▲ 644 ▼ Feds Warn SMS Authentication Is Unsafe After ‘Worst Hack in Our Nation’s History’ (gizmodo.com) submitted 2 years ago by return2ozma@lemmy.world to c/technology@lemmy.world 158 comments fedilink hide all child comments
[–] shortwavesurfer@lemmy.zip 66 points 2 years ago (1 child) Been saying that for years. It's about damn time. permalink fedilink source hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 17 points 2 years ago (2 children) SMS spoofing and SIM swapping have been around for ages. It was never secure and that's always been known. The number of companies that rely on it despite sending me a zillion other fucking useless emails is too damn high! Email, or better yet, an authenticator app, are far more secure. Not perfect, but better. permalink fedilink source parent hideshow 4 child comments replies: [–] shortwavesurfer@lemmy.zip 5 points 2 years ago (1 child) One big reason I'm hesitant to keep my money in banks is because banks think the best form of two-factor authentication is text message based 2FA and I'm like that's barely any 2FA at all. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 6 points 2 years ago (1 child) My banks are like that too. Of course I can't speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 4 points 2 years ago (1 child) I keep my money in Monero. That way, it's me who has to be targeted instead of an institution. And if I fuck up and lose it, it's my own damn fault. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn't there yet. Maybe someday... But having money distributed is still smart either way, so I have many baskets for my eggs. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Wait, how is email more secure than SMS? permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) https://en.m.wikipedia.org/wiki/SMS_spoofing So, it's not that the message itself is insecure, but the inability to verify the sender makes phishing attacks possible or similar things. I get a text from a random number saying "click this link to pay your bill!" And I don't have any way to trust its legit. SIM swaps make it so people can take over your phone number temporarily and then generate 2fa requests to gain access to accounts. Doing the swap usually involves bribing someone or gaining access to a providers database by other means, but its been done a lot. There are ways to prevent this, but the most straight forward is using a MFA app. Barring that 2FA via email is the next best thing. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Forgive my ignorance, aren't emails sent in plain text that can be read by any of the networks they are passed between? I've always been taught email is the least secure of any communication. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I'm not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That's not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] Screen_Shatter@lemmy.world 17 points 2 years ago (2 children) SMS spoofing and SIM swapping have been around for ages. It was never secure and that's always been known. The number of companies that rely on it despite sending me a zillion other fucking useless emails is too damn high! Email, or better yet, an authenticator app, are far more secure. Not perfect, but better. permalink fedilink source parent hideshow 4 child comments replies: [–] shortwavesurfer@lemmy.zip 5 points 2 years ago (1 child) One big reason I'm hesitant to keep my money in banks is because banks think the best form of two-factor authentication is text message based 2FA and I'm like that's barely any 2FA at all. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 6 points 2 years ago (1 child) My banks are like that too. Of course I can't speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 4 points 2 years ago (1 child) I keep my money in Monero. That way, it's me who has to be targeted instead of an institution. And if I fuck up and lose it, it's my own damn fault. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn't there yet. Maybe someday... But having money distributed is still smart either way, so I have many baskets for my eggs. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Wait, how is email more secure than SMS? permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) https://en.m.wikipedia.org/wiki/SMS_spoofing So, it's not that the message itself is insecure, but the inability to verify the sender makes phishing attacks possible or similar things. I get a text from a random number saying "click this link to pay your bill!" And I don't have any way to trust its legit. SIM swaps make it so people can take over your phone number temporarily and then generate 2fa requests to gain access to accounts. Doing the swap usually involves bribing someone or gaining access to a providers database by other means, but its been done a lot. There are ways to prevent this, but the most straight forward is using a MFA app. Barring that 2FA via email is the next best thing. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Forgive my ignorance, aren't emails sent in plain text that can be read by any of the networks they are passed between? I've always been taught email is the least secure of any communication. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I'm not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That's not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] shortwavesurfer@lemmy.zip 5 points 2 years ago (1 child) One big reason I'm hesitant to keep my money in banks is because banks think the best form of two-factor authentication is text message based 2FA and I'm like that's barely any 2FA at all. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 6 points 2 years ago (1 child) My banks are like that too. Of course I can't speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 4 points 2 years ago (1 child) I keep my money in Monero. That way, it's me who has to be targeted instead of an institution. And if I fuck up and lose it, it's my own damn fault. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn't there yet. Maybe someday... But having money distributed is still smart either way, so I have many baskets for my eggs. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent
[–] Screen_Shatter@lemmy.world 6 points 2 years ago (1 child) My banks are like that too. Of course I can't speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 4 points 2 years ago (1 child) I keep my money in Monero. That way, it's me who has to be targeted instead of an institution. And if I fuck up and lose it, it's my own damn fault. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn't there yet. Maybe someday... But having money distributed is still smart either way, so I have many baskets for my eggs. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent
[–] shortwavesurfer@lemmy.zip 4 points 2 years ago (1 child) I keep my money in Monero. That way, it's me who has to be targeted instead of an institution. And if I fuck up and lose it, it's my own damn fault. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn't there yet. Maybe someday... But having money distributed is still smart either way, so I have many baskets for my eggs. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent
[–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I have some crypto, some stocks, etc. For many things I still need standard banking though. Crypto just isn't there yet. Maybe someday... But having money distributed is still smart either way, so I have many baskets for my eggs. permalink fedilink source parent hideshow 2 child comments replies: [–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent
[–] shortwavesurfer@lemmy.zip 1 point 2 years ago I keep a little bit in the bank, like enough to pay my bills and such, but any extra I put into Monero. permalink fedilink source parent
[–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Wait, how is email more secure than SMS? permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) https://en.m.wikipedia.org/wiki/SMS_spoofing So, it's not that the message itself is insecure, but the inability to verify the sender makes phishing attacks possible or similar things. I get a text from a random number saying "click this link to pay your bill!" And I don't have any way to trust its legit. SIM swaps make it so people can take over your phone number temporarily and then generate 2fa requests to gain access to accounts. Doing the swap usually involves bribing someone or gaining access to a providers database by other means, but its been done a lot. There are ways to prevent this, but the most straight forward is using a MFA app. Barring that 2FA via email is the next best thing. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Forgive my ignorance, aren't emails sent in plain text that can be read by any of the networks they are passed between? I've always been taught email is the least secure of any communication. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I'm not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That's not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) https://en.m.wikipedia.org/wiki/SMS_spoofing So, it's not that the message itself is insecure, but the inability to verify the sender makes phishing attacks possible or similar things. I get a text from a random number saying "click this link to pay your bill!" And I don't have any way to trust its legit. SIM swaps make it so people can take over your phone number temporarily and then generate 2fa requests to gain access to accounts. Doing the swap usually involves bribing someone or gaining access to a providers database by other means, but its been done a lot. There are ways to prevent this, but the most straight forward is using a MFA app. Barring that 2FA via email is the next best thing. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Forgive my ignorance, aren't emails sent in plain text that can be read by any of the networks they are passed between? I've always been taught email is the least secure of any communication. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I'm not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That's not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] frostysauce@lemmy.world 2 points 2 years ago (1 child) Forgive my ignorance, aren't emails sent in plain text that can be read by any of the networks they are passed between? I've always been taught email is the least secure of any communication. permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I'm not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That's not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] Screen_Shatter@lemmy.world 3 points 2 years ago (1 child) I'm not a security expert so my ability to explain is limited, but no, emails have long used encryption protocols like SSL to prevent such problems. However, your email provider may scan and read your emails. That's not much different than a text message service reading those messages, but you can choose your provider. From what I can tell proton.me is the way to go for resolving that issue - they provide encryption which prevents their own machines and employees from being able to read your messages and other data. Otherwise, your email is basically as secure as your passwords are. permalink fedilink source parent hideshow 2 child comments replies: [–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] frostysauce@lemmy.world 2 points 2 years ago (1 child) OK, I had no idea what I was talking about, lol. Thanks for responding! permalink fedilink source parent hideshow 2 child comments replies: [–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent
[–] Screen_Shatter@lemmy.world 2 points 2 years ago No prob, this stuff is difficult to keep up with. I'm still always learning and hoping I'm doing it right permalink fedilink source parent