6 ms·
SMS 2fac to a google voice account with 2 fac
by hansolosays 5y ago
SMS 2fac to a google voice account with 2 fac
- latchkey 5y agoStill not secure.
- neatze 5y agoWhy ?
- ARCarr 5y agohttps://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-16-dollars-sakari-netnumber https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
- Hnrobert42 5y agoThat is SMS hijacking. That’s why @epitom3 says 2FA with an app.
- irq 5y agoAll SMS 2FA is insecure by design / default
- neatze 5y agoWith one big assumption attacker know you 2FA SMS number, it is not hard to have second number.
- nikanj 5y agoBecause you can keep dialing customer service with various stories. ”A shark ate my phone”. ”It’s my husbands account. A shark ate him and I want to post a funeral invitation on his page”. Just keep dialing, and you’ll find a compassionate and helpful person at some point
- gambiting 5y agoFor that reason I'm very happy I'm with Giffgaff in the UK - they literally don't have any telephone based support. If you need support you need to message them.....from your account online. Oh and any request to transfer the number takes at least a few days to go through, and you get notification that it's happening - same if you are being sent a replacement SIM. I imagine a number takeover attack would be very difficult due to this.
- neatze 5y agoThis assuming you know my SMS 2FA number, it not not that expensive to have second phone number and second sim on a phone.
- nikanj 5y agoJust start the phone tour from the Instagram support line. ”My son was abducted by sharks, and I need to dial my wife. Which of her phones did she use for her Instagram?” Again, the kindness, compassion and flexibility of humans is the weak link in security. I bet that’s why Google has all but eliminated the support staff!
- Epitom3 5y agoalways use 12-18 digit random passwords and an authenticator app for 2fa.
- path411 5y agoIf you are using a random password generator, don't be doing 12 character lol. Do 20+
- wohfab 5y agoYeah, true. I do 64 on default, except the service doesn't allow it, then I'll do the max allowed characters.
- jspash 5y agoBe care with that! I've created accounts in the past with a 40+ random character password and everything went swimmingly. Until I tried to log in. Bzzzt! Couldn't get in. Apparently the password had a character limit that wasn't mentioned when signing up and was silently truncated server-side. A bit of investigation showed the <input> had maxlength="20" which is only enforced when typing characters. When using Javascript to fill a form will just ignore this attribute. https://codepen.io/jspash/pen/XWerVzY https://codepen.io/jspash/pen/XWerVzY
- zo1 5y agoI've noticed my bank doing shenanigans in order to prevent password managers from working well. It appears to be JS scripts that uppercase or lowercase the input field after posting but before the browser saves it. So it perpetually looks like I'm updating my password when I'm not. It literally just got populated by the browser.
- tossaway9000 5y agoWhat is the deal with banks being actively hostile to password managers? One bank specifically I have to deal with will: - Not allow you to paste a username/password (ctr+c/ctrl+v, right click disabled) - Lastpass autofill doesn't work - If the page loses focus, both user/password inputs are cleared, you get to start all over. There is also a very small subset of special characters that are allowed. If you do not reset your password as often as they'd like, you have to agree to waive any responsibility for any issues with your account before logging in. SMS 2FA required, there's no other 2FA option. After entering your 2FA code, the "proceed" and "cancel" buttons are the exact same shape and color and I've hit the wrong one multiple times, in which case there is also SMS 2FA cool down and you have to wait 15 mins to start all over again. It's absolute insanity and every time I have to login its an adventure.