news.volyx.in

Companies embracing SMS for account logins should be blamed for SIM-swap attacks (keydiscussions.com)

451 points by spenvo · 925 days ago · 321 comments on HN

Article summary

The article argues that companies using SMS for account logins and password resets should be held liable for SIM-swap attacks, which are preventable and allow hackers to steal sensitive information. The use of SMS for authentication is considered insecure due to its vulnerability to SIM-swap attacks and man-in-the-middle attacks. Many companies, including Apple, Google, and financial institutions, still rely on SMS for authentication despite its weaknesses. The article calls for companies to move away from SMS-based authentication and adopt more secure methods, such as email verification or authenticator apps.

Main themes

  • SIM-swap attacks
  • SMS authentication insecurity
  • 2FA solutions
  • Customer convenience vs security
  • Company liability
  • Regulation and standardization
  • Biometric authentication and smart tokens
  • Email verification as an alternative to SMS
  • Telco responsibility for securing phone numbers

What commenters say

  • Companies should prioritize security over convenience and stop using SMS for authentication.
  • The use of SMS for authentication is a lazy and insecure solution that puts customers at risk.
  • Telcos are primarily responsible for securing customers' phone numbers and should be held liable for SIM-swap attacks.
  • Email verification is a more secure alternative to SMS-based authentication.
  • Some argue that SMS-based authentication is still a good option for customer convenience, despite its security risks.
  • Others believe that companies should focus on implementing more robust identity services, such as biometric authentication or smart tokens, to improve security.
  • The lack of standardization in 2FA solutions is a significant obstacle to widespread adoption of more secure methods.
  • Regulations and laws may be necessary to force companies to adopt more secure authentication methods and hold them liable for security breaches.