- cross-posted to:
- news@lemmy.world
- cross-posted to:
- news@lemmy.world
in other news grass is green
It’s brown in my area. Check mate!
Yes mate! I checked mate, you’re right mate!
actually it’s white
Always has been
Authentication for my work email: Enter 28 character password, receive sms, enter message, log in
Authentication for my Battle.net account:
-Enter email made before 2000 because they don’t let you change email
-Enter password
-Get rejected
-Solve CAPTCHA
-Try backup passwords, get rejected
-Request new password
-Send request to 24 year old email
-Try to log on to 24 year old email, email is suspicious and sends Authentication request to my newer email
-Open newer email, Authenticate older email
-open old email, Put in code to battle.net
-Battle.net requests Authenticator code from Battle.net app
-Open battle.net app (no requests)
-Try manual code, doesn’t work
- Realize Battle.net app Authenticator not connected
-Try to connect Battle.net app Authenticator to account
-Realize you cannot connect Authenticator without signing in AND signing in requires Authenticator
-Close Battle.net app
-Open Blizzard Authenticator
-Close warning that this app got depreciated in January
-Enter manual code
-it works
-Attempt to change password to password I first attempted
-Won’t let me use same password
-Try logging in using that password
-Still doesn’t work - Solve one more CAPTCHA
-Change password to backup password and back to original password - have to solve 2 more Captchas
-Finally works
-Log in
I wish Signal stopped using it. I know you can set a Signal PIN but a lot of the non-techy friends I speak to on Signal probably wouldn’t think to, or look through the settings (not that you need to be “techy” to set it, but you know the kind of learned helplessness most people have about tech). At least a prompt for all users to set an account PIN so their account can’t just be stolen by anyone with their SIM card.
Another thing is that even if you set a PIN, you’d still have to log into your account relatively regularly so that if you lose access to your number, you wouldn’t lose an account. It’s logical, given that numbers are reused… But that means that if you want to register without effectively tying your account to your ID (KYC when buying numbers is mandatory in a lot of the world, remember!), you’d have to pay for another phone bill (expensive given that the number’s practically doing nothing!) or use a one-time rental… Which guess what, puts your account at constant risk!
I thought they abandoned SMS a couple years ago??
They abandoned letting you use the Signal app to send and recieve SMS. You still need to get a code via SMS to activate your Signal account. I believe this is what they are referring to.
Yep, I was referring to that. You can stick someone else’s SIM in your phone and log into their signal account if they’ve not set a Signal PIN. You don’t see message history but new messages to that person will go to you.
New Clipper Chip mandatory in new phones for “security” 😉
Who’s security, tho? 🤔
Security against foreign hackers, of course
(But with the additional purpose of securing the #LandOfTheFree against those pesky #Terrorists, of course. Who’s a terrorist? Why of couse that’s anyone who dares to
criticize the governmentahem I mean… make threats against the United States of America 🇺🇸🦅)
NIST has been saying since 2016 not to use SMS for MFA. It’s always been horribly insecure.
The problem for me is that most Canadian Banks give you the choice of SMS or their shitty adware filled bank app that relies on Google Play Services and wont implement TOTP so I can use a true MFA app. And Im done with being forced to accept user policies I don’t agree with to do shit, and most of all done with Google Play Services on my device 😑
My bank prides itself being the first in the country to support yubikeys for 2fa. I was so happy until i learned it’s just for logging in, transactions are still confirmed by SMS or their app. And security experts all say it’s better this way, using a regular 2fa solution would be insecure because you wouldn’t know what you’re confirming.
There really is no hope.
It’s definitely possible to have a hardware token which allows confirming the transfer details - https://www.manua.ls/nationwide/card-reader-security-for-internet-banking/manual
I’m not defending that madness, but that device doesn’t show who is the recipient. The argument was that this is protection against phishing sites pretending to be a bank, proxying your connection but sending it to a different recipient.
Makes one wonder how much the user has to fuck up to end in such a scenario, and of it’s really worth transmitting everyone’s financial data in almost plain text over the air for this
Even Bank of America doesn’t support MFA apps.
why bank when you can dank
They support USB hardware tokens… but only for the website. Everything else is SMS which kinda defeats the point.
Annoyingly, other than Vanguard, they are the only financial institution to support USB FIDO tokens
in my experience, FIDO tokens suck. I have to around 10 times every time I use one to log in.
Should be illegal to put ads in something as crucial to day-to-day life as a banking app.
If it’s not illegal, then everyone is going to do it and we won’t have the “choice” that crapitalists love to tout so much.
Its supposed to be illegal for banks to be in “sales” but my wife was working for BMO and they were forcing her to prioritize outbound cold calls ans upselling products the customer didnt need and would clearly be bad for their financials as a Personal Banking Assistant. The conflict of interest was so great it stressed her right the fuck out and she had to take leave and start therapy. Her MS also spiked likely due to the stress levels. She was there to help people, and she made the bank earn loyal customers and they willing got more products from the bank because she helped them. She was the top performer at the bank if she just let her do the job she was there to do, but instead her boss started ragging on her daily about her cold calling numbers and forcing her to cancel necessary appointments and focus time to deal with customer requests and instead prioritize sales.
In the end her numbers dropped, her customer satisfaction dropped, and her MS got worse from the stress and she’s now on long term leave, uncertain if she’ll recover her focus and able to go back to work. Her neurologist has said she cannot go back for now.
Not sure how that bullshit helped the bank, but I can sure see how I didn’t, and I may be wrong but I think there are laws against it.
Also worth noting that this change in tactics happened right at the same time BMO took all their “we’re here to help” signage down. Brings so many memories of Google dropping the “don’t be evil”. Everything that came after in both cases was shit.
Adding to this that my Canadian bank just updated their app and it doesn’t work with my older phone. So my only option is to use online services with SMS/call verification.
It’s such a joy to know that my bank, who made $40.670 billion last year, takes care of every customer equally.
This is the main reason I switched to Fidelity here in the US. It’s a brokerage, but it does basic bank things, like checks, debit card, etc, and they support SymantecVIP, which works w/o Google Play Services. TOTP support really isn’t that hard, I don’t understand why banks are so slow in adopting it…
In case you weren’t aware, Symantec VIP is just TOTP-OATH in a fancy coat. You can extract the secret and use it with any TOTP app. I use Authenticator Pro (now called Stratum) because it’s open-source and has a watch app.
Do you know how to extract it?
I have this bookmarked from a few years ago, back when PayPal only supported Symantec VIP: https://gist.github.com/jarbro/ca7c9d3eebba1396d53b4a7228575948. I haven’t tried it for a while, but it should still work.
Thanks for this…I might be opening a Fidelity account…
I’ve got one. It’s nice. The cash is automatically invested in a money market account, which is a bit like a high yield savings account.
They’re fantastic. :)
The only negative stories I’ve heard are from people who really push the boundaries, like people day trading and whatnot. If you’re a regular user looking for a bank alternative, you should be good.
Just know their branches don’t really have any banking services, so you can’t go there to withdraw or deposit cash, get a cashier’s check, etc. I keep an account w/ a local institution and transfer money as needed for banking services.
I had a negative experience when initially setting up my account, because of TikTok. This group of kids who called themselves “Fidelity Boyz” discovered that you could deposit a fake check and immediately withdraw the money.
So many people did this that they had to severely lock things down. For most customers, money transferred in either via check or via ACH pull (telling Fidelity to take the money from an account at another bank), was subject to a 16 business day (three weeks and one day) hold. Direct deposits (e.g. paychecks) were not affected, and ACH pushes (when you tell another bank to send the money to Fidelity) were eventually fine too.
It was a big pain. The money I transferred was in limbo for a long time, after I had already switched all my auto-pays over to Fidelity, so I had to switch them all back until the money cleared.
Now that that’s over, it’s great. I love that they reimburse ATM fees worldwide, and I’m a big fan of their basket portfolios product since it makes it so easy to rebalance a portfolio. Saves me from having to manually do a bunch of calculations, and I love that it has a fixed monthly price instead of being percentage based like roboadvisors.
The issue is, banks are only going to do what they’re required to do by law. The government is run by dinosaurs who don’t know what computers are, let alone what TOTP is.
No, they’re only going to do what they’re required to do by their insurance. The law is an option, but if insurance costs go way up if they don’t have proper MFA, they’ll get MFA.
Now you’ve got me wondering about this for Canada. Would be a pita to move mortgage and investments, but there must be a better way than the big banks.
Here’s a website that tracks this kind of thing. No guarantees about being up-to-date, but from a surface-level check, it looks like you have options.
Wouldn’t count on it being up to date. For my country 4 out of five biggest banks in the country are missing.
Thanks!
Why the hell is this in 4K HDR?
We here at Lemmy are professionals
Only the best for the worst hack in history.
of course it is. forced 2fa BY SMS OF ALL THINGS is one of the stupidest ideas
I assume businesses only jumped at the chance to enable SMS 2FA to get their greedy little fingers on our phone numbers.
It was the simplest/cheapest form of 2FA to implement. Grandma will never understand how to setup TOTP.
Capitalism requires regulations, otherwise it will ALWAYS do what is cheapest or most profitable, regardless of how dangerous or destructive.
Even stupider is supporting hardware keys for MFA, but having SMS fallback which can’t be disabled (looking at you, Vanguard). I’d much rather have email as my second factor than SMS, and I literally abandoned a bank (Ally) for removing email as an alternative to SMS.
I hate forced 2FA that you can’t disable anyway. I don’t want to waste time waiting for an insecure text, I don’t want to input an unencrypted code you sent to my email, I don’t want to click your damn notification that runs through Play Services, and no I’m not enrolling in passwordless auth. I don’t need to be babied into securing my accounts. Any account I do actively and willingly secure is already using TOTP. Let me put in my username and password, then kindly fuck off.
Yeah. So you, myself, and some others are the exception to the rule. But, you can’t look at it that way because its a ‘lowest common denominator’ problem. The least secure of us means we are all only as secure. Others need to be hand held.
It’s definitely time to raise all boats and drop SMS 2fa like a hot rock.
The most natural authentication mechanism for humans is a key. That thing you carry with yourself. A physical key containing, well, the actual secret (shouldn’t be retrievable, should be used for decrypting access request and signing the response) that, maybe combined with your password (another natural for humans authentication mechanism) or maybe, yes, TOTP, gives you access.
Like those “security keys” Imperial officers in Jedi Outcast carry with them. Maybe a bad example.
Phone numbers are used as identifiers because governments like it, nerds don’t like it, and normies explicitly like what nerds don’t like and also want everything to be insecure, they call it “having nothing to hide”.
Also “normal and social” people have that idea that their social prowess is more elegant, smarter at ensuring their security that those dumb and boring nerd technical solutions. So them always choosing things logically opposite of sane, like social media instead of forums, and phone numbers instead of any other identifier, is literally a matter of principle. It’s really not that hard to use something else. They do the stupidest possible thing technically to prove a point that you only have to do the smart thing socially. I mean, in Galileo Galilei’s case the other side of the disagreement is generally considered right, but that’s not an argument effective in society.
I should admit that I’ve been doing the opposite - the stupidest possible thing socially to prove a point that only technical sense matters, which is why nobody would send me encrypted mail except Facebook with its notifications, and nobody would write me in Tox, and nobody would even contact me via XMMP. Which is why I’m now using TG, VK, FB, WA and Signal for communication, of these Signal is secure, and WA is kinda better than the rest of them.
You can apply this logic to nearly anything with very bad consequences.
is already using TOTP.
A lot of things are moving to phishing-resistant technologies like FIDO2/WebAuthn or passkeys. All my important accounts, like my password manager, are secured using Yubikeys (one that I keep with me and one as a backup in a secure place).
@return2ozma @technology
10 years ago, the Feds wanted backdoors to all of phones so they could read all of our text messages. Now, the Feds want everyone not to use software that has backdoors so the Chinese cannot read our phones. The Feds don’t want competition.The backdoors they use are there for freedom and justice, the backdoors the “others” use are tools of evil and security risks!
“They’re the same picture”
Braindead take of the day.
Your comment applies more to your own than the one you responded to. It’s a crazy form of recursion.
Nah that’s just your own wishful thinking.
Why do you hate America’s children?
For real, I bet this guy didn’t back the “Definitely Don’t Maybe Not Almost Probably Save The Children ACT.”
The backdoors they use are there for freedom and justice, the backdoors the “others” use are tools of evil and security risks!
did you forget to add “/s” or do you really believe what you wrote?
Sometimes sarcasm is clear enough without signalling it. I guess not for everyone.
It was a joke, bruh!
Edit: Huh. Guess people downvoting didn’t read up on Poe’s Law posted above. Shocked! Well, not that shocked.
For clarity, I was being satirical.
-signed, DefinitelyNotAFed@Federal.Bureau
Yes
Absolutely. They were so arrogant they never thought it would happen to us. After all, we are in charge of our own networks so why would we expect the enemy to be at the gates? Let’s make those gates out of cardboard so it’s easier to spy on everyone.
Of course then you have things like CALEA mandating a back door, you have cheap telecom companies that will happily buy cheap lowest bidder Chinese hardware and install it "everywhere* without concern for security (after all, it’s not their data being stolen) and now the enemy isn’t just at the gates but inside the walls.
A decade ago, making sure the feds could read everyone’s mail was the national security priority. Suddenly when the Chinese can read everyone’s mail, good security is the national security priority.
It’s too bad there was no way to predict this in advance. Oh wait…
Hollywood hacking has nothing on real hacking it seems.
'nuf said
id take email Authentication over sms Authentication if there was only them 2 let me use my 2facter app for the love of god plz i hate how banks use sms its like come on man
I’m really happy that my doctor’s website uses Signal to send the authentication code.
Email is also unencrypted
Ya just saying I don’t like sms I wish email was encrypted maybe one day
Been saying that for years. It’s about damn time.
SMS spoofing and SIM swapping have been around for ages. It was never secure and that’s always been known. The number of companies that rely on it despite sending me a zillion other fucking useless emails is too damn high! Email, or better yet, an authenticator app, are far more secure. Not perfect, but better.
Wait, how is email more secure than SMS?
https://en.m.wikipedia.org/wiki/SMS_spoofing
So, it’s not that the message itself is insecure, but the inability to verify the sender makes phishing attacks possible or similar things. I get a text from a random number saying “click this link to pay your bill!” And I don’t have any way to trust its legit.
SIM swaps make it so people can take over your phone number temporarily and then generate 2fa requests to gain access to accounts. Doing the swap usually involves bribing someone or gaining access to a providers database by other means, but its been done a lot.
There are ways to prevent this, but the most straight forward is using a MFA app. Barring that 2FA via email is the next best thing.
Forgive my ignorance, aren’t emails sent in plain text that can be read by any of the networks they are passed between? I’ve always been taught email is the least secure of any communication.
I’m not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That’s not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are.
One big reason I’m hesitant to keep my money in banks is because banks think the best form of two-factor authentication is text message based 2FA and I’m like that’s barely any 2FA at all.
My banks are like that too. Of course I can’t speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts.
I keep my money in Monero. That way, it’s me who has to be targeted instead of an institution. And if I fuck up and lose it, it’s my own damn fault.
I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn’t there yet. Maybe someday… But having money distributed is still smart either way, so I have many baskets for my eggs.
I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero.
What are yall using as an alternative?
TOTP or Signal, depending on the use-case
Any examples on what could cause the preference?
Usually signal for communication, totp for 2fa. I’ve as of yet seen only one site that sends 2fa codes through signal.
Oh interesting thanks
Yubikey