by nde on 11/6/22, 12:04 PM with 9 comments
Fast-forward a couple weeks: I go to log in to change one of my templates, and I get prompted to enable 2FA on my account. Thinking, “it’s kinda neat they make it this easy,” I click “Next”. Then, Sendgrid prompts me to enter my phone number so that in case I lose access to my 2FA device, they can send me a one-time code via SMS…
In other words, SMS can be used to bypass the 2FA you set up with Sendgrid. After going back and forth with their customer support team, it looks like providing your number is the only way to enable 2FA and unless you enable 2FA you can not log into your account…
by Normille on 11/6/22, 1:45 PM
a while back I visited one of those 'send a 2FA code to you via SMS' websites and, not noticing the SMS bit, I entered a 2FA code from my phone's authenticator app as the number I'd been sent by SMS --which worked to let me in.
When the actual SMS 2FA code arrived on my phone a few mins later [crap phone signal here] I noticed it was the same code. So it seems like at least one site is just forwarding you the same code your authenticator app would generate, as an SMS. I'm not sure of the security implications of that --if any.
I've also noticed that, quite often when I check verious bank and credit card accounts, one after the other, the 'please enter the Xth, Xth, Xth and Xth numbers from your security code' prompt is asking for the same numbers, on each bank's site. Which strongly suggests a load of separate banks are using the same centralised security prompt generation --which sounds like a bad case of 'single point of failure' to me.
by simondanerd on 11/6/22, 12:22 PM
by nde on 11/7/22, 12:28 PM
The more cynical reason might revolve around getting access to your phone number, but we’ll give the benefit of the doubt and say that’s not the case.
In my opinion, websites offering 2FA should give users a choice to pick between: - Security Key (with Backup Codes you can store offline or SMS) - Authenticator App (with Backup Codes you can store offline or SMS) - SMS - No 2FA
If I want to choose a less secure method for 2FA or backup codes, that should be my choice but clearly communicated.
by hayyyyydos on 11/6/22, 2:42 PM
by curiousgal on 11/6/22, 3:23 PM
by rat9988 on 11/6/22, 2:19 PM