Comment on Millions of people imperiled through sign-in links sent by SMS

<- View Parent
irotsoma@piefed.blahaj.zone ⁨2⁩ ⁨days⁩ ago

How so?

It’s a second factor. It’s “something you know”, “something you have”, and/or “something you are”. The username and password is the “something you know” and the sms message is “something you have” (I.e. the phone). There’s no need for the second factor to be secret as long as it is single use and time sensitive and is only used as a second factor, not the only factor.

This article was about single factor messages that are the entirety of the login flow, so not about 2FA, but I’m still interested in the concerns for second factor. It is still adding security over a password alone which is the only goal in the 2FA subject.

source
Sort:hotnewtop