A hacker got all my texts for $16
1–10 of 296 posts
Re: A hacker got all my texts for $16
#2Re: A hacker got all my texts for $16
#3Re: A hacker got all my texts for $16
#4SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.
Re: A hacker got all my texts for $16
#5SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.
"2 Factor" isn't the right word choice. SMS isn't being used as a second factor here; it's the only factor.
and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph
Re: A hacker got all my texts for $16
#6Re: A hacker got all my texts for $16
#7Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .
Unfortunately, big parts of the industry seem to be headed the other direction.
Re: A hacker got all my texts for $16
#8Earlier quoted context omitted.
"2 Factor" isn't the right word choice. SMS isn't being used as a second factor here; it's the only factor.
"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph
The problem is purely with how some companies are applying SMS as an auth factor. In cases where SMS us being used as a recovery factor, it should not be allow for immediate recovery. Instead the user should be notified via other channels (email, phone notifications) about the recovery attempt, be given the opportunity to reject it, and for the recovery to only succeed if it is not denied after e.g. 3 days.
Re: A hacker got all my texts for $16
#9Re: A hacker got all my texts for $16
#10How do you protect against this type of attack?
Lucky's company has this product that can monitor for the attack, but it won't prevent it: https://okeymonitor.com/