Original post: infosec.exchange (glitch-soc (Mastodon fork))

BeyondMachines ( @beyondmachines1@infosec.exchange: "#VibeCoding your MFA". Attached image: a two-factor authentication screen that says "We have just sent the code 435841 to your phone number: xxx-xxx-8247. Please enter the code below to access your account:"
you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 1 year ago

Spear phishing disagrees with you.

If you're targeting a specific individual, cloning their SIM or performing another number hijack or even intercepting their SMS in flight, are all viable.

For broader, more general attacks SMS is usually enough to keep anyone out.

  • source
  • parent