11 ms·
I wonder if this was SIM-swapping and if so if it will finally get a bit more federal attention
by wackycat 3y ago
I wonder if this was SIM-swapping and if so if it will finally get a bit more federal attention
- lxgr 3y agoThe problem really isn’t SIM swapping, it’s that we’ve become used to treating phone numbers as reliable personal identifiers, and SMS OTP as proof of identity (for authentication) and/or humanity (for spam/sockpuppet account protection). Mandating 2FA methods other than SMS OTP would be amazing, but I don’t see that happening at the federal level, largely due to the complete lack of other digital authentication methods. What else should companies use?
- out-of-ideas 3y agothe same thing hacker news uses; a user name and a password. if we want proof that each account correlates to exactly one person, well i think that should 100% not be a phone number and is an entierly bigger+different problem
- lxgr 3y agoI fully agree, but practically, this is what many companies are doing right now.
- out-of-ideas 3y agolol after what we've just seen, when one company jumps off a bridge and lays off a ton of folks, other companies copy that same move...