Comment on Anon notices what they've taken from us

<- View Parent
drathvedro@lemm.ee ⁨1⁩ ⁨year⁩ ago

2FA is good, but SMS is one of the worst options. SMS is interceptable, fakeable, and requires a phone connected to network, which, by merit of being carried around, is less secure than, say, a PC located at home, behind a closed door, or, even better, a secondary offline PC locked in a safe. TOTP or things like digipass are a lot better. Actually, after writing the above comment, I’ve went to bully my bank to consider adding TOTP as 2FA option, and, in the discussion, they’ve admitted that they’ve had state actors tampering with SMS messages before, hence why they’ve added an additional layer of 4-digit PIN codes on auth, which is dumb, but is telling of how secure SMS messages really are.

source
Sort:hotnewtop