this post was submitted on 29 Feb 2024
80 points (100.0% liked)

technology

23212 readers
345 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 4 years ago
MODERATORS
top 9 comments
sorted by: hot top controversial new old
[–] PorkrollPosadist@hexbear.net 38 points 7 months ago* (last edited 7 months ago) (1 children)

Any 2FA that sends you an authentication code though SMS is masturbation. That "secret" code is getting broadcasted over the air in cleartext. Time-based OTP is the only reasonable solution.

[–] ColeSloth@discuss.tchncs.de 6 points 7 months ago

If you're willing enough to intercept my text messenger data and hack my system to know my login credentials and password before doing it, I'll just let you into my mcdonalds rewards account myself.

[–] Yurt_Owl@hexbear.net 34 points 7 months ago

I hate the ones that push their shitty 2fa app for only their one service

[–] FuckyWucky@hexbear.net 28 points 7 months ago (1 children)

yes that and the fact that phone numbers are more difficult to create and keep compared to emails. you can have a hundred gmail accounts but you can't have 100 SIM cards (yes there are VOIP numbers but those cost money too).

[–] snooggums@midwest.social 18 points 7 months ago

And companies frequently prohibit VOIP numbers from being used for 2fa.

[–] BeanBoy@hexbear.net 12 points 7 months ago

Surely they have our best interests in mind

[–] ChaosMaterialist@hexbear.net 10 points 7 months ago
[–] Tabitha@hexbear.net 7 points 7 months ago

SMS is the least secure form of MFA that I'm aware of, so objectively, yes.

[–] oscardejarjayes@hexbear.net 3 points 7 months ago