4 ms·
I don't carry around my smartphone, just a nokia. I hate this approach with a passion. Please just send me a text message, or an email to confirm my login as a
by radicalriddler 5y ago
I don't carry around my smartphone, just a nokia. I hate this approach with a passion. Please just send me a text message, or an email to confirm my login as a second factor to my password, and then trust the IP on user decision. Please don't make me use a smartphone app.
- deleted 5y ago[deleted]
- fuzxi 5y agoSMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.
- stan_rogers 5y agoSMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).
- atatatat 5y agoI got 29 hours out of my Pixel last charge.
- perryizgr8 5y ago29 hours is downright disgusting, when compared to feature phones battery life. Some of them have 20-30 days of standby.
- atatatat 5y ago7 hours of that was Hotspot WiFi to two laptops in the park and playing tunes. shrugs
- fuzxi 5y agoNeither does TOTP? There are plenty of desktop applications that support it. I personally use Keepass.
- Dylan16807 5y agoWell TOTP is absolutely trivial and there's no reason a non-smart phone couldn't or shouldn't have support for it too.
- just-ok 5y agoI hear this all the time, but you’re sooo unlikely to be important enough for this to actually matter. And even if it did happen, the attacker would still need your password (and sometimes your phone number) first.
- fuzxi 5y agoOk. It's still a good reason for companies to not support SMS 2FA. Email 2FA or TOTP are miles better.