this post was submitted on 16 Sep 2023
-10 points (43.6% liked)

Memes

45655 readers
1632 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 
  • fucking annoying
  • can't believe they sold people that it's BETTER to have to get your phone out to login
  • incredibly annoying
  • if you're using this willfully you're clearly just as worried about security as before anyway
  • companies love having real phone numbers to pair with 'their' data
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 1 year ago (7 children)

I don't think thats necessarily true. If diverting phonecalls were so easy there are a bunch of reasons outside of two factor attacks that it would be used for.

[–] [email protected] 1 points 1 year ago (6 children)

There actually are lots of things it's been used for in addition to stealing 2FA codes. SMS based 2FA is better than no 2FA at all, but it's insecure and not recommended to be used when dedicated authenticators are available instead. The NIST has warned against their use since 2016.

[–] [email protected] 1 points 1 year ago (5 children)

you seem to be limiting it to sms. you do realize your talking to a person who mentioned microsofts option to call you and you hit pound. They actually have an app where you input a two digit number and if anything I would have liked them to expand the phone call function with that. Anyway I was not speaking about sms but I still feel the vulnerabilities are overblown when used with a good password.

load more comments (4 replies)
load more comments (4 replies)
load more comments (4 replies)