In fact, it is less secure than no MFA at all if that number is also used for password reset.
-
-
-
And yet, people argue this fact.
Kraj razgovora
Novi razgovor -
-
-
NIST already told us years ago. The IAM company I worked for phased it out like 4 years ago. The company that hired me now doesn’t use it either and they’re BIG in their field ;) So yeah.. SMS != 2FA
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
Another layer to slow down the bad actor... defense in depth.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
2FA better than not having it, and improved security if services using it also include sim-swap detection, which various banks already do. Hint,
@imimobile help provide that service for financial services with additional security practices.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
This covers SIM fraud, but isn't SS7 still a problem as well?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
1.5 Factor. It protects an account from untargeted password spreading attacks and the like, but provides little against a targeted attack
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
Seems like a simple order of ops query...
-
If SMS is compromised your 2FA that relies on the security of SMS is too. Quid pro quop.
Kraj razgovora
Novi razgovor -
-
-
Nothing can ever be truly secure. The problem with SMS 2FA is not the SMS's themselves, but the carrier's vulnerabilities in SIM swap fraud. App and token based 2FA is better but still vulnerable to social engineering. If tokens can't be used, SMS's are still better than nothing.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.




