Original post: infosec.exchange (glitch-soc (Mastodon fork))

BeyondMachines ( @beyondmachines1@infosec.exchange: "#VibeCoding your MFA". Attached image: a two-factor authentication screen that says "We have just sent the code 435841 to your phone number: xxx-xxx-8247. Please enter the code below to access your account:"
you are viewing a single comment's thread
view the rest of the comments
[–] 0 points 1 year ago

The insecurity of SMS is the inability of telcos to secure number porting. If someone wants to compromise your shit, they can easily steal your phone number, if your phone number is sufficiently public

One defence is to have a second service that is only used for authentication, and never share the number except to those providers that need to message you codes

  • source
  • parent