2 ms·
The attack in the article had zero mention of SMS 2FA. They swapped the sim to get access to credit card fraud alerts, delivered via SMS.
by mox1 4y ago
The attack in the article had zero mention of SMS 2FA.
They swapped the sim to get access to credit card fraud alerts, delivered via SMS.
- JohnFen 4y agoMy CC company sends fraud alerts via email as well as SMS. They all should.
- throw101010 4y agoIf they used SMS to identify the customer, isn't it a form of authentification? Having the credit card/credit card info is the first factor and the second factor seems to only have been being able to receive the SMS to confirm it wasn't fraud. I've experienced better banking apps which did use SMS at the initialization, but coupled it with other identifying factors (eg the phone IMEI or a code sent through postal services). If these app needed to be reinstalled the whole verification process would have to be redone.