3 ms·
I would say that for the average user sms 2FA is secure enough. P.S. I might have a different perspective as where i am from, there really aren't important ser
by tooop 7y ago
I would say that for the average user sms 2FA is secure enough.
P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i feel secure enough when using sms 2FA.
- iNate2000 7y agoIt wasn't secure enough for the author of this article.
- tooop 7y agoNot really an average person isn't he?
- mceachen 7y agoHow is he not an average person, as far as security goes? 1) he didn't use a password app 2) he thought google drive was a safe place for his stuff 3) he thought google drive was a secure place for his stuff All three things, which I would bet are fairly common assumptions (the last 2 are certainly part of Google's marketing!), turned out to bite him.
- ijpoijpoihpiuoh 7y agoHe is a public personality and in that role has been related to Bitcoin. And he also has his phone number and email publicly visible on the internet. https://gizmodo.com/a-tv-anchor-tries-to-gift-bitcoin-on-air-is-immediatel-1488636715 https://gizmodo.com/a-tv-anchor-tries-to-gift-bitcoin-on-air... It seems like this only happens to people who have poor opsec about their email addresses, phone numbers, and are publicly related to the cryptocurrency movement. I mean, I'm sure it happens to other people, but that's the only case I've ever heard about. I would personally be wary about publicly listing the email I use with my bank, or my phone number, and I've done what I can to scrub the internet of these values. If you have to be publicly reachable through a medium other than Facebook or Twitter, have a separate email and phone number through which you conduct your serious personal business. But most people do not need this kind of public reachability, or else have it through work. For those types of people, it would behoove them to keep their profile small.
- darkpuma 7y agoBefore the identity theft occurred, what about the the author made him particularly "not average"? Being an early twitter adopter or something?
- baloki 7y agoDepends on what it’s protecting, for example banks using it isn’t, as it’s a common enough attack vector it’s appeared on consumer programs on TV fairly often and they had to introduce a law to allow people to be refunded in cases of sim swap.
- azinman2 7y agoBank of America uses SMS.
- heliodor 7y agoYou're saying that you're safe because you're not an interesting target. People tend to agree that security through obscurity is not a good strategy. As for how hackers can swap someone's SIM, consider: - Does the 20 year old minimum wage employee working at that store know how to spot a good quality fake ID card? - What about hackers bribing an employee?