3 ms·
The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech c
by cbdumas 4y ago
The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech companies start outsourcing their identity verification to cell phone providers those providers come under attack.
- jandrese 4y agoSMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.
- twosdai 4y agoMost users don't know what the words sms or totp mean. I'm not saying that totp isn't easy to implement in the grand scheme of things, but for many people it's not straight forward to setup. Entering a cellphone number and responding to text messages is well known since we've been doing it for 20 something years now. I think totp would probably get more traction with normal users if people started calling it app verification, or something similar eventhough that is slightly incorrect.
- ridgered4 4y agoSMS allows you to collect phone numbers which are quite good at identifying users for tracking and ad targeting though. And since most large tech companies are advertising companies (in whole or in part) it is no surprise they chose this as a second factor. Even if you try to avoid using SMS for 2FA they'll try to collect the number for account verification or recovery, with regular nags or lately go straight to extorting it out of you to continue to access purchased services or software.
- deleted 4y ago[deleted]