4 ms·
I think the point of the article was to spook the non tech crowd into moving away from SMS based 2FA. Obviously the tech crowd has known for a long time but mos
by jacoblambda 8y ago
I think the point of the article was to spook the non tech crowd into moving away from SMS based 2FA. Obviously the tech crowd has known for a long time but most other people are oblivious to all of this.
- jchw 8y agoReally? They mention YubiKey but it seemed to me like they just lumped it in with less effective SMS 2FA.
- sgustard 8y ago> Obviously the tech crowd has known for a long time Who else but the "tech crowd" implements SMS 2FA on these websites? What does it say about our industry if we're pushing solutions we know to be flawed?
- scrollaway 8y agoIt's not about who implements it, it's about who pays to implement it and gives the orders. The tech crowd isn't implementing SMS 2FA for fun. They're doing so because the manager is like "wait what! they'd need to install an app? but we can just use SMS! I don't care what you say about it being insecure, it's still more secure than not having it!" What's the fix? I mean for fucks sake, naming & shaming companies doesn't ever work for security stuff. It doesn't even work for getting https on login forms; it's not like it's easy to push through the nuances of SMS 2FA's security issues. Or even tech stuff in general. I just moved to Belgium and half the national services here don't know how to dial an international phone number, don't support + or 00 at the beginning of phone number inputs, etc. There is no end to how technologically illiterate services can be. And yet, it's still "the tech crowd" implementing all these things. We need to find a way to push these obvious fixes through, but as far as I know, short of reporting the issue and crossing your fingers someone relevant hears it, it's not possible.
- rebuilder 8y agoFixing it seems like a tough task. At first glance, somehow requiring tech vendors to work not to fulfill the customer's technical specs, but their actual real-world needs, seems necessary. But all other problems aside, if the customer doesn't have the knowhow to specify their needs in the first place, that's a tough task. Maybe it would have to be a combination of bolstering the buyer side's in-house technical understanding and legally requiring providers to commit to delivering the product their customer needs, not the one they say they want. I wouldn't want to try to formulate that into concrete legislation, though. It would be an enormous change, and I'm not sure what we'd end up with if we tried that.
- cwyers 8y agoThe "tech crowd" tends to implement what the business asks them to implement, like you said. In the case of security, fixing it is straightforward -- there's a large enough amount of fines for breaches where customer data was leaked to a third party where any company would either implement really good security or hire out to platforms that could do it. It's not easy, because there's not a lot of people in government who have incentives to make that happen.
- gsich 8y agoStill better then nothing.