this post was submitted on 17 Oct 2024
81 points (98.8% liked)

Technology

59374 readers
6264 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 8 points 4 weeks ago* (last edited 4 weeks ago) (8 children)

Idiot. Why did they not run those searches over the tor network to anonymize themselves? That is quite frankly stupid. And the fact that the SEC was using SMS-based two-factor authentication is also stupid. One time pads or bust motherfuckers.

[–] [email protected] 6 points 4 weeks ago (5 children)

One time pads or bust motherfuckers.

Not sure if you're being facetious, but one time pads are for encryption, not authentication. They're also impractical (and overkill) for most purposes.

[–] [email protected] 4 points 4 weeks ago (4 children)

OTP 2FA Codes are one time pads

[–] [email protected] 5 points 4 weeks ago

Ah, gotcha. Those are one-time passwords. Same acronym, so it's easy to confuse them.

But yeah, I agree that everything should use (T)OTP for two-factor authentication, instead of SMS messages. The later mainly provides a false sense of security and presents only a minor hurdle for attackers to overcome.

load more comments (3 replies)
load more comments (3 replies)
load more comments (5 replies)