3 ms·
I don't think it was up to Reddit. Some providers offer no way to do MFA without mandatory SMS involvement in some way -- either primary delivery is by SMS or
by aroch 8y ago
I don't think it was up to Reddit. Some providers offer no way to do MFA without mandatory SMS involvement in some way -- either primary delivery is by SMS or you can "reset" / get back up codes via SMS.
- dbg31415 8y agoLooking at you, LinkedIn. Microsoft has been lax on this.
- robohoe 8y agoMany major banks do that too.
- hackinthebochs 8y agoI've been interested in enabling MFA on my google account, but with no obvious way to bypass/disable SMS, I don't even bother.
- wolf550e 8y agoLook at step 18 in this guide: https://techsolidarity.org/resources/security_key_gmail.htm https://techsolidarity.org/resources/security_key_gmail.htm
- Alex3917 8y agoBecause of cases like this, it's also the admin's responsibility to have their wireless provider put a security pin and a Do Not Port order on their account. Sometimes reps will ignore this and port people's accounts anyway, but it's still negligent not take this precaution.
- aroch 8y agoPhone company reps are notorious for ignoring any and all such notes on accounts, we can't know for sure if Reddit had this in place but it probably wouldn't be much of a hurdle
- shakestheclown 8y agoIt does sound like they used TOTP when possible but in some instances only SMS was available. My issue is that they seem to act surprised that SMS is so broken. I have trouble believing that any admins of a site that large have missed the various security alerts and news articles about hacked accounts, lost cryptocurrency, etc.