Most casuals don't even realize that their thickest layer of protection atm is that nobody currently desires to fuck with them
-
-
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I recently signed up for an account on
@UbisoftUplay and was shocked that they had an option for 2FA with Google Authenticator. I enabled it just to see how the process worked because I had no idea other sites could even use it. -
All the crypo exchanges use it.
End of conversation
New conversation -
-
-
well people also still use credit cards whose security model is “frequently give strangers your secret key”
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
i was horrified to hear that there's literally insiders working for cell companies who facilitate instances of SIM-swap/porting fraud
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Right, *cough* yeah (googles) everyone. Idea: social verification — people who know you can vouch for your identity. That's resilient. If there was accessible 3,4,5FA, etc, what would the other factors be? Thumbprints, facial rec, etc are more precise, high res, secure, right?
-
If a high resolution scan of my fingerprints/retinals/etc gets leaked, I'm screwed forever. Fooling a biometric scanner is very feasible, think 3-D printing. Also American police in some areas can force you to unlock with biometrics, supreme court will probably eventually agree.
- Show replies
New conversation -
-
-
Do you know anyone that this has happened to? What did they do once the attack occurred? How long could the individual go to prison for should they carry out such an attack?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I'd say SMS 2FA is flawed for that reason. Something like an authenticator app tho is relatively safe and secure. You need to have the physical device to log in.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
For the uninitiated, you might want to mention that apps like google authenticator are immune to SIM swapping (not that they're perfect).
-
Many financial institutions don't accept Google authenticator. A SIM PIN would help (not foolproof) Authentication via email would help, as well.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.