
    23. Re:Better vs. Perfect by pak9rabid · · Score: 1

      See also: FreeOTP

    24. Re:Better vs. Perfect by rjstegbauer · · Score: 1

      If I understand this properly...big IF I guess...

      I use Google's SMS TFA, which is uses when I logon using a new computer and love it. Google also allows me to print out a set of codes that I keep handy in case I don't have my phone.

      Additionally, the second factor could be a call on a preregistered land line. Couldn't it?

  6. Non-sequitor by Todd+Knarr · · Score: 4, Insightful

    The recommendation doesn't make sense. Yes, your phone may not always be in your possession. That would rule out software authenticators too, since they reside on the same phone that may not always be in your possession. Even dedicated hardware tokens may not always be in your possession, they can be lost or stolen just like a phone. So if not being always in your possession is the criteria, then all of the NIST's recommended methods fail to meet it.

    As for VoIP lines, yes they can be intercepted. They do however share one characteristic with cel-phone lines: they don't normally share a path with the network connection being authenticated except possibly at the user's ISP and computer (if the VoIP line terminates on their computer as opposed to their cel phone). That limits the ability of a single attacker to intercept and alter both paths, which is the central facet of what 2FA does.

    Ultimately the only secure 2FA is a dedicated hardware token that requires biometric authentication to function. Anything less than that is insecure, the question being merely whether the insecurity reaches the point of being unacceptable.

    1. Re:Non-sequitor by GeekWithGuns · · Score: 2

      I agree, if your concern is possession of the phone, then soft tokens are almost equal to SMS. The big difference is the ability to intercept the code out on the network (VoIP, Google Voice, etc...).

      One thing that I have seen done with RSA tokens that could be done with software tokens as well as SMS tokens would be appending a PIN to the token. That way even if the token is stolen, the thief would need to know the PIN and where to append it. You don't need a biometric to unlock the token, just a password or PIN to be the 2nd factor.

      --
      [End of diatribe. We now return you to your regularly scheduled programming...] - Larry Wall in Configure from the perl
    2. Re:Non-sequitor by EvilSS · · Score: 1

      There is another problem with SMS 2FA that isn't covered in this document, and is much easier to pull off: It is currently too easy to social engineer phone companies to move service to a new device. This has happened recently to several execs to allow script kiddies to take over social media accounts that are using SMS 2-factor.

      --
      I browse on +1 so AC's need not respond, I won't see it.
    3. Re:Non-sequitor by Nemyst · · Score: 5, Insightful

      The recommendation doesn't make sense. Yes, your phone may not always be in your possession.

      I'd recommend re-reading the actual recommendation: "The NIST DAG draft argues that SMS-based two-factor authentication is an insecure process because the phone may not always be in possession of the phone number". It's not the user having the phone on them, it's the phone having the number associated with it. They're essentially saying that it's too easy to hijack the phone's number (or simply get it when the user changes it) and receive the SMS instead of the legitimate user.

    4. Re: Non-sequitor by Ronin+Developer · · Score: 2

      This, theft or the cloning of the SIM are three possible threat. Another is the display of the SMS on the lock screen which would divulge the token to anyone who has access to the device.

    5. Re:Non-sequitor by Anonymous Coward · · Score: 0

      > user's ISP and computer

      But that's where the attack is *most* likely in the first place. Intercepting in the cloud doesn't work at the domestic level.

    6. Re:Non-sequitor by PrimaryConsult · · Score: 3, Interesting

      RSA has software tokens too. The app prompts for a pin and regardless of what you enter, will generate a token code. The catch is, the resulting token code will simply not work if the wrong pin is entered. No way to brute force that, you'd have to take the software token and submit that to the login form to see if the combination was correct (which after 3 tries will still lock you out). Pretty ingenious, the app doesn't need network access and will still work when you change your PIN.

    7. Re:Non-sequitor by Anonymous Coward · · Score: 0

      You at least have to login to your phone to use an authenticator app.
      With SMS it will show on the phone if you are logged in or not.

        I actually think an authenticator app is insecure compared to a physically separate authenticator token.
      Also I've already lost google auth tokens, since they are not backed up when replacing your phone.

    8. Re:Non-sequitor by Anonymous Coward · · Score: 0

      The recommendation doesn't make sense.

      Actually, it does.

      Yes, your phone may not always be in your possession.

      That is not what it is about, though. Re-read carefully.

      It is not your possession of the phone that is the issue.

      It is the phone's possession of the phone number that is the issue.

      It is easier to subvert the latter than the former. Thus relying on the phone still having the number associated with it is the less secure option and is thus now somewhat frowned upon.

      There are many grey areas in this field, where you cannot pick the perfect option because it simply does not exist. You have to pick among the less bad options. That is what is happening here.

      So, they are actually right and it does make sense.

      I hope that helped.

    9. Re:Non-sequitor by tlhIngan · · Score: 1

      The recommendation doesn't make sense. Yes, your phone may not always be in your possession. That would rule out software authenticators too, since they reside on the same phone that may not always be in your possession. Even dedicated hardware tokens may not always be in your possession, they can be lost or stolen just like a phone. So if not being always in your possession is the criteria, then all of the NIST's recommended methods fail to meet it.

      The summary is poorly worded. It's not YOU in possession of your phone, it's your PHONE in possession of the PHONE NUMBER. The idea is this - if you're going to do SMS as a verification, NIST recommends checking that the phone number you're sending the SMS to is actually the phone you intend to send it to.

      There is another problem with SMS 2FA that isn't covered in this document, and is much easier to pull off: It is currently too easy to social engineer phone companies to move service to a new device. This has happened recently to several execs to allow script kiddies to take over social media accounts that are using SMS 2-factor.

      No, that's what NIST is talking about. Your phone may not be in possession of the phone number.

      Basically what NIST is saying is that phone numbers don't lead to a specific phone. They lead to A phone, but not necessarily the phone you think it goes to. This is especially as modern phone systems allow trivial movement of phone numbers to anything that can provide voice service.

    10. Re:Non-sequitor by Vliegendehuiskat · · Score: 1

      Ultimately the only secure 2FA is a dedicated hardware token that requires biometric authentication to function. Anything less than that is insecure, the question being merely whether the insecurity reaches the point of being unacceptable.

      I would not use a hardware device with biometrics since you can be forced to provide those. I'd rather use a hardware token which requires a PIN to function which only allows you to enter an incorrect number a few times before it wipes the key.

    11. Re:Non-sequitor by bradley13 · · Score: 1

      Ultimately the only secure 2FA is a dedicated hardware token that requires biometric authentication to function

      Only, biometrics can be faked. A couple of years ago, my favorite computer magazine (German) showed how they could lift and reproduce a fingerprint good enough to fool many fingerprint scanners. For that matter, biometrics are stored as digital data, which can be stolen. And once your biometric data has been stolen, you are well-and-truly screwed, because you can't exactly change your fingerprints, retina, or whatever.

      Security is a problem, and there is no perfect solution...

      --
      Enjoy life! This is not a dress rehearsal.
    12. Re:Non-sequitor by Anonymous Coward · · Score: 0

      An obvious improvement (have thought about this many times). Won't work well for grandma and Millenials though.

    13. Re:Non-sequitor by Anonymous Coward · · Score: 1

      There was a cluster of hacks of various YouTube channels recently which coincided with a convention.

      The mechanism was social engineering of various cell phone providers to transfer a phone number to a new SIM card, together with compromise of passwords via some other method, possibly rogue WiFi APs.

    14. Re:Non-sequitor by Anonymous Coward · · Score: 0

      All of the "hacks" recently were simple social engineering. Tell the cell phone companies to get their shit together and stop randomly transferring phone numbers to new SIM cards because Joe Dickhead called the phone support number and said that they were an employee and "would you please put the number on this new SIM card, thanks!"

      You could say the same thing is true with software or hardware tokens when someone calls up an account holder and claims something vaguely technical like "your token is getting out of sync, can you read us the next consecutive codes right as they change so we can resync your token?"

      Punish the people stupid enough to let the issue happen because they're too incompetent to do basic security checks before giving away someones fucking phone number.

    15. Re:Non-sequitor by Anonymous Coward · · Score: 0

      In Germany, there have been many cases where crooks were able to convince the phone company of their victims to send them a replacement or additional SIM card for the victims phone, enabling the crook to receive all SMS.

    16. Re:Non-sequitor by Anonymous Coward · · Score: 2, Insightful

      Too easy for who? I suspect 2FA over SMS would thwart 99% of the account hacks that occur today.

    17. Re:Non-sequitor by Anonymous Coward · · Score: 0

      Yes it makes sense.
      The cops buy STINGRAY canned solutions , and it only takes a little more money to by other features to fool so called experts.
      Snatching or denying money transfers will trigger calls between parties will give them more options and rope in accomplices.
      This will work almost anywhere. except German banks that issue one time pads.
      Tokens are not much better, given RSA was hassled by foreign players once.

    18. Re:Non-sequitor by Anonymous Coward · · Score: 0

      USAA does this for 2FA logins. Your login password is a PIN + number from token.

      That requires a Shared Secret plus the random string from the token, rather than just the token its self.

      As for the phone part, think of it this way. Let's say you have an android phone with the Duo app installed, and you have a password set to get into the OS and maybe to even boot the phone up.

      In theory, someone would need to know the code(s) to boo the phone and then to get into the OS, and from there they could then run the application to do the 2fa.

      Or, someone could just pull the SIM from the phone, stick it into another device they have full control over, and BAM. They now have your cell phone number and can receive the SMS messages to complete the 2fa.

      I'd have to assume this would also mean that the PSK codes send over SMS for 'offline use' would also be deprecated.

    19. Re:Non-sequitor by Nemyst · · Score: 1

      The NIST deals with recommendations for just about everyone at once, so while it may not matter for Joe Q. Public, it's a good thing to keep in mind for government implementations or sensitive academic work and so on.

    20. Re:Non-sequitor by Anonymous Coward · · Score: 0

      I think this is a reaction to the ability to 'clone' a sim card and have a phone in essence intercept what's going on somehow.

    21. Re: Non-sequitor by Anonymous Coward · · Score: 0

      Also:

      SS7 (cellular network) weaknesses
      Mobile malware capturing SMS

  7. If the message is intercepted and not delivered... by mark-t · · Score: 1

    wouldn't the person who is expecting to receive it kind of, you know, notice?

  8. Provide your phone number for extra security? by Tokolosh · · Score: 3, Interesting

    Many websites ask this - Facebook is top of the list. I fail to see the reason. It is just another part of their project to collect data on you.

    Also, security questions are a joke. Where was I born? The whole world knows by now. Why would I provide yet another vector for compromising my account?

    If the site insists, I type garbage, and save a copy in Lastpass.

    Sheesh.

    --
    Prove anything by multiplying Huge Number times Tiny Number
    1. Re: Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      This, if you're using a proper password manager there is no reason the security questions shouldn't be random garbage as well.

      +1 lastpass

    2. Re:Provide your phone number for extra security? by Alan+Shutko · · Score: 4, Interesting

      Having password reset happen with a text to your phone is more secure than the typical security questions that websites and (worse) CSRs ask. The text message is intended to help prevent what happened to Mat Honan, where his google account, twitter, and Apple ID were hacked, and his MacBook and phone erased remotely. This happened because a hacker was able to convince help desk folks he was the legitimate owner of the accounts, using info scraped from different places.

      Cell phone numbers aren't as good as hardware or software-based authenticators for applications that require more security. It's part of a continuum, where the more security is needed, the more of a hassle it can be to get in.

    3. Re:Provide your phone number for extra security? by the_Bionic_lemming · · Score: 1

      It's even worse when you DON'T have SMS. Websites and steam keep spamming you with "upgrading security" and refuse to let you OPT OUT of the harassment.

      --
      _ _ _ Go for the eyes Boo! GO FOR THE EYES!
    4. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      My favorite question was "Who was your childhood hero?", to which I replied "Hitler".

      This was for signing in to a snail mail provider's e-mail service, I otherwise provided real information (this e-mail box to be used for very few services).
      I then receive a real paper letter reminding me that my childhood hero was Hitler (emphasis theirs) and telling me to not reveal it to other people.

    5. Re:Provide your phone number for extra security? by ChunderDownunder · · Score: 1

      One reason I avoid SMS signups - travel.

      I've never done global roaming, picking up a local SIM when I get there. So what happens if my Australian bank detects I've been shopping in Argentina or Portugal and asks to verify I haven't had my details stolen by sending an SMS?

      My previous phone had dual-SIM which might have been an option. Although these Asian manufactured things tend to be 4G on one and 2G on the other, which is no help if, as here in AUS, they intend to discontinue 2G capability.

    6. Re:Provide your phone number for extra security? by PopeRatzo · · Score: 0

      My favorite question was "Who was your childhood hero?", to which I replied "Hitler".

      I bet your password is #MAKEAMeR1CAGREATAGa1N69.

      --
      You are welcome on my lawn.
    7. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      Wow. You really have a hardon for Trump, don't you.

    8. Re:Provide your phone number for extra security? by PopeRatzo · · Score: 0

      You mean BabyPutin? Yeah, I dig him.

      --
      You are welcome on my lawn.
    9. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      You were born in garbage?

    10. Re: Provide your phone number for extra security? by Anonymous Coward · · Score: 1

      Works fine until they ask you for the answer to your security question over the phone. So make sure your random garbage is still pronounceable and not too revealing about your sexual preferences.

    11. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      The problem is, help desk staff is always able to override security mechanisms. Just tell them you lost your phone and they'll be satisfied with your mama's maiden name.

    12. Re:Provide your phone number for extra security? by Anne+Thwacks · · Score: 3, Interesting
      My bank decided I did a suspicious transaction because I was away, and used a UK (my homeland) website to buy something. They sent a text to my UK phone (running software to reply by SMS saying"my phone is out of order, send me an email") . I did not know about this, so they blocked my card.

      I asked if it was possible to advise them to use a different number if I was away. They said NO.

      --
      Sent from my ASR33 using ASCII
    13. Re:Provide your phone number for extra security? by Opportunist · · Score: 1

      Yes, "security questions" are quite an oxymoron, they DEcrease security considerably. Because they are usually made up from things that anyone can find out about you or that some people who know you may know. Your mom's maiden name? Easy to find out. Your first teacher's name? Not that hard either. Your pet's name? Likely to be found on your Facebook page. Your first car? Probably something I'd know if I had known you for long enough.

      So my mom's maiden name is something akin to fRwef12$nu'ka. And don't you DARE disallow me to set that, you xenophobe racist bastard!

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    14. Re:Provide your phone number for extra security? by Opportunist · · Score: 1

      I laughed, but still: Waaaay too easy to guess.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    15. Re:Provide your phone number for extra security? by pla · · Score: 1

      Also, security questions are a joke. Where was I born? The whole world knows by now. Why would I provide yet another vector for compromising my account?

      You realize that you don't need to give a meaningful (nevermind "true") answer to those security questions?

      "Mother's maiden name?" "#10 dual-window envelopes".

    16. Re:Provide your phone number for extra security? by jittles · · Score: 1

      Many websites ask this - Facebook is top of the list. I fail to see the reason. It is just another part of their project to collect data on you.

      Also, security questions are a joke. Where was I born? The whole world knows by now. Why would I provide yet another vector for compromising my account?

      If the site insists, I type garbage, and save a copy in Lastpass.

      Sheesh.

      I always make up the answers to these questions using a system based on the question and the site that helps me remember the answer but prevents someone from just Googling my life store too find out the answer.

    17. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      still 'phone number' can be stolen if not attached to HW as is the case with voip - this means I can access the webside as somebody else, intercept the SMS and have a field day. The authentication where I have for instance let my phone translate some picture into a code and enter this into a web page form is just the same unless the application on the phone is secured with pwd or biometric data in which case they probably need something like iris scan for instance. Nothing makes it secure in an absolute way. They just increase difficulty for the abuser (who more and more is a member of a state run operation).

    18. Re: Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      yet you use lastpass? it's only a matter of time before that honeypot is compromised.

    19. Re: Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      not what a honey pot is, but your point that last pass is a huge target is valid.

    20. Re: Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      This, if you're using a proper password manager there is no reason the security questions shouldn't be random garbage as well.

      +1 lastpass

      -1 lastpass
      +1 keepass

      How are people not afraid of the inevitable infiltration of lastpass? It's a goldmine for hackers and nothing is 100% safe. If it's not hacked online, all that needs to happen is a little social engineering.

      At least keepass can be stored how I want and where I want. It's much less likely that someone is going to specifically target me to get my info. But a user base in the millions of nothing but website credentials? No thanks.

    21. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      Also, security questions are a joke. Where was I born? The whole world knows by now. Why would I provide yet another vector for compromising my account?

      You realize that you don't need to give a meaningful (nevermind "true") answer to those security questions?

      "Mother's maiden name?" "#10 dual-window envelopes".

      The problem then is that you've juts reinvented the password.

      This adds no additional security to a system secured with a password, they just add one more thing you might forget, or an avenue to bypass the systems designed to make the password itself stronger (character minimums, disallowing common words/phrases, etc.)
      It's still asinine that they are even asking those questions.

    22. Re:Provide your phone number for extra security? by pla · · Score: 2

      This adds no additional security to a system secured with a password

      Sure it does - It means you have two passwords, rather than a password and a piece of publicly-available information... Though the GP already gets that, I basically just rephrased his "type garbage, and save a copy" as something a bit more user-friendly. :)

      That said, I otherwise agree with you completely - Though, I also don't really see the problem here. Biometrics would solve some of the usability issues with passwords, but at the cost of introducing entirely new ones.

      Really, I think a lot of this comes down to "how much security is enough"? Sending an SMS for two-factor counts as far, far more than adequate 99% of the time; and that even counts as massive overkill 99% of the time. For virtually all uses, just using something like your favorite porn star's name is good enough.

    23. Re:Provide your phone number for extra security? by Anonymous Coward · · Score: 0

      Many websites ask this - Facebook is top of the list. I fail to see the reason. It is just another part of their project to collect data on you.

      Also, security questions are a joke. Where was I born? The whole world knows by now. Why would I provide yet another vector for compromising my account?

      If the site insists, I type garbage, and save a copy in Lastpass.

      Sheesh.

      ummm - the idea is 'you lie' when you answer those kinds of question, and only you know which false answer you gave.

  9. Re: the phone may not always be in possession phon by Entrope · · Score: 2

    In that authentication paradigm, biometrics is usually called "something you are", while an authentication token/device/badge is "something you have".

  10. Good. Now ban credit cards. by Anonymous Coward · · Score: 0

    TFA should not be about the ability to track you or your money. I'm looking at you Facebook.

    Stupid twats will not give an app id without your cell phone number or your credit card number.

    People without credit cards or cell phones are actually real people too, believe it or not.

    1. Re:Good. Now ban credit cards. by Anonymous Coward · · Score: 0

      Totally agree. Two factor authentication should not be about your financial status.

    2. Re:Good. Now ban credit cards. by PrimaryConsult · · Score: 1

      People without credit cards or cell phones are actually real people too, believe it or not

      Yes but they don't actually matter to to large corporations. Accommodating a few outliers is simply more trouble than it's worth.

    3. Re:Good. Now ban credit cards. by Anonymous Coward · · Score: 0

      Well, if you consider the majority of the worlds population "a few outliers", well then maybe you are correct.

    4. Re:Good. Now ban credit cards. by Anonymous Coward · · Score: 0

      The problem here is these large corporations are pushing US expectations out to become the standard in places that can't support it. Think Latin America. Some places don't even have a landline and people are more traditional with pre-2000 common sense and suspicious of BOGUS requests for DOB, ALT email, town, credit cards [app store used to prevent free app DLs back in 2012].

      Worse, some services that collected security questions drop them and/or demand even more info in unrelated fallbacks. GMail wants "words in one of your recent outgoing emails" despite the reality that most people who need a pw reset never having sent anything out from their Android phone. And they have no clue who configured the pw for them, since there is always a rush to get that one App from the store when their phone is new. Facebook IS that one App.

    5. Re:Good. Now ban credit cards. by Anne+Thwacks · · Score: 1
      Well, if you consider the majority of the worlds population "a few outliers", well then maybe you are corporate America

      FTFY

      --
      Sent from my ASR33 using ASCII
  11. Re: the phone may not always be in possession phon by Anonymous Coward · · Score: 0

    And you never leave a finger print on a glass that could be 3d printed or jelly moulded into a fake replacement? I am sure your optometrists is securely storing the pictures of your eyes from your last check up. What happens when government department is hacked and your finger print files are leaked (omb), you can't change your finger prints or rentinas.

  12. WAS by Kunedog · · Score: 1

    phone

    WHO?

  13. Re:If the message is intercepted and not delivered by uvajed_ekil · · Score: 1

    wouldn't the person who is expecting to receive it kind of, you know, notice?

    Not if your VOIP is hacked and you aren't immediately aware of it.

    --
    This is a hacked account, for which the owner can not be held responsible.
  14. Re:If the message is intercepted and not delivered by uvajed_ekil · · Score: 1

    oops, if it is read before delivery I mean

    --
    This is a hacked account, for which the owner can not be held responsible.
  15. that's not a "ban" by ooloorie · · Score: 5, Insightful

    NIST can't "ban" the use of SMS for two factor authentication in general. Those are NIST guidelines (of course, some organizations may choose to make those guidelines mandatory). Furthermore, they don't seem to have a problem with SMS verification per se, but as the announcement itself says, they merely want people to verify that the phone number is an actual mobile phone, a reasonable recommendation.

    1. Re:that's not a "ban" by Anonymous Coward · · Score: 0

      It is quite easy for a hacker to redirect a telephone number to another phone, not just to a voip.
      This has been shown on national TV, where they hacked the 2FA with SMS of an account of the journalist.

    2. Re:that's not a "ban" by Anonymous Coward · · Score: 0

      I have seen it done myself. At work we urgently needed a number transferred (sim card physically broken) and the person to authorize this was on vacation, so it was not possible in the physical store. Another employee called the support and told them 'yes I am Mr bla bla' and they did it, no questions asked.

    3. Re:that's not a "ban" by jittles · · Score: 1

      NIST can't "ban" the use of SMS for two factor authentication in general. Those are NIST guidelines (of course, some organizations may choose to make those guidelines mandatory). Furthermore, they don't seem to have a problem with SMS verification per se, but as the announcement itself says, they merely want people to verify that the phone number is an actual mobile phone, a reasonable recommendation.

      The NIST most certainly can ban their use for government projects. Also, you can clone someone's SIM card or use a social engineering attack to get a new SIM issued for a specific number. So it's not just a matter of verifying the phone is a mobile phone. There are more sophisticated attacks that SMS auth allows.

    4. Re:that's not a "ban" by ooloorie · · Score: 1

      The NIST most certainly can ban their use for government projects

      Which part of "of course, some organizations may choose to make those guidelines mandatory" did you not understand?

      So it's not just a matter of verifying the phone is a mobile phone. There are more sophisticated attacks that SMS auth allows. Also, you can clone someone's SIM card or use a social engineering attack to get a new SIM issued for a specific number.

      Those are not "sophisticated attacks" and other two factor authentication schemes are subject to cloning and social engineering. It is exceptionally stupid to give up the extra security and simplicity of SMS authentication because of such objections.

    5. Re:that's not a "ban" by jittles · · Score: 1

      The NIST most certainly can ban their use for government projects

      Which part of "of course, some organizations may choose to make those guidelines mandatory" did you not understand?

      My point in mentioning this is to say that NIST is a government agency and that certain parts of the government are bound to NIST determinations. Not as a matter of self determination but a matter of law. And that you cannot just say that "NIST can't ban SMS 2FA" because they did exactly that for the US Government.

      So it's not just a matter of verifying the phone is a mobile phone. There are more sophisticated attacks that SMS auth allows. Also, you can clone someone's SIM card or use a social engineering attack to get a new SIM issued for a specific number.

      Those are not "sophisticated attacks" and other two factor authentication schemes are subject to cloning and social engineering. It is exceptionally stupid to give up the extra security and simplicity of SMS authentication because of such objections.

      The problem is not 2FA but doing 2FA over SMS. And those are relatively sophisticated attacks as they require a bit more knowledge and planning than just taking over someone's email account and using the password reset option to capture password reset requests or something like that. You actually have to know who the person is and who their cell phone provider is in order to execute such an attack. If you're overseas, you may need a local accomplice to help you execute the attack. There are better ways to provide 2FA. For instance, you can use an auth system that uses secret information from the server plus a user PIN to help prevent someone from using a auth code captured by something like a MITM attack.

    6. Re:that's not a "ban" by ooloorie · · Score: 1

      There are better ways to provide 2FA.

      There are better cars that a Honda Civic. That doesn't make a Honda Civic a bad car.

    7. Re: that's not a "ban" by Anonymous Coward · · Score: 0

      Sweet Jeasus, it's like you read the entire recommenation.

      All frustration a side, NIST isn't saying "No 2-factor" they just don't want a uername/password guarding a VOIP SMS recipient that is used to fetch the 2 Factor authentication token. Kind of defeats the point if an attacker can brute force you login for Google voice that delivers the login code for your work email!

  16. Mom was phone by tepples · · Score: 1

    In the story about making out with your girlfriend, getting a call from her parent to check on her, and discovering that her dad is dead?

    Simple. Mom was phone.

  17. Three factor auth by Anonymous Coward · · Score: 1

    Stop, please stop pushing three factor auth with the "are, have and know". Biometrics = bad = unchangable. Auths have to be mutable in order for plausible deniability. Body parts will be ripped off either to extort a non-body physical item or for the body part itself - never worth it. How many movies have to be made to drive this point home?

    1. Re:Three factor auth by Anonymous Coward · · Score: 0

      Biometrics only work when you have a guard with medical training to see if the biometrics have not been tempered with.
      The guard will also need to immobilise the person being authentication, in case of slight of hand.
      The guard will have to physically move the biometric object to the scanner as well, so that it will be scanned correctly.

  18. The issue with smartcards... by Anonymous Coward · · Score: 0

    is ensuring any keys stored on them can't be exfiltrated from the card itself (are the electronics on the card trustworthy and emissions shielded?), and that any keys stored within them were generated/are backed up on an airgapped computer, ideally in an isolated room (meaning visually, acoustically, electrically, and physically. Failure at any of the four can lead to exfiltration or generation compromise as well.) If those mitigations are taken, then short of very expensive 'active' surveillance from an extremely well equipped foe it is unlikely for the keys to be compromised. Assuming you have a smartcard that is 'programmable' (javacard, basic card etc.) you could also use non-standard algorithms on them to ensure your encrypted/decrypted/signed output is quantume hardened, although likely at a significant throughput penalty.

    I'm not sure what the patent/copyright situation is on smart cards today, but they, sim cards, and sdcards (now that the memory/device industry is looking to abandon them for that incompatible new sd-card replacement) would all make good candidates for open source electrical/protocol compatible equivalents with fully documented and vetted designs for security related purposes. SD cards, esp multi-device SDIO cards would be perfect for a combination storage/crypto device with a protocol standard that could be used on almost any device with an sd card slot and open source firmwre (IE most cell phones, tablets, and some media players.) Done properly you could have the keys stored in protected memory on the sd card and have plaintext data encrypted *ON* the sd card and read/written as the OS provided necessary lock/unlock instructions. While data could still be extracted in three corner cases, under normal circumstances the data would not be in a usable state except when an authorized application/kernel had provided the identity information needed to unlock it (which could be scripted for a card by card authentication method.) Done right it would raise the bar to data exfiltration significantly, outside of already compromised devices. (Any modern x86/x86_64 or arm chip is probably compromisable if not compromised by the factory firmware by default though :/)

  19. Nah the password is.... by Anonymous Coward · · Score: 0

    4ry4nbr0sb4pUr3bl00d3dh03z :^P

  20. I think about this sometimes by Anonymous Coward · · Score: 0

    If somebody gets a hold of my phone they could fuck me over pretty good.

    1. Re:I think about this sometimes by Chrisq · · Score: 1

      If somebody gets a hold of my phone they could fuck me over pretty good.

      Chances are that Apple or Google "owns" your phone. And yes, they could fuck you over pretty good.

  21. Re: the phone may not always be in possession phon by Anonymous Coward · · Score: 0

    you can't change your finger prints or rentinas

    I don't care if I don't own them. I'll just hire different ones.

  22. Not a big deal by ITRambo · · Score: 1

    The only problem I see with SMS codes is that if you don't have your phone you can't log into your MS, or other, online account from a new device. If you do have it, receiving the SMS is simple. Why would someone steal an SMS double authentication code? They can't do anything with it, except annoy the person waiting for it.

  23. Software Defined Radio by Orgasmatron · · Score: 5, Insightful

    Part of the cell phone security model was that it was expensive and difficult to build the radio gear necessary to spoof a cell tower. Fast forward to the last few years, and you can get an excellent board for SDR for like $500. The guidelines list steps you can take to reduce the risk of SS7 routing shenanigans, but there isn't much you can do about a highschool kid (or an organized crime outfit) playing MITM with a cheap radio, which is why it will be deprecated soon.

    If you are in IT, and your environment demands security compliance, this will reach you eventually. It might take a few years if your structure is slow.

    I'm not using secondary device auth anywhere because I believe that dedicated hardware is more secure, but many of my peers are.using this. They will be switching off the SMS option and pressing on with online OOB methods, at least until their next cycle. We suspect that online OOB will go away entirely soon as tablet/phone malware matures and starts emptying phone-2FA-protected bank accounts.

    --
    See that "Preview" button?
  24. Error: Tinfoil hat too tight by Anonymous Coward · · Score: 0

    At the risk of sounding very paranoid, I wonder if 2FA SMS isn't being doubted by NIST because LEO cannot effectively hack it as it has tokens.
    Naaa. Too far out there to be true. I mean, that would assume that US security organs have weakened encryption or something silly like that.

  25. Number portability by quenda · · Score: 2

    In Australia, and presumably other countries with number portability, SMS authentication is a joke.
    While a SIM has strong crypto, and cannot easily be cloned, it is trivial to steal someones phone number by 'porting' it to another SIM.
    The only 'secret' you need is their account number (dumpster dive, emails, social engineer or mailbox) or date of birth for prepaid.

    The only thing less secure is those password resets, that ask for the make of your first car, etc - something guessable or found on your facebook profile.

  26. Hacked phone, wrong focus? by Anonymous Coward · · Score: 0

    As people use phones for browsing, the second factor in phone-based 2 factor auth is essentially moot. Any attaker with root on the phone can get both the password and the SMS (or token, what ever). Less likely: if a phone is stolen, the thief could possibly get in, if the user used some kind of password manager. How can routing of SMS messages be a bigger problem than this?

  27. Ban? Melodrama much? by Opportunist · · Score: 1

    NIST isn't your god, you can safely ignore whatever NIST says, unless you are one of the handful of companies that actually HAVE to follow NIST guidelines.

    What NIST does in this case is provide best practice recommendations. Nothing more. That's no "ban", not even by a longshot. Hell, if the FCC says "oh, we think you maybe shouldn't..." it is closer to a ban than NIST saying "you SHALL NOT!"

    The article doesn't even talk about who has to implement this, only that two-factor out of band authentication shall not be done via SMS anymore in future implementations.

    Sorry, but ... the hell, how is this newsworthy?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Ban? Melodrama much? by Anonymous Coward · · Score: 0

      It's extremely newsworthy for a number of industries. Anything in a sector with any regulation has just had it banned. Healthcare, Financials, etc cannot go against publicly regulated best practices and still be compliant in their sector.

      In addition, any business compromised that utilized technology that went against best practices could be held liable in case of legal investigations.

      So, for most of the U.S. Business world this effectively means it is banned.

  28. They can steal your money directly, and your car by raymorris · · Score: 1

    Suppose your car has a fingerprint scanner, along with a keyfob. That's something you HAVE and something you ARE.

    Theoretically, could a thief steal your key fob and your fingerprint? Yes, of course. Would it be easier to just a call bring a trailer and steal your car directly? Yes, of course.

    People will ALWAYS be able to steal. Security isn't about making it impossible. It's EASIER to steal a key fob than to steal both a fingerprint and a key fob. Therefore, adding the fingerprint increases security.

  29. Who was phone? by Anonymous Coward · · Score: 0

    Who was phone?

  30. Re: the phone may not always be in possession phon by gumbi+west · · Score: 2

    With this new "knife" technology in the hands of the wrong folks, your finger/eye are suddenly much more like, "something you have."

  31. Re:They can steal your money directly, and your ca by Anonymous Coward · · Score: 0

    It is EASY to steal a fingerprint, if you're ruthless.

    Just hack the finger off with a machete. Simple way to steal luxury cars or empty rich guys bank account. The rich guy won't come after you - he'll be on his way to the hospital. Oh, and he won't be pulling a trigger either . . .

  32. It really is very insecure by Murdoch5 · · Score: 1

    Currently I work for startup and my job is to secure our web based protect, which includes enforcing login authentication, encryption standards, database usage and more.

    The method we use to employ was a tri-factor authentication system, password, TOTP and SMS / Email based tokenization, but we've officially taken the SMS authenticator away because just as this post points out, you have to guarantee who has the phone and somehow confirm the phone which received the SMS is the phone which was meant to.

    Think of this concept as having an IP Address, you can send a message to IP 1.1.1.1 and you have to assume that where it ends up is the right destination, because you have to assume the person saying they're 1.1.1.1 is who was assigned that IP Address and not someone who basically stole it and is using it in an unauthorized fashion.

    The better way to handle this kind of access security is to use AES_CCM based tokens that have TOTP built into them and force a login through use of a mutli-hop path that gets created and is active only for X Minutes after the user tries to login with their password. How this is works is that after you get the password, you generate a path descriptor which can talk with your Secure DNS. You encrypt this information with some form of AES (or any other standard). You put this information into a secured database system such as MongoDB with the FIPS compliance module active, and then send an email to person X with a link that activates the SDNS module, to read the string from the database, unencrypt it, develop a dynamic path to the end point and request the users TOTP from something they have. Once the user is logged in, you scramble all this information, then securely wipe it from both the program, memory and database and start all over.

  33. Re:They can steal your money directly, and your ca by Anonymous Coward · · Score: 0

    Still, the best factor is "something you know".
    It's the easiest to invalidate if stolen, the easiest to make arbitrarily complex to defeat brute force, and the hardest to reconstruct from casual observation or theft unless you are carless.

    Something you have, is the second best because it's the easiest to detect when you have lost it, only marginally harder to revoke and replace if lost, and can be hardened against unauthorized reproduction to some extent. It is also the very best second factor to include as it is strong in ways "something you know" is weak and "something you know" is strong in ways it is weak. The authentication device + password is the best overall solution, and even weak implementations like using your phone as the device and allowing 4 diget numeric pass codes are very strong compared to other common systems.

    By far the worst factor is "something you are" because you can't revoke it, you can't hide it from casual observation, and you won't know is someone else is using it. Hell in some cases it can't even uniquely identify you (facial recognition vs twins).

    The only use case where biometrics makes any sense are when you would seriously consider "no security" (say to unlock your X-Box or keep your sister out of your diary) or in cases where you are adding additional security to a system that already has the otehr two (like adding a retina scanner to a key-card + pin lock ).

    Laypeople think biometrics are the strongest factor because they mistakenly assume that it being hard to revoke makes it hard to forge (they're assuming you ahve to get plastic surgery to fool facial recognition for example). That isn't true as the forgery can use any method to produce a fake (like a mask or photograph), but revocation means changing the way the actual person reads on the scanner.

  34. Re:If the message is intercepted and not delivered by mark-t · · Score: 1
    If you are expecting a message, and do not receive, it, then how would your VOIP being hacked stop you from noticing? You might not realize that your VOIP has been hacked, but how could you not notice that you didn't receive the message?

    If the message is intercepted while it is being delivered, but is still otherwise delivered normally while a copy is saved elsewhere, I can see that being a problem, because the recipient gets no cues that interception is occurring. But that's not what I was talking about... the article talked about the problem of messages being intercepted and then *NOT* being delivered, which I would imagine is not going to be a serious problem.

  35. This is 100% CORRECT by Anonymous Coward · · Score: 0

    >SMS messages may be intercepted and not delivered to the phone.

    It shouldn't take NIST to make you aware of this though.