6 ms·
SMS based OTP has been known to be unreliable way to authenticate someone because exactly this type of social engineering hacks. All software providers and the
by devy 2y ago
SMS based OTP has been known to be unreliable way to authenticate someone because exactly this type of social engineering hacks.
All software providers and the industry should ban SMS based OTPs as a standard practice. Either leapfrogging to a Passkey implementation or just time based OTPs.
- akerl_ 2y agoWhat software provider or industry group is in a position to enact a ban on an MFA strategy?
- mathgradthrow 2y agothe US government.
- bhaney 2y agoMaybe organizations in charge of cybersecurity compliance frameworks? We'd see a lot of companies drop SMS 2FA pretty quickly if it became a requirement to maintain their SOC compliance. I don't think we need a complete sweeping ban to get it to largely fall out of use, just a critical mass to drop it so it's no longer defensible as an industry standard
- deleted 2y ago[deleted]
- dvngnt_ 2y agoafter years with no issues, my bank stopped supporting my google voice number and said I have to use regular SMS as it's more secure