So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…
It's been proven time and again that cyber criminals frequently target people using SMS 2FA to steal from them. Most implementations of 2FA might as well be 1FA. People might even use worse passwords when they think 2FA protects them.
I think the adoption of SMS as a "universal 2FA" was not worth it. We should've just gotten people used to the less easy but more secure methods. U2F bluetooth keyfob on my keychain would be good enough for my phone and PC. Remote access seems like the hardest nut to crack.