4 ms·
The beauty of it is cases like Google's. They have this bizarre 2FA security-theater Google Authenticator thing, but then nearly force everyone to have their ph
by notzorbo3 9y ago
The beauty of it is cases like Google's. They have this bizarre 2FA security-theater Google Authenticator thing, but then nearly force everyone to have their phonenumber as a "backup device".
Guess what the send you when you forget your 2FA or password? Yep, an SMS. So out the door goes the whole point of 2FA. Your three factors (account name / email address + password + Google Authenticator) have now been reduced to one factor: your email address.
I can rent a mobile tower in Malaysia or some other asian country, advertise your phonenumber as roaming there for about €10/h and start intercepting all your shit. Or just get your telco's inept service dept to forward your number somewhere else.
Lessons here:
1. Even the giants get it wrong.
2. There is no security anywhere in the tech world. Literally everything is broken. Your electronic car locks / starter system, your phone, your internet, everything is horribly horribly horribly broken beyond any imagining, even for hyper-tech savvy people.
3. Remove your phonenumber as a backup device from your google account and never use it as a backup device every again.
- walrus01 9y agohttps://medium.com/message/everything-is-broken-81e5f33a24e1 https://medium.com/message/everything-is-broken-81e5f33a24e1
- karlshea 9y agoOnce you add another factor you can remove SMS from your Google account. I’ve done it with all of mine. Edit: Oh, you said that.
- hirsin 9y agoI just removed my SMS from Google auth, thanks! And set up an Authenticator (Azure). I would like to see a world where we start removing SMS (and old passwords) from existing accounts.