5 ms·
SMS as 2FA is so stupid. So many banks and financial institutions are doing it in America and it amazes me. I mean what are they spending million of dollars in
by codegeek 5y ago
SMS as 2FA is so stupid. So many banks and financial institutions are doing it in America and it amazes me. I mean what are they spending million of dollars in compliance/security/SOC etc on if they can't get a basic 2FA done correctly ? And don't get me started on stupid password requirements where a more secure password generated in keypass etc won't be valid. Who builds this stuff today ?
- azinman2 5y agoIt provides good security for most people and is a big ease of use trade off. Hardware can be lost, software is difficult for most people to install and use. You need solutions that account for 95% of people. Ideally there’s non SMS for the other 5%, but unless Apple/Google/telcos come out with something better that’s built in, integrated, and dead simple, we’re stuck with SMS for a long time. Security is a spectrum.
- ikiris 5y agosms as 2fa raises the bar signifigantly for non organized attackers. You'd be amazed how much of the meth crowd that encompases.
- vlovich123 5y agoThe challenge I’ve found is that I end up with a lot of different MFA options which makes it hard to track where my exposure is. In some places I have two methods because I set up SMS when it was available and switched to an authenticator app and forgot to turn down SMS. It’s a shame there’s no SSO for personal accounts that established dominance so that I could just have 1 account I need to secure (although SSO solutions never put you in control of being able to minimize data leakage and let providers force you to disclose certain information for using their service).
- mulmen 5y agoCompliance is about liability, not security.