Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
Why the hell is this in 4K HDR?
Only the best for the worst hack in history.
id take email Authentication over sms Authentication if there was only them 2 let me use my 2facter app for the love of god plz i hate how banks use sms its like come on man
Email is also unencrypted
Ya just saying I don't like sms I wish email was encrypted maybe one day
Been saying that for years. It's about damn time.
SMS spoofing and SIM swapping have been around for ages. It was never secure and that's always been known. The number of companies that rely on it despite sending me a zillion other fucking useless emails is too damn high! Email, or better yet, an authenticator app, are far more secure. Not perfect, but better.
of course it is. forced 2fa BY SMS OF ALL THINGS is one of the stupidest ideas
I assume businesses only jumped at the chance to enable SMS 2FA to get their greedy little fingers on our phone numbers.
Even stupider is supporting hardware keys for MFA, but having SMS fallback which can't be disabled (looking at you, Vanguard). I'd much rather have email as my second factor than SMS, and I literally abandoned a bank (Ally) for removing email as an alternative to SMS.
Hollywood hacking has nothing on real hacking it seems.
Thank god, give me my HMAC hash please.
Nothing more terrifying than losing your phone number these days because of all the accounts tied to it via 2FA.
Didn't this happen quite awhile ago? I don't see anything new in this article
The novelty is the fact that it's ongoing. They haven't mitigated the hack. The threat actors are still inside the networks, which is why the government is telling people to switch to E2EE apps.
I wish Signal stopped using it. I know you can set a Signal PIN but a lot of the non-techy friends I speak to on Signal probably wouldn't think to, or look through the settings (not that you need to be "techy" to set it, but you know the kind of learned helplessness most people have about tech). At least a prompt for all users to set an account PIN so their account can't just be stolen by anyone with their SIM card.