I messaged my bank and they were unable to opt me out of it….
Comment on Millions of people imperiled through sign-in links sent by SMS
artyom@piefed.social 3 days ago2FA via SMS is a perfectly fine solution
Completely disagree
sem@piefed.blahaj.zone 2 days ago
artyom@piefed.social 2 days ago
Same. Most of them don’t allow it.
irotsoma@piefed.blahaj.zone 2 days ago
How so?
It’s a second factor. It’s “something you know”, “something you have”, and/or “something you are”. The username and password is the “something you know” and the sms message is “something you have” (I.e. the phone). There’s no need for the second factor to be secret as long as it is single use and time sensitive and is only used as a second factor, not the only factor.
This article was about single factor messages that are the entirety of the login flow, so not about 2FA, but I’m still interested in the concerns for second factor. It is still adding security over a password alone which is the only goal in the 2FA subject.
artyom@piefed.social 2 days ago
All of the same reasons for single factor also apply to MFA.
It’s also dependent on other services, is a privacy violation, and a giant fucking pain in the ass if you ever want to change your phone number, or like me, you have service issues.
There are many other alternate, more secure, more convenient, more resilient options.
irotsoma@piefed.blahaj.zone 2 days ago
Problem is finding something that is universal that is a “something you have” is difficult to find that almost everyone has. Almost everyone has a cell phone these days, so it’s a good option to use as that kind of factor. Email is a second “something you know” factor (I.e. via the password to your email account) and could be the same something if you use the same password. And getting someone to carry yet another device even if it’s simple like a Yubikey or something like that can be difficult. And unless biometric devices become universal on computers as well as phones, the “something you are” factor is hard to accomplish universally as well.
So, what options do you think are better that can be a “something you have” for use as a second factor to a password or other type of “something you know” factor?
artyom@piefed.social 2 days ago
TOTP or passkey are my preferred MFA options