Earlier quoted context omitted.
Google Authenticator provides a list of backup codes that you can print and put in your wallet, or store as a secure note (e.g. in 1Password): https://support.google.com/accounts/answer/1187538?hl=en
Google provides backup codes, not Google Authenticator. Each service you add to your Authenticator keychain will have its own backup codes, if any.
Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
101–110 of 225 posts
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#102Earlier quoted context omitted.
If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.
But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#103When I asked (via Twitter) if my credit union would provide a secure 2FA option, they told me: > We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#104Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#105My bank's 2FA literally comes on a piece of paper. A set of numbered codes, and the banking app/site tells me which code to use for any given transfer.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#106Earlier quoted context omitted.
You dont even need to buy a $18 hardware token. You can use a software TOTP token (ie. google authenticator)
So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#107Earlier quoted context omitted.
Note that one time codes do not protect against phishing the same way U2F does (U2F is always bound to secure origin).
U2F is great but everything is better than SMS.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#108One of the newly discovered great sins of the early 21st century, is to disseminate insecure code. Before the public became widely aware of chemical pollution, I'm sure many polluters thought themselves innocent and environmentalists as pernicious busybodies.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#109Earlier quoted context omitted.
U2F is great but everything is better than SMS.
Except SMS is better than nothing, right? Yes it's flawed. But it's a harder attack than simple password auth. An attacker has to to target an individual and know their phone number, and be able to spoof their phone.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#110Earlier quoted context omitted.
If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.
But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…