3 ms·
The concern is that in the 2 seconds it takes me to type the password in someone will intercept it and beat me to it? This is way safer than email.
by javery 14y ago
The concern is that in the 2 seconds it takes me to type the password in someone will intercept it and beat me to it? This is way safer than email.
- apawloski 14y agoI don't understand why you downvoted me -- my point is perfectly valid. "The concern is that in the 2 seconds it takes me to type the password in someone will intercept it and beat me to it?" The concern is that someone will snoop the password before it even gets to your phone. SMS snooping/MiTM has been demonstrated before [1]. Time-Based One-time Password algorithms are safer because they are not vulnerable to the aforementioned probems -- they never touch the network. "This is way safer than email." I never said it wasn't? [1] http://en.wikipedia.org/wiki/IMSI-catcher http://en.wikipedia.org/wiki/IMSI-catcher
- javery 14y agoI didn't down vote you.
- peterwwillis 14y agoIt's a matter of how comfortable you are with someone having access to your bank account. If you believe it's unlikely anyone will ever either A. work for a telecom company, or B. build an OpenBTS base station, while also C. try to get into your bank account, then you shouldn't worry. If you believe it's unlikely anyone will ever A. work for an ISP or other mail relay, or B. sniff traffic on a network segment that an unencrypted mail relay runs on, while also C. try to get into your bank account, then you shouldn't worry. Now then. If you think both of those are likely to happen, you can simply use a one-time pin program on a phone (or a keyfob -- much more secure than on a phone) and neither of the two attacks will be possible, thus your bank account will be more secure. It's only a matter of how much you care about your bank account. If you care enough you won't use e-mail or SMS. If you don't care, then whatever happens, happens.