Earlier quoted context omitted.
Paypal, an actual bank, still only allows SMS 2fa. It's stupid.
Wrong. TOTP is supported, although hidden.
Personally I wouldn't risk it since it could mean risking getting locked out of your account.
61–70 of 95 posts
Earlier quoted context omitted.
Paypal, an actual bank, still only allows SMS 2fa. It's stupid.
Wrong. TOTP is supported, although hidden.
Personally I wouldn't risk it since it could mean risking getting locked out of your account.
Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
Google has a new account setting called Advanced Protection. All it accepts is two hardware U2F keys (primary and backup) and your password. It supposedly makes your Google account pretty hardened. The only issue is that you can only use Chrome with U2F keys right now because Firefox U2F isn't fully baked yet. I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as…
This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…
They said the best they could do was to add a note to my file to check id in store before transferring.
This is better than nothing, but relies on the CS representative actually seeing the note on my file. Even then, there might be ways around it.
And more importantly, it does noting to stop someone asking another provider to port my number to them. Apparently Inter-provider ports are all automated and there is nothing anyone could do to stop it.
Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything .
Trivial if you have access to an SS7 network that has a direct access or a roaming agreement with the network of the victim, and the proper tools to do that. But you will not manage to do it within 2 minutes if you have.
Earlier quoted context omitted.
If you register your phone nr your password basically get useless as someone can remotely (from another country even) steal your phone number and then reset your password.
That would be one factor, no?
Earlier quoted context omitted.
I ported my Google Voice number to T-mobile about 6 years ago, replacing my main number Great decision as I got to reset my social graph - no services would try to auto-connect me with everyone from high school and college that had data dumped their contacts 10/10
Is it worth it though? Now you can't fully rely on your phone number for 2FA, T-mobile is one of the providers notoriously known for transferring numbers without asking too many information. My daily number, not connected to any 2FA (for which I use Google Voice) is a T-mobile, and a couple years ago I bought a nano sim to replace a larger sim, and the call center operator transferred the number without me having to…
Offering SMS based one time codes - with no OTP protocol alternative - should be considered negligence of the legally sanctionable kind.
and finally who cares about your social graph on Google? Thats not the issue at alllll
Earlier quoted context omitted.
Many of these services, I believe google is one, still require mobile phone as a fallback option.
Paypal, an actual bank, still only allows SMS 2fa. It's stupid.
Earlier quoted context omitted.
The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"
You have no obligation to answer the secure questions truthfully, or not to write a long random string of text... Starting with "Do not accept the answer if I can't spell this exactly" in case a human gets involved...
Earlier quoted context omitted.
Many of these services, I believe google is one, still require mobile phone as a fallback option.
Google requires at least 2 ways of 2fa protection. You can enable a third one and disable the phone completely.
Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything .
Trivial if you have access to an SS7 network that has a direct access or a roaming agreement with the network of the victim, and the proper tools to do that. But you will not manage to do it within 2 minutes if you have.