Earlier quoted context omitted.
Do you happen to know if they allow you to also totally disable SMS 2FA? I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).
I believe you can remove SMS fallback now on Vanguard.
Hackers claim they breached T-Mobile more than 100 times in 2022
331–340 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#332Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#333Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#334Earlier quoted context omitted.
As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…
Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#335Earlier quoted context omitted.
> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. I gotta admit, that's pretty clever. Crude, but effective.
Another common technique is a filter to forward all mail. Hard to notice. I ought to go check right now...
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#336Earlier quoted context omitted.
It’s a notification pop-up the Google mobile app can send, asking for login confirmation.
I see, but doesn't have the same issue as sending an SMS to the phone if the phone has been stolen in that the thief can just say "yes" to the prompt?
A stolen phone can of course be a problem as well, but at least it's somewhat under my control and I may notice pretty quickly when it's gone.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#337Earlier quoted context omitted.
Should we throw the President in jail if the government gets breached?
no, of course not. (nice straw-man attempt, btw) Just the way boards of companies have fiduciary duty, there should be some of sort customer information protection duty that companies are responsible / liable for. basic security practices are being neglected at far too many companies.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#338Earlier quoted context omitted.
How would you know unless you check your credit card statement every day?
FWIW, some banks will let you setup email alerts for when your cc is used, or used over a certain threshold.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#339Earlier quoted context omitted.
Google Voice isn't a wireless carrier. VoIP only.
This is part of my question. How does Google provision VoIP numbers? When someone calls / texts a VoIP number from a normal number, that call / SMS travels over normal wireless infrastructure. So VoIP numbers are still connected to the same infra, right?