3 ms·
SMS 2FA never should have been deployed. It's a disaster and we'll be cleaning up this mess for decades.
by staticassertion 4y ago
SMS 2FA never should have been deployed. It's a disaster and we'll be cleaning up this mess for decades.
- winternett 4y agoEven before all the robo-call Armageddon started, I was getting flooded with calls whenever I logged into Azure, which was the first time I was required to use 2FA. I would get calls from strange sources literally seconds after authenticating. Even trusted companies really dont need that private data. Secure email accounts better and use it. That way mis-use of it on government resources at least would carry harsher penalties. We should have established an email service within the postal service for every citizen, that would also regulate misuse and spam better... I wrote about it long ago, it should have been in place by now instead of corp run services being used for PII things. Gmail, Google, and many other corp run services are being used for very critical and sensitive things (Not referring to contracted services) that never should be the case.
- fragmede 4y agoIt's true the publicized SS7 attacks brought forwards the timeline with which SMS based auth should be deprecated, but "never should have been deployed" is a bit much. There simply wasn't the infrastructure to support anything else. Hardware RSA SecurID keys from the 90's wouldn't have scaled.
- staticassertion 4y agoWhen Twitter implemented its SMS 2FA TOTP was already standard.
- ASalazarMX 4y agoYes, but those sweet phone numbers are a valuable targeting product.