Since when was sms ever secure? My understanding is that messages are sent in the clear, meaning your carrier and the recipient’s carrier both have the opportunity to intercept messages.
I mean that’s the message content, not the authentication, but still, sms is the opposite of secure, always has been.
Not true. SMS is encrypted in 3G, LTE, 5G. Block cyphers like Kasumi and A/9 are used. SMS is reasonably secure, because it’s hard to infiltrate telecom systems like S7
because it’s hard to infiltrate telecom systems like S7
cough You can pay a few grand and get access to SS7 networks.
Might be out of reach for most of us, but we can rest assured that any and all security firms and goverrnment agencies have access to this information at a moment’s notice.
S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.
Nah what we need is good privacy-focussed companies getting into the public IAM space.
You know how you can sign into stuff with your Google or Facebook account? And get a 2FA push to your phone?
Like that. Except by a company with a shred of ethics and morality. Like Proton.
I do also think that we all should have a cryptographically secure federally issued identity for official uses such as signing documents or signing into financial accounts and other things that must use your official identity, and not an online pseudonym. Like SSN but on a smartcard. Basically CAC or ECA but for general civilian use.
Proton is already used for identity management: OTP via email. They’ll implement OAuth if there’s enough demand for it. A company’s purpose is to be profitable, ethics side is largely irrelevant.
Many countries already have digital government ID: Australia, Estonia, Russia.
A company’s purpose is to be profitable, ethics side is largely irrelevant.
Maybe so, but companies such as Proton’s biggest asset is their reputation…a reputation of being privacy-focussed. Without that they are nothing, and they know that. As a result, they try to live up to that reputation as well as possible.
Being as it was started by Sir Tim Berners-Lee (among some of CERN’s other founding fathers of the web) is just icing on the cake.
Since when was sms ever secure? My understanding is that messages are sent in the clear, meaning your carrier and the recipient’s carrier both have the opportunity to intercept messages.
I mean that’s the message content, not the authentication, but still, sms is the opposite of secure, always has been.
Not true. SMS is encrypted in 3G, LTE, 5G. Block cyphers like Kasumi and A/9 are used. SMS is reasonably secure, because it’s hard to infiltrate telecom systems like S7
cough You can pay a few grand and get access to SS7 networks.
Might be out of reach for most of us, but we can rest assured that any and all security firms and goverrnment agencies have access to this information at a moment’s notice.
Simply paying is not sufficient. You need to be a telecom company, or a researcher afaik.
In what world would the US gov care to get into your bank account? Or your Facebook account when it’s already tightly controlled?
Telecom systems can be (and are) infiltrated though, which is what the FBI is warning about.
SS7 is very insecure. See this video, too: https://www.youtube.com/watch?v=wVyu7NB7W6Y
Watch the video again to see how hard it was for Derrick to get access. He got it via his telecom/academia researcher contact.
It’s hard, but not hard enough from what I’ve been able to gather. We should want something better IMO. I’m surprised that TOTP isn’t more common.
S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.
Nah what we need is good privacy-focussed companies getting into the public IAM space.
You know how you can sign into stuff with your Google or Facebook account? And get a 2FA push to your phone?
Like that. Except by a company with a shred of ethics and morality. Like Proton.
I do also think that we all should have a cryptographically secure federally issued identity for official uses such as signing documents or signing into financial accounts and other things that must use your official identity, and not an online pseudonym. Like SSN but on a smartcard. Basically CAC or ECA but for general civilian use.
Proton is already used for identity management: OTP via email. They’ll implement OAuth if there’s enough demand for it. A company’s purpose is to be profitable, ethics side is largely irrelevant.
Many countries already have digital government ID: Australia, Estonia, Russia.
Maybe so, but companies such as Proton’s biggest asset is their reputation…a reputation of being privacy-focussed. Without that they are nothing, and they know that. As a result, they try to live up to that reputation as well as possible.
Being as it was started by Sir Tim Berners-Lee (among some of CERN’s other founding fathers of the web) is just icing on the cake.
Proton gives data to governments if requested. Why are you trying to shill it?