SMS-based two-factor authentication is not safe — consider these alternative 2FA meth
#1
Lightbulb 
[Image: 2fa-practical-guide-featured.jpg]
Quote:In the past couple of years, the concept of two-factor authentication (2FA), long the preserve of geeks, has found its way into the mainstream. However, the talk is still largely confined to using 2FA for one-time passwords over SMS. Sad to say, this is not the most reliable option. Here’s why:
  • It’s easy to sneak a peek at passwords sent by SMS if lock-screen notifications are enabled.
  • Even if notifications are turned off, a SIM card can be removed and installed in another smartphone, giving access to SMS messages with passwords.
  • Password-bearing SMS messages can be intercepted by a Trojan lurking inside the smartphone.
  • Using various underhanded tactics (persuasion, bribery, etc.), criminals can get hold of a new SIM card with the victim’s number from a mobile phone store. SMS messages will then go to this card, and the victim’s phone will be disconnected from the network.
  • SMS messages with passwords can be intercepted through a basic flaw in the SS7 protocol used to transmit the messages.
Full reading: https://www.kaspersky.com/blog/2fa-pract...ide/24219/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 140.0.2
Mozilla Firefox Br...harlan4096 — 06:15
Emsisoft Emergency Kit 2025.7.0.12683
Changes in 2025.7....harlan4096 — 06:14
Kaspersky\VPN\KSOS 21.22 & KES 12.10 be...
harlan4096 — 06:12
Bitdefender 27.0.53.265
Latest version of ...harlan4096 — 06:12
ESET 18.2.14
ESET NOD32 Antivir...harlan4096 — 06:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>