Comment on Millions of people imperiled through sign-in links sent by SMS
irotsoma@piefed.blahaj.zone 1 day agoExactly, so it does that job because it requires an entirely different and complex skill-set to intercept sms messages and you have to do both things now if sms 2FA is in place. With the issue in the article you dont even need to intercept sms meant for a particular user to get access to random users’ accounts, thus totally different issue.
I asked, what is better for a second factor than SMS?
artyom@piefed.social 1 day ago
It does, really poorly, for the reasons I’ve listed, and for the reasons in the OP.
Not a different issue at all. Exact same issue, with lower risk.
I answered this like 12 comments ago.
We’re going around in circles now so I’ll bid you good night.