2 ms·
You know pre-paid burner phones are a reasonable option to harden security at your own pace, right? No one is forcing you to use the same number for everything
by clydesdale 8y ago
You know pre-paid burner phones are a reasonable option to harden security at your own pace, right?
No one is forcing you to use the same number for everything. And don't complain that it's just too expensive and unrealistic to maintain more than one phone number, because that is simply untrue.
Yes, I am aware of NIST's guidelines, regarding SMS as a layer of multi-factor authentication [0]. Those guidelines are for large organizations that dictate user behavior in a top-down hierarchy. Individual security profiles are much more flexible, and don't require the same degree of adherence to recommended practices.
[0] https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
- sgwae 8y agoSeems pretty wasteful solution if everyone maintains a secondary burner phone for login. But it works for the short term, and I would worry about fees, and inactivity cancelations.