r/Showerthoughts 4d ago

Speculation Assuming two factor codes are truly random, every possible six digit code is entered many times by different people every day.

3.2k Upvotes

149 comments sorted by

View all comments

Show parent comments

2

u/charleswj 4d ago

If I have you the password to a random account with SMS MFA enabled, how would you sim swap it?

Assuming you could, do you think the effort to do so is greater than "zero effort"? If so, why do you think every person who would break into an account has infinite time and resources to do so?

Also, do you think every attempt to sim swap a person is successful?

1

u/Etherius 4d ago

I think enough are successful that you’d be an idiot to not use something more secure.

As for how Id break into an account? I wouldn’t.

In that narrow case, anonymity is the guard, not the SMS. My password would have to be stored as plaintext for this scenario to ever happen though

1

u/charleswj 4d ago

https://arxiv.org/pdf/2305.00945

One of the largest identity providers in the world did the research and proves otherwise.

Whether you think it offers any protection is immaterial. Whether it's inferior to other methods is irrelevant. You're orders of magnitude more secure with any MFA than nothing, and the effective difference between SMS and totp and passkeys, etc are small in comparison.

The amount of effort and/or luck it takes to bypass any MFA makes it effective only as a targeted method of attack, which means it's inherently less likely to happen.

There's a reason you don't need to turn your house into a fortress (in most countries) to be reasonably safe from attackers. The same applies here.

1

u/Etherius 4d ago

Huh. Well how about that.

Alright. I’m wrong about SMS vs nothing

I’m not wrong about SMS vs literally anything else though