2 ms·
The only thing that's bothering me is that it is done through e-mail. I would prefer the token to arrive as a text message to my phone number. I feel like it is
by danijelb 10y ago
The only thing that's bothering me is that it is done through e-mail. I would prefer the token to arrive as a text message to my phone number. I feel like it is safer and faster. However, I understand that it is more expensive option, especially for services where you need to log in multiple times, compared to mobile apps where you log in only once.
- consp 10y agoSMS (in it's classical form) is highly spoofable as has been proven with TAN codes time-and-time again. It will work most of the time (sms has no guarantee of delivery as far as I know) and is somewhat secure but by no means good in any way. This relies on email, which is highly secure, smtp is not spoof-able, server and mail origins are traceable and verifiable and there is no way to intercept the message on a malicious router/switch whatever. Ow wait ...