Sms based 2fa is a known crummy 2fa. Get TOTP or a hardware token.
I feel the article is trying to sound smart by using lofty words when the answer really is simpler.
41–46 of 46 posts
Sms based 2fa is a known crummy 2fa. Get TOTP or a hardware token.
I feel the article is trying to sound smart by using lofty words when the answer really is simpler.
Earlier quoted context omitted.
Slower != secure. But secure implies slower. Therefore, fast as possible implies not secure.
So theater. You actually do need to present consistently slow evaluation times when handling encrypted values, as failing fast gives out information that can be used for cracking. But other than that, there usually isn't a good reason to do it.
You could slow your stuff down without securing it in response to the article's idea, but that's not what I was referring to in my comment.
It’s not terribly difficult in case of financial transactions. Just separate into queueing and executing, with an auto-timer, notifications (email, push etc) and an option to cancel directly from the notification channel (without requiring 2FA etc to prevent hijacking issues). This could be applied to other things, like updating an auth factor (change email for instance). Just notify the old email and queue the opera…
> in case of financial transactions The friction is already there. Every single goddamn time I want to transfer more than a few thousand dollars between any of my accounts, it turns into a complete shitshow of bouncing transactions, hunting down reasons, navigating bureaucracy that doesn't want to be navigated, sometimes to the point of looping in authorities (!), and generally burning many hours of my life to get th…
Wise has a way to set rolling limits on things like online purchases and ATM withdrawals. That’s very neat. I think that if you’re say emptying your entire savings, it’s good to have multiple safeguards (and of course being clear about what happens and why).
Earlier quoted context omitted.
Tap-to-pay NFC credit cards Chip and pin or even chip and signature is just too much effort to pay for something
To do this, are they using some kind of modified payment terminal with extended range somehow? My understanding is that the NFC coils have to be very close, like single-digit cm to get any kind of power or data through.
[flagged]