3 ms·
Use security keys or TOTP. No one should be using SMS based 2FA considering how broken it is (SIM swap attacks). It shouldn't even be an option IMO. I find it
by krmbzds 4y ago
Use security keys or TOTP. No one should be using SMS based 2FA considering how broken it is (SIM swap attacks). It shouldn't even be an option IMO.
I find it quite ironic that the words "Supply Chain Attack" and "SMS-based 2FA" are mentioned in the same blog post. It's like no one made the connection.
- marssaxman 4y agoAnd yet... github will not allow you to avoid this problem: https://github.com/orgs/community/discussions/22500 https://github.com/orgs/community/discussions/22500