this post was submitted on 24 Jun 2024
440 points (98.0% liked)

Asklemmy

43894 readers
1041 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy 🔍

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_[email protected]~

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] refalo 32 points 4 months ago (1 children)

Now tell banks to stop requiring SMS 2FA holy shit

[–] [email protected] 7 points 4 months ago (1 children)

You actually want them to do this, it’s terrifying easy to set up a cell tower or call centre and convince banks and people you are customers or banks.

[–] [email protected] 20 points 4 months ago (2 children)

I think he was meaning because of how easy it is to spoof and intercept sms. Use some thing like OTP that’s a common standard instead.

[–] [email protected] 7 points 4 months ago

You probably mean TOTP. OTP is a generic term for any one-time-password which includes SMS-based 2FA. The other main standard is HOTP which will use a counter or challenge instead of the time as the input but this is rarely used.

[–] [email protected] 4 points 4 months ago

Ah I see, yes app/web OTP is one of the best methods, unless people are calling to report the app/website not working (a workflow I’ve seen many times) The industry has put hundreds of millions into voice recognition but the sample size required for AI to trick voicerec is really low now.