5 ms·
2FA based on mobile phones is a very weak method of security. It goes worse, when using smartphones. When you use your smartphone to access internet services (w
by PythonicAlpha 12y ago
2FA based on mobile phones is a very weak method of security. It goes worse, when using smartphones. When you use your smartphone to access internet services (worse: make banking) secured by 2FA, your 2FA is reduced to 1FA, Trojaner prone security.
There are also already cases known, where attackers just made phone companies send a "replacement" sim card and the attackers intercept those. Thus the second factor was very simple out. Some phone companies are more aware now, but all is very much prone to social engineering.
So: 2FA is only a good idea, when using some dedicated device, else it just makes the barrier a little higher, sometimes not so much, as you think.
- Oletros 12y agoWhy a 2FA based on mobile phones using Authenticator app is a very weak method?