Earlier quoted context omitted.
I think requiring you to be physically present and having a human take the sample in a prescribed manner serves as an effective 'password' - unless it's a live sample, the DNA is useless.
I think there's a misunderstanding of what is possible with DNA[0]. We take DNA from dead stuff all the time. I will agree with "you have to be physically present" is good enough password. This is Yubikey, which works fantastic. The problem with DNA is when it is compromised - you can't throw it away/change it without exorbant effort (bone marrow transplant? and then you're simply taking on someone else's identity? i…
SMS is not 2FA-secure
341–350 of 379 posts
Re: SMS is not 2FA-secure
#342Earlier quoted context omitted.
> Walk into a store and provide a government ID and the original SIM card. This is how it works in Poland since September 2019, after some recent SIM-swap attacks. You can swap SIM or get a replacement if stolen only at store showing government ID. It is free of charge with Orange and not always free with T-mobile. But this has some downsides in real life. 1) I had to walk my 88 yo Mom to the store to swap SIM card.…
The problem is that the ID is still checked by the clerk. They could be bribed or tricked by a fake ID. A recovery code snail-mailed/e-mailed to the account holder when they first open the account is the correct way to go, and if they can't provide it they need to go through a lengthy process where many factors are used to authenticate them (verify their physical address, verify their ID, ask to confirm last call rec…
Re: SMS is not 2FA-secure
#343Re: SMS is not 2FA-secure
#344Earlier quoted context omitted.
Walk into a store and provide a government ID and the original SIM card. If customer doesn’t have the sim/phone, send a recovery code to the billing address on file in lieu of the SIM card.
What if you are abroad? My debit card was recently blocked and I had to wait until I went back, walked in the bank and show my face and ID.
[0] Full disclosure: I work at Twilio and built the first version of the wireless product, so I'm a bit biased.
Re: SMS is not 2FA-secure
#345Earlier quoted context omitted.
Yes, super annoying. Now I can no longer get into my Apple Developer account without walking to my development mac I use to run xcode builds (for a react native app), since for some bizarre reason the only 2FA they support is their own which requires Apple hardware. It's bad enough their development toolchain requires you to buy their hardware, now to log into their websites you also have to buy their expensive hardw…
Apple continues to support SMS as 2FA. It is a bit hidden when signing in.
Re: SMS is not 2FA-secure
#346Re: SMS is not 2FA-secure
#347I wonder how many of these ultra security crazy people lose their accounts because something happens with their login method.
Re: SMS is not 2FA-secure
#348Re: SMS is not 2FA-secure
#349Not in Russia. Numerous examples exist when victim's number was linked to attacker's sim card to obtain 2FA code, then linked back to victim's sim so he does not notice anything. This happened both by government-linked parties, where they are able to coerce providers to do it, mostly targeting prominent political opposition members. It also happened without government involvement, done by provider's personnel with su…
Shitty 2fa will still deter people who get a list of a hundred million emails/usernames and passwords and try them on banks, Twitter etc from putting in the extra work to break into your account specifically.
If you expect targeted attacks - from governments, because you oppose them, from determined criminals, because you have a lot of nice stuff to steal, or from people around you, because you know too many assholes - maybe it might as well not exist, but for most people, most of the time, any 2fa is better than none.
Re: SMS is not 2FA-secure
#350Earlier quoted context omitted.
The problem is that the ID is still checked by the clerk. They could be bribed or tricked by a fake ID. A recovery code snail-mailed/e-mailed to the account holder when they first open the account is the correct way to go, and if they can't provide it they need to go through a lengthy process where many factors are used to authenticate them (verify their physical address, verify their ID, ask to confirm last call rec…
You can require the clerk to note the document ID to avoid bribery.