75
submitted 1 week ago by HiddenLayer555@lemmy.ml to c/canada@lemmy.ca

cross-posted from: https://lemmy.ml/post/46348914

TIL your phone apparently does no or easily spoofed authentication of the identity of the base station it decides to connect to. Anyone know more about this and how it's possible?

you are viewing a single comment's thread
view the rest of the comments
[-] snoons@lemmy.ca 30 points 1 week ago

I have zero trust in any company that uses 2FA over SMS.

[-] Reannlegge@lemmy.ca 4 points 1 week ago

A few years ago all banks were supposed to move to that, I was so unhappy with that. I sent so many emails to my back bencher do nothing MP the heads of the financial institutions I was using complaining about this saying how easy it was to spoof text messages or high jack peoples numbers, I considered doing some of the spoofing to them but decided better not.

Yesterday, or the day before, my Credit Union started offering TOTP I was so giddy and excited! I figured out how to add all my keys that I was using in Raivo, because the app has sorta gone to poop town, onto my self hosted Vaultlocker. You cannot believe how happy I was today the first time I needed to use one of those numbers and I was able to open up Bitlocker on my phone and use the number today.

My place flooded so a little more than half of my one level is to the sub floor my office has a lot off “stuff” stuff into it and I have been living out of my bedroom, home labing went from a hobby to something to keep me sane.

[-] HellsBelle@sh.itjust.works 11 points 1 week ago

My bank (RBC) does, but luckily they also give me other options to choose from.

[-] snoons@lemmy.ca 11 points 1 week ago

Tangerine doesn't, and they also can't get their website to work on firefox lol.

[-] phoenixz@lemmy.ca 5 points 1 week ago

If your website requires a specific browser then you do websites wrong

[-] iamthetot@piefed.ca 4 points 1 week ago

I've never had a problem with their website on Firefox. What issues do you have?

[-] snoons@lemmy.ca 2 points 1 week ago

It says the service is unavailable after entering my username/account numbers.

[-] dudesss@lemmy.ca 3 points 1 week ago

Should work. Although I've had authentication problems with Tangerine with Chrome and Firefox.

[-] HellsBelle@sh.itjust.works 3 points 1 week ago

Damn. That sucks.

[-] HiddenLayer555@lemmy.ml 8 points 1 week ago* (last edited 1 week ago)

TOTP is both more secure and cheaper to implement since you don't have to pay for text messages or directly communicate with the 2FA device in general. Honestly whenever some obsecure app or website demands my phone number as the only 2FA option I immediately assume it's a front to get my phone number for data brokerage. Like no way does a random online game or something care so much about security to demand 2FA but then proceed to choose the least secure and hardest to implement option. There's another reason.

this post was submitted on 24 Apr 2026
75 points (97.5% liked)

Canada

11924 readers
599 users here now

What's going on Canada?



Related Communities


🍁 Meta


🗺️ Provinces / Territories


🏙️ Cities / Local Communities

Sorted alphabetically by city name.


🏒 Sports

Baseball

Basketball

Curling

Hockey

Soccer


💻 Schools / Universities

Sorted by province, then by total full-time enrolment.


💵 Finance, Shopping, Sales


🗣️ Politics


🍁 Social / Culture


Rules

  1. Keep the original title when submitting an article. You can put your own commentary in the body of the post or in the comment section.

Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage: lemmy.ca


founded 5 years ago
MODERATORS