5 ms·
my bank insisted that i add a phone number to my account when i called them today. i declined and when pressed briefly explained sim swapping and declined again
by abdel_nasser 5y ago
my bank insisted that i add a phone number to my account when i called them today. i declined and when pressed briefly explained sim swapping and declined again. a glaring and obvious flaw in the integrity of using a phone number for id verification was not even in the lexicon of this establishment that safeguards nothing less than all of my literal fucking money. they then went on to find that i actually did have a phone number on record and that it is authorized for identity verification and also that i have never even heard of this phone number! im still dealing with it.
its amazing to think that not just this but the entire mountain of bullshit could be avoided with simple passwords. it should be an option offered by every service for a user to deactivate all authorization methods besides one very strong password and perhaps a backup password. we should at least have the option.
- jaza 5y agoUnfortunately people like you (and me), who actually have strong passwords, let alone who understand in any detail what constitutes a strong password, are a tiny minority. They have to design for the lowest common denominator. And even those of us with strong passwords, and a strong understanding of cyber security, are vulnerable to phishing and other attacks, that can be defended against by using MFA. Obviously MFA can be taken to ridiculous "ten factor" extremes. But sticking with, or going back to, just passwords, isn't the solution.
- abdel_nasser 5y agoif we had just passwords then there would be far fewer people losing their life savings than with the current system.