I guess I'm not sure I understand where we disagree, we both agree that attackers can improve, and both agree they haven't yet while adoption is so low. Is it that you argue that even when forced to adapt because of high adoption of SMS-2FA, they'll just pack up and go home?
Password reuse + SMS 2FA > password reuse. How big? I can’t know for sure but given my experience, my hunch is that it’s much larger than one might guess because humans have threshold behaviors. They stay in certain lanes, drastically avoid others.
-
-
You can teach the binomial theorem to a 10 year old, just don’t tell them it’s math. Tell people it’s probability theory, they cannot understand. Don’t, easy peasy. So phishing isn’t a default among the politically motivated opportunistic attackers, in my experience. \_(ツ)_/¯
-
(I have hundreds of security keys in my office; I give them out like candy, btw.

)
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
