3 ms·
I prefer TOTP for privacy and control reasons, but I think you're overselling the disadvantages of SMS here. If you have to find and pay an inside guy to do SIM
by bonton89 3y ago
I prefer TOTP for privacy and control reasons, but I think you're overselling the disadvantages of SMS here. If you have to find and pay an inside guy to do SIM swaps, they'll be limited in the number they can do before getting caught so it really will only be suitable to do targeted attacks on targets you're pretty sure have something worth stealing.
There was a DND that talked about how sim swaps used to be a cakewalk over the phone social engineering exercise but were now kind of expensive to pull off and required a man in a physical location, with T-mobile remaining the easiest target. The black hat guy they were talking to said his first steps were finding a target worth swapping, usually some one that bragged a lot about bitcoin or some other crypto currency on twitter. And getting the phone number was usually really easy to do with a combination of OSINT and abusing the fact services will give you a partially masked phone number when you try to login.
- ssklash 3y agoI agree it's a threat that is not exactly easy to pull off. But my main issue with is is represents an attack vector that you can do exactly nothing to defend against yourself. If you use other forms of MFA, you are at least in charge. Sure you can lose your TOTP seed or something, but you have agency in how it is stored. SMS forces you to rely on companies that have log histories of failing to protect your phone number.