• refalo
    link
    fedilink
    arrow-up
    33
    arrow-down
    1
    ·
    5 months ago

    Now tell banks to stop requiring SMS 2FA holy shit

    • manualoverride@lemmy.world
      link
      fedilink
      arrow-up
      10
      arrow-down
      3
      ·
      5 months ago

      You actually want them to do this, it’s terrifying easy to set up a cell tower or call centre and convince banks and people you are customers or banks.

      • ramble81@lemm.ee
        link
        fedilink
        arrow-up
        20
        ·
        5 months ago

        I think he was meaning because of how easy it is to spoof and intercept sms. Use some thing like OTP that’s a common standard instead.

        • kevincox@lemmy.ml
          link
          fedilink
          arrow-up
          7
          ·
          5 months ago

          You probably mean TOTP. OTP is a generic term for any one-time-password which includes SMS-based 2FA. The other main standard is HOTP which will use a counter or challenge instead of the time as the input but this is rarely used.

        • manualoverride@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          5 months ago

          Ah I see, yes app/web OTP is one of the best methods, unless people are calling to report the app/website not working (a workflow I’ve seen many times) The industry has put hundreds of millions into voice recognition but the sample size required for AI to trick voicerec is really low now.