Erik van Straten<p><span class="h-card" translate="no"><a href="https://mastodon.laurenweinstein.org/@lauren" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>lauren</span></a></span> : in 2020 I wrote a "Secure SMS 2FA Proposal" (<a href="https://security.nl/posting/638976" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">security.nl/posting/638976</span><span class="invisible"></span></a>) - there's English and Dutch text.</p><p>The main idea is for the recipient to modify the received code using a shared secret, before entering it as the second factor.</p><p>Of course weak 2FA (without E2EE channel binding) is not phishing proof, but my proposal should prevent successful SIM-swap attacks (and redirecting calls and messages by manipulating the telco backbone as shown in <a href="https://www.youtube.com/watch?v=wVyu7NB7W6Y" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=wVyu7NB7W6Y</span><span class="invisible"></span></a>).</p><p>I cannot change anything in those postings anymore (and I'm in no way related to security.nl apart from being a regular -unpaid- contributor).</p><p>Feel free to pass this idea to your contacts at Google as an alternative to QR-codes - from which I fail to understand how they'd improve security. In fact, the unprotected channel from screen with QR-code to the camera recording it, allows for all kinds of (AitM) phishing attacks.</p><p><span class="h-card" translate="no"><a href="https://sfba.social/@not2b" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>not2b</span></a></span> </p><p><a href="https://infosec.exchange/tags/SMS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMS</span></a> <a href="https://infosec.exchange/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://infosec.exchange/tags/Weak2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Weak2FA</span></a> <a href="https://infosec.exchange/tags/WeakMFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WeakMFA</span></a> <a href="https://infosec.exchange/tags/NotPhishingResistant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NotPhishingResistant</span></a></p>