These places need to stop using SMS for 2FA.
You didn't provide a secure and practical alternative, please enlighten people unaware of them.
Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
11–20 of 312 posts
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#12If we want to authenticate a user, what is the best way to do it? best: a great balance between convenience, security and cost. Lately, it bothers that we cannot be sure that we are interacting with real people or the people that we are interacting with are not the same people with different accounts.
If I have 2 accounts, and you can tell that they're both me, doesn't that compromise my privacy?
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#13This is why SMS should be never an option for MFA. You simply cannot rely on a telco employee for the security of your organization or online presence.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#14These places need to stop using SMS for 2FA.
You didn't provide a secure and practical alternative, please enlighten people unaware of them.
WebAuthn uses FIDO Security keys, relatively cheap USB or Bluetooth devices or sometimes just a built-in feature of a smartphone, to authenticate. They are Something-You-Have, but the WebAuthn protocol also offers:
* Optionally a mode where you give the FIDO key a PIN (Something-You-Know) or biometric input (Something-You-Are) to do all the authentication locally
* Phishing proof - there's no decision about whether this is really your bank. WebAuthn is completely happy to log you into https://fake.bank.phishingsite.example/ but the credentials are useless to the crooks who own that site because they won't work on https://your.actual.bank.example/ even if the crooks got the logo just exactly right and wrote a very convincing pleading email from your bank saying they definitely need you to go to the fake bank site.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#15Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#16How does this work? The sim-card is sent to your own address, in a plain white envelope.They have to steal that envelope to gain physical access to the sim. Why is it so hard to stop sending sim-cards to different addresses than the main address where it was registered?
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#17Well, MAYBE, just maybe Twitter should stop require new users to enter their phone number in order to validate their account.