Other ways to 2FA

Hi Neo Community,

I was looking at some posts lately where people get locked out of their accounts because their phone numbers are now inaccessible. It seems that the current method of 2FA (more commonly known as 2-factor authentication) used by neo is very antiquated.

SMS-based 2FA is easily bypassed by hackers by social engineering the victim’s cellular company (porting the number to the hackers own device, so they can get the codes instead). It also has a problem when the codes don’t get delivered or if the user is not in an area with cellular service.

There are new, more secure methods to login such as:

  • Passkeys (authenticate with device security to login, user never sees a password or has to remember it),
  • OTP apps (6 digit codes that reset every 30 or 60 seconds, similar to the codes sent to SMS, but are not tied to a phone number),
  • Security keys (physical devices that you insert and tap to send security info that verifies it’s you).

All of these would have to be setup by the user prior, but passkeys are already deeply integrated into iOS, Android, macOS, and Windows.

It was very dissapointing when I joined to learn that neo doesn’t support basic 2FA methods like OTP codes beyond SMS. Adapting the current system to add OTP apps should not be difficult at all.

Absolutely! This MUST be the highest priority of neo product management. TOTP is the most important and relevant 2FA to be implemented ASAP!

Neo does use passkeys. I use a passkey using my biometrics as 2FA both on the browser and Neo mobile app.

Hi,

Just confirming, the biometrics prompt definitely says use a passkey? Passkeys are an alternative to passwords for logging in, even for the first time, so the neo app may support biometrics but that is not the same as a passkey.

On iOS, Apple unifies passwords and passkeys by making them virtually transparent to the user, so you may be using a password without realising it.

Can anyone else confirm if neo supports passkeys now?

@izelik please vote for this if you believe it’s as important as you described!!

Yes, passkey, not password.

I actually agree that more, and more secure, login methods are very important features. A little more context on the posts you see here:

Sometimes people do lose access to their phones and need to get back into their Neo accounts. Passkeys and authenticators fail in this situation as well, we’ll always need to be able to authenticate people via support just in case. This is typically a very easy process, unless you have also lost your Canadian ID. We don’t have a great solution for this.

In these forums, we also get people posting because their accounts are frozen. This can happen for a variety of reasons. Sometimes we do it because we suspect someone has compromised their email and/or phone and are attempting to steal, sometimes we do it because the user is suspected of wrongdoing. There’s nothing we can do to speed this up, our investigations team needs time to go through the evidence and make a decision.

All that to say, I personally support alternate verification methods. If you’ve got more ideas, maybe this extra context helps!

passkey is the newest kid on the block - and it’s nice.
TOTP like google/microsoft and other authenticator apps is very nice option, it’s kinda the best from the usability/ease of implementation perspective.
security key is very similar to passkey in terms of level of protection - possession based authentication - if you have it you can enter.

Recovery is complicated.
the main issue there is that if person is compromised then everything about this person can be compromised.
so there should be a mix of possession based, knowledge based and some other ways to authenticate.

Canadian ID i consider almost public, because of how often they get lost. e.g. my mom needed to reissue her ID and service Ontario said "we sent it’ , but she didn’t receive it, which means that her ID is possessed by someone somewhere.

In the ideal case, you want to have multiple steps including face scan, some code, and something else.

It’s scary that security is lagging behind, especially in AI era.

This is definitely a big topic and one worthy of some attention.

It’s funny though, I haven’t given it much thought in a long time, and especially didn’t see Neo as a problematic service in this regard, because compared to the Canadian landscape (I know Europe was decades ahead though, decades ago), especially to how it was maybe 10 years ago, Neo’s login was/is actually by far one of the better ones as far as banks go when I first signed up. While most companies dealing with far less important information were offering the security methods you describe, banks were often using passwords of max 8 chars with most special chars forbidden, (as opposed to a min of 8 or more with a requirement for more variety), and SMS f2a at best, if even at all, which it often was not. Neo at least allowing (requiring even) a real password, and 2fa (even if it is just SMS), stood out at the time, wildly enough (though most have improved by this point thankfully!)

But, like you say, it could stand to progress for sure. Just because it was once far better than the competition doesn’t mean it still is, or that it was ever actually good to begin with.

That said, banking, government services, and things like this are a tricky case. I’m a huge proponent of encrypted services with secure login methods such that if you don’t have your credentials, the data may as well not exist - there’s no work around, no rear service entrance; the account and data is just gone. That works for less important things, and/or people who can manage their credentials well enough to handle that safely, but for most people, and especially when it comes to banking, this would be a greater threat to them(selves) than they face from potential attackers. The option to permanently lose your life savings because you forgot to backup a passcode or didn’t have a secondary device, etc. would probably not fly with most.

Of course, that’s not to say though that they already have the best system and can’t improve - just that the “end state” may always look a little different than it will for other services. I alluded to the European option at the start and they have had physical 2fa code keys (basically the 6 digit code you get in an app, but instead of an app, it’s a physical pager-like device) for ages now, so clearly it is possible to handle things securely without running into issues.

Semi-related Rant

Although it’s a bit of a tangent, this is related to a broader society-wide issue that I think gets far too little attention for how serious it is. If you’re up for a read, allow me to begin:

Whether people have stopped to think about it or not, most people (I think) would easily understand and agree with the following ways you could label or break up types of data:

Public vs Private

  • Public: things that others might know, or even need to know as part of people interacting and living life normally
    • Example: your address, phone number, perhaps your face or name
  • Private: things only you know, and are only needed to facilitate services or verify identity, but would never have a reason to be shared socially
    • Example: your password to a website

Meaningful vs Meaningless

  • Meaningful: info that inherently carries information
    • Example: an ID code like 42-07-510 that the company created because you were 42 years old when you joined, joined in 2007, and are the 510th customer
  • Meaningless: info that may or may not unlock other information, but by itself is just (for example) a random, meaningless string of numbers and/or letters
    • Example: an ID code like 62-41-607 that the company randomly generated for you that doesn’t mean anything

Changeable vs Inherent

  • Changeable: things like a password that you can just change at will without any impacts or friction
  • Inherent: things like your phone number, address, name, fingerprints, face, or birthday, that at best, you could change only with difficulty and significant inconvenience, and at worst, cannot change at all

With that established, identification verification should only ever use private, meaningless, changeable information!

You wouldn’t need to worry about sharing your address, birthday, or phone number, since no one could do anything with it. You wouldn’t need to worry about your ID information leaking because - unlike those - you could just change it, like a password. You wouldn’t need to worry about revealing excess or unnecessary information by signing up to something because the ID method would be meaningless (as described above).

If you try to use public information like your birthday, address, a mother’s maiden name, etc. for identification,

  1. it creates pressure to keep that information private, which is inconvenient at best, and impossible at worst, lest it leak out and be used against you, and
  2. it accomplishes nothing to prevent fraud or actually prove identity, because this information was not previously considered private, so you cannot start using it for private purposes now, because it was and is already “out there” and thus could be learned and used fraudulently by attackers

If you try to use inherent information like your address, face, fingerprint, phone number, birthday, etc. for identification,

  1. If it leaks, you can do little or nothing to change it, so it remains out there, posing a risk to you forever, unlike a password that can be changed so no one with the leaked code can use it

If you try to use meaningful information like your address, name, birthday, etc. for identification,

  1. there is an inherent privacy loss in that exchange

Despite this, most of society is structured around doing exactly these impossible and illogical things for identification, which makes it no surprise how rampant identity theft is, and why people are constantly in a panic about their sensitive information, data leaks, etc. If systems were designed correctly, these concerns would not exist. Your password gets leaked? No worries, you change it before it can be cracked and go on with your day. Your “sensitive information” like your birthday or phone number got leaked? First of all, not really, because surely that was already out there if you’ve ever interacted with another person, and second, too bad, now you’re just [in trouble] since there’s nothing you can do about it!

To tie this back to the original post, consider the SIM-swapping threat mentioned. A bad actor can go to your phone company/mobile carrier, pretend to be you, and get them to hand over a new SIM, so all your messages and calls now go to them instead of you, thus allowing them to steal your SMS 2fa code(s). The only reason this works and is possible is the phone company was probably asking public information like your address, birthday, name, phone number, etc. to “prove” that the person in front of them is you, but, because none of that information is private or remotely suitable for identification in any way, the bad actor was easily able to acquire and abuse it to pull off this stunt. With a correctly designed system like I’m describing where people are identified not by things anyone could look up about them, but instead by meaningless, easily changeable secrets that only they know, this would not be possible.

The thing is, basically every website and other technology already more or less works correctly, and did from the beginning - it’s mostly public/government services that are the problem, along with any legacy-style services like perhaps a mobile carrier. I can only assume it’s a holdover from a time when no one thought or cared about any of this because no one was trying to be malicious with it, but times have changed and these systems need to be modernized. I know it’s not a Neo problem, or something any one person or group can fix on their own, but perhaps with more people thinking about this, one day, we’ll see progress.

You continue to raise the bar for the quality of this discussion, much appreciated! This is all true and great. Special credit for knowing exactly how SIM swaps work, it’s not the dark web black box most people seem to think it is… it’s basically just charming a support rep over the phone.

You underestimate the power of the dark side :sweat_smile:
All information about you is kinda private and not so much the values, but their combinations, e.g.: you name and birthday. At some point i had a db of people in a country and let me tell you that this intersection of birthday and name filters out from millions to thousands at best, but sometimes to hundreds or even few dozens. Without city, province and further filters.

Also, you are touching a core issue of security: if you want to put it on a coordinate system from the most secure to the lest secure you can overlay the same scale with usability: from the non usable to the most use-friendly. The most usable systems are the lest secured and the other way around - if no one can even use something it’s basically absolute security (e.g. it doesn’t exist).

Then you re touching a most scary part for me - social engineering. The thing is that something like 80% of attacks (don’t remember from the top of my head) still happen through e-mail. And with AI phishing will not be same mail to everyone, but automatically tailored to you. And this is scary, because humans can’t be always vigilant, you may be tired, in a rush and so on.

Random IDs are not so random))
if I see enough IDs I can understand how your DB generates them, and then being a legitimate user, I can ask the server to give info about IDs that I should not even know about. Sounds dumb, but look into the real world. CISA Left Its Own Passwords on GitHub for Six Months and it’s a freaking CIA! And we expect some granny to have a good security practices :laughing:

This is me complaining in overall poor state of privacy and security, especially in North America (CA+US).

On the positive note - improvement can and shall be made like the recent trend “zero trust architecture” which means you think about security of the system as if it’s already compromised. So that’s how you should think about your security - you passwords may already be leaked.

It sounds like you could probably provide a lot of value to this topic if it progressed into planning or just advising people or institutions on how to improve! In the interest of making sure we’re on the same page I want to clarify some points I brought up in my post.

When I make the private vs public distinction, I’m purely and theoretically defining the difference between things people will need to share to interact, and things that they have no need to ever make public. It sounds like you’re talking more about “private information” the way it’s commonly described, which is info that, due to how the world is setup, we need to keep private, regardless of how feasible that may or may not be. As you mentioned, things like address, birthday, etc. are absolutely “private” in that sense. In the world I’m describing however, it would be harmless to have them known since they wouldn’t be used for verification as if they’re a secret code that only you know, because, of course they aren’t - many people in one’s social circle may know these facts. Confusion around or misuse of information in this way is perhaps the most significant aspect or cause of the problem I’m describing in general.

The impact of cross-referencing or combining multiple data points to narrow down or de-anonymize a list like you mentioned is certainly something to keep in mind too, as is the trade-off of convenience or usability vs security. It’s precisely why locking things down too much for many people will do more harm than good, as the risk or threat of them losing their own access is greater than the risk of someone breaking in.

Phishing or social engineering like you said is absolutely a big threat too. Hardware security keys that only respond to the real site are one thing that it would be nice to see support for because of how they protect people from being tricked into giving up information to a fake site.

As for the random ID angle, you bring up a few important facets that I glossed over or didn’t mention at all. Computer randomness is indeed imperfect, hence the Cloudflare lava lamp wall (or other more practical examples) of introducing true randomness into an otherwise deterministic system so that they truly can be random. Combined with the simple design choice to not embed or encode information in them and base them purely on this meaningless, random generation, they can be ensured to reveal no information, regardless of how many you see. I think this is important not only for the reasons I said (not directly giving out information by encoding it into the number), but also what you mention about the ability to guess at other valid IDs you shouldn’t even know of. The ways to avoid that and the importance of doing so, given the impacts of failing to shield against it, could surely be a whole post on their own! Obviously an improperly configured server that returns information about an ID, or even just its existence, without proper authentication would - especially when combined with improper generation methods leading to the issues you mentioned - definitely be a recipe for problems, and highlights the importance of companies having the right expertise to design and construct things correctly - something easier said than done for sure, as perfectly illustrated by your CISA story.

Precisely because granny won’t have the best practices, I think it’s important to have systems like this in place - IDs that, if revealed don’t leak any actual information, sites that don’t hand over info without authentication, authentication methods that aren’t based on things someone can easily look up about a person, and practical ways to cut down on the ability for social engineering to get anywhere, whether that’s a phishing attack or tricking the clerk at the phone company. “Zero trust”, as you mentioned, along with other related and beneficial approaches. I’m certainly not the first, or smartest person to think of any of this, and the fact positive trends exist is fantastic. I hope awareness and adoption of them can keep up with their development, since best practices do nothing if not implemented.

+1 for passkeys. Presumably to save money on the SMS vendor, some banks push passcodes to the app which I find annoying because at least with SMS I could autofill it on my Mac if I’m using Safari. Push notifs / 2FA via app aren’t bad but the fact that you make me open the app just to type in 6 digits to my computer AFTER I’ve bio-authenticated on my phone is annoying af.

Totally agree. The fraud team has good stuff on the roadmap, I don’t know exactly where passkeys fits in the order yet.