Second factor SMS: Worse than its reputation
1–10 of 323 posts
Re: Second factor SMS: Worse than its reputation
#2Re: Second factor SMS: Worse than its reputation
#3Re: Second factor SMS: Worse than its reputation
#4"CCC researchers had live access to 2nd factor SMS of more than 200 affected companies - served conveniently by IdentifyMobile who logged this sensitive data online without access control."
Instead they bought API access without the leastest of due diligence, putting their customers and their reputation at risk.
Additionally, the merging of different customer’s data by the processor is probably not GDPR-compliant (even if access control was in place).
Re: Second factor SMS: Worse than its reputation
#5"CCC researchers had live access to 2nd factor SMS of more than 200 affected companies - served conveniently by IdentifyMobile who logged this sensitive data online without access control."
Look at the list of customers, most of them should be able to build their own service. Instead they bought API access without the leastest of due diligence, putting their customers and their reputation at risk. Additionally, the merging of different customer’s data by the processor is probably not GDPR-compliant (even if access control was in place).
Isn't the hard prt the connectivity bit i.e. negotiating with the various telcos? I once saw a telco use a third party SMS vendor for messaging their own customers for an app - because setting it up internally was too much of a hassle.
Re: Second factor SMS: Worse than its reputation
#6I hope a day or another people will understand and IMPOSE an end to such crappy unsafe practice.
Re: Second factor SMS: Worse than its reputation
#7The modern auth invented just to push mobile + cloud model is DISGUSTING. We have since decades smart cards for various things, from payments to IDs, why the hell not keep inserting readers in keyboards and laptops bodies, selling cheap desktop USB reader and teach people to use them? Simply because with them there is no way to force mobile computing allowing some third party to snoop a bit in end users lives. I hope…
Re: Second factor SMS: Worse than its reputation
#8The modern auth invented just to push mobile + cloud model is DISGUSTING. We have since decades smart cards for various things, from payments to IDs, why the hell not keep inserting readers in keyboards and laptops bodies, selling cheap desktop USB reader and teach people to use them? Simply because with them there is no way to force mobile computing allowing some third party to snoop a bit in end users lives. I hope…
Many people today don't even own a computer and do everything on their phones. Teaching the masses safe habits rather than convenient ones is a difficult problem, most don't care.
Re: Second factor SMS: Worse than its reputation
#9Re: Second factor SMS: Worse than its reputation
#10The modern auth invented just to push mobile + cloud model is DISGUSTING. We have since decades smart cards for various things, from payments to IDs, why the hell not keep inserting readers in keyboards and laptops bodies, selling cheap desktop USB reader and teach people to use them? Simply because with them there is no way to force mobile computing allowing some third party to snoop a bit in end users lives. I hope…
Many people today don't even own a computer and do everything on their phones. Teaching the masses safe habits rather than convenient ones is a difficult problem, most don't care.