▲ 644 ▼ Feds Warn SMS Authentication Is Unsafe After ‘Worst Hack in Our Nation’s History’ (gizmodo.com) submitted 2 years ago by return2ozma@lemmy.world to c/technology@lemmy.world 158 comments fedilink hide all child comments
[+] umbrella@lemmy.ml 25 points 2 years ago* (last edited 1 year ago) (2 children) [deleted] permalink fedilink source hideshow 4 child comments replies: [–] capital@lemmy.world 14 points 2 years ago (1 child) I assume businesses only jumped at the chance to enable SMS 2FA to get their greedy little fingers on our phone numbers. permalink fedilink source parent hideshow 2 child comments replies: [–] WhatAmLemmy@lemmy.world 2 points 2 years ago It was the simplest/cheapest form of 2FA to implement. Grandma will never understand how to setup TOTP. Capitalism requires regulations, otherwise it will ALWAYS do what is cheapest or most profitable, regardless of how dangerous or destructive. permalink fedilink source parent [–] sugar_in_your_tea@sh.itjust.works 10 points 2 years ago Even stupider is supporting hardware keys for MFA, but having SMS fallback which can't be disabled (looking at you, Vanguard). I'd much rather have email as my second factor than SMS, and I literally abandoned a bank (Ally) for removing email as an alternative to SMS. permalink fedilink source parent
[–] capital@lemmy.world 14 points 2 years ago (1 child) I assume businesses only jumped at the chance to enable SMS 2FA to get their greedy little fingers on our phone numbers. permalink fedilink source parent hideshow 2 child comments replies: [–] WhatAmLemmy@lemmy.world 2 points 2 years ago It was the simplest/cheapest form of 2FA to implement. Grandma will never understand how to setup TOTP. Capitalism requires regulations, otherwise it will ALWAYS do what is cheapest or most profitable, regardless of how dangerous or destructive. permalink fedilink source parent
[–] WhatAmLemmy@lemmy.world 2 points 2 years ago It was the simplest/cheapest form of 2FA to implement. Grandma will never understand how to setup TOTP. Capitalism requires regulations, otherwise it will ALWAYS do what is cheapest or most profitable, regardless of how dangerous or destructive. permalink fedilink source parent
[–] sugar_in_your_tea@sh.itjust.works 10 points 2 years ago Even stupider is supporting hardware keys for MFA, but having SMS fallback which can't be disabled (looking at you, Vanguard). I'd much rather have email as my second factor than SMS, and I literally abandoned a bank (Ally) for removing email as an alternative to SMS. permalink fedilink source parent