Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Millions of people imperiled through sign-in links sent by SMS

⁨41⁩ ⁨likes⁩

Submitted ⁨⁨5⁩ ⁨days⁩ ago⁩ by ⁨along_the_road@beehaw.org⁩ to ⁨technology@beehaw.org⁩

https://arstechnica.com/security/2026/01/millions-of-people-imperiled-through-sign-in-links-sent-by-sms/

source

Comments

Sort:hotnewtop
  • artyom@piefed.social ⁨4⁩ ⁨days⁩ ago

    This is a crazy problem. Even Apple requires you to use SMS 2FA, and does not let you opt out or use any alternatives.

    My employer uses this as well and I was locked out (couldn’t do any work) for an entire day because their SMS messages were not being delivered.

    source
    • irotsoma@piefed.blahaj.zone ⁨3⁩ ⁨days⁩ ago

      2FA isn’t the issue. The issue is single factor logins with only text messages, no password and often no username. Those messages allow anyone who intercepts them to login, no username or password is involved at all.

      2FA via SMS is a perfectly fine solution, though there are more secure options like yubikeys or TOTP generation apps.

      source
      • artyom@piefed.social ⁨3⁩ ⁨days⁩ ago

        2FA via SMS is a perfectly fine solution

        Completely disagree

        source
        • -> View More Comments