3 ms·
Any ‘push’ method to an app will end up being more secure than pure SMS 2FA, because it’s relatvely hard to MITM/hijack it, unlike social engineering your way i
by packetized 9y ago
Any ‘push’ method to an app will end up being more secure than pure SMS 2FA, because it’s relatvely hard to MITM/hijack it, unlike social engineering your way into porting a cell number.
- Spivak 9y agoIf you're at the point where your biggest threat is a SE attack on a major cell provider I think you're doing pretty good with security.
- jkaplowitz 9y agoI used to agree, but those attacks are pretty easy to do and have been reported on this site many times. Whereas the other solutions described in the post don't have that attack vector.
- Twisell 9y agoWell it however come with a big con, you become dependent of a third party implementation with dependencies and specifics rules whereas sms is amongst the most used and understood communication standard. This blog post publicise Microsoft implementation but it’s the same problematic for every possible GAFAM specific solution. Apple approach to include a secure and synced password manager in all their product is far more standard friendly approach imho.
- jkaplowitz 9y agoTOTP codes like Google's and Microsoft's apps can use, as well as the U2F security keys, are standardized with multiple implementations in existence. No lock-in with those solutions.
- always_good 9y agoWell, security is only useful when it protects you when you're actually attacked. Social engineering has shown that it's just about effortless to take down someone once they are targeted. It's about as hard to target someone as it is to read their whois address to a customer support rep.
- packetized 9y agoWhat about being targeted for $40k in your 401k? How about your one-or-two-letter Twitter nick? These are things that have actually happened.
- s73v3r_ 9y agoI know I recently got something from T-Mobile asking if I wanted to set up a password that I had to give in order to port my number out. I called up T-Mobile and set it up.
- Buge 9y agoA push method that contains a code, or a push method where you just tap "yes"? Because just tapping yes is much easier to MITM/hijack. The attacker just has to log in at the same time as you're trying to log in, and you will tap accept and let the attacker in.