211 ms·
This is the same issue that plagues SMS 2FA. Services constantly treat SMS as 1FA so by sim swapping someone you can get access to their account. If SMS is trul
by pat2man 6y ago
This is the same issue that plagues SMS 2FA. Services constantly treat SMS as 1FA so by sim swapping someone you can get access to their account. If SMS is truly used as 2FA, and is part of MFA, it is a much more reasonable solution. These days most services should probably gather three forms of authentication and require at least two to do anything. Username/password, email, and SMS at a very minimum, with the ability for users to opt in to QR codes or FIDO devices.
It is a good thing that most devices will be shipping with platform FIDO support soon, will make some of this a lot more bearable.