907
MFA (lemmy.world)
you are viewing a single comment's thread
view the rest of the comments
[-] cooopsspace@infosec.pub 167 points 7 months ago* (last edited 7 months ago)

SMS: Here is your 30s "MFA" code, I'll send it to you 40 minutes after you need it.

SMS isn't 2FA. Its 1.5FA.

[-] KairuByte@lemmy.dbzer0.com 90 points 7 months ago

SMS isn’t even secure. Mitm, social engineering, straight up theft, and more are all ways around it. It should never have been implemented, but especially not when totp exists.

[-] Opisek@lemmy.world 50 points 7 months ago

What I despise most in when SMS is not just optional but forced upon me as "backup" to TOTP. "Lost your authenticator app? Send an SMS instead." How about no?

[-] KairuByte@lemmy.dbzer0.com 10 points 7 months ago

I don’t believe I’ve run into that, but yeah it completely misses the point of totp. Hell, I’d prefer a lockout over SMS backup in most cases, my totp authentication has multiple encrypted backups.

[-] lorkano@lemmy.world 8 points 7 months ago

Especially because you can just backup authenticator to the pendrive in encrypted form. I don't care I loose my phone, that's exactly the reason authenticator is better.

[-] JasonDJ@lemmy.zip 16 points 7 months ago* (last edited 7 months ago)

Dude.

My wife's phone started acting up the other day. It would keep losing cell service and even when it showed a signal, it still would only work on wifi.

That happened a few hours after I ported my phone number (on the same family plan) to another carrier. So naturally, I thought the issue was with the carrier.

Since I planned on porting her number out to my new carrier anyway, I didn't want to troubleshoot.

Well, get to the new carrier and it's still not working. Go through the whole process of resetting network settings, and then eventually deleting the esim.

New carrier, though, needs you to receive a text message before they send the esim.

Naturally, with the esim deleted, it couldn't receive text messages.

Her issue did end up being her phone. Even after the port went through in full, it was still hit-or-miss with cell service. Worked on wifi though.

[-] datelmd5sum@lemmy.world 13 points 7 months ago

I've heard people in the US still use SMS to communicate with eachother. Fucking crazy.

[-] Crashumbc@lemmy.world 23 points 7 months ago* (last edited 7 months ago)

Inertia and ease of use are powerful.

SMS "just works" and works for everyone here.

While I would like the new fancy features. At least RCS is bringing some and is seamlessly integrated.

Bonus I have 10+ years of txt history and can scroll/search to find something. And since my phone is Google (I know evil) I can access it all from the desktop seamlessly in one window.

[-] mexicancartel@lemmy.dbzer0.com 5 points 7 months ago

Sms just works everywhere though

[-] JasonDJ@lemmy.zip 22 points 7 months ago

Only when iPhone users need to send a message to literally anyone else.

[-] Swedneck@discuss.tchncs.de 8 points 7 months ago

uhhh that's not some unique american thing lol, that's how people here in sweden communicate too

Barely anyone cares what specific protocol is being used, they just care about what app they have to use and who they can reach, and if anyone isn't using a normal sms app they're generally using facebook messenger or imessages both of which support sms fallback and thus their users don't even know there's a difference half the time.

[-] rickyrigatoni@lemm.ee 7 points 7 months ago
[-] datelmd5sum@lemmy.world -2 points 7 months ago

Can you for example send a video, encrypted and to your computer via SMS? I don't know how much tech they've built over the protocol over in the US, but in many parts of the world SMS was charged per message in your phone bill and things like photos or video cost more to send. People abandoned SMS quickly when 3rd party IP messaging apps like whatsapp came out.

[-] rickyrigatoni@lemm.ee 0 points 7 months ago

i think most people have unlimited texting and data in america, the greatest country.

[-] datelmd5sum@lemmy.world 3 points 7 months ago

Yeah data got unlimited here before texts, which caused people to move on to other things. Now texts are usually unlimited, but that train has already sailed.

[-] jnk@sh.itjust.works 3 points 7 months ago

Blame apple for that. IPhone has this proprietary messaging app pre-installed which is probably super convinient for the ecosystem but uses some obsolete SMS protocol to communicate with android phones. I think recently this has gotten better, but only because beeper and the EU pressing on them

this post was submitted on 03 Apr 2024
907 points (96.1% liked)

Mildly Infuriating

35459 readers
723 users here now

Home to all things "Mildly Infuriating" Not infuriating, not enraging. Mildly Infuriating. All posts should reflect that.

I want my day mildly ruined, not completely ruined. Please remember to refrain from reposting old content. If you post a post from reddit it is good practice to include a link and credit the OP. I'm not about stealing content!

It's just good to get something in this website for casual viewing whilst refreshing original content is added overtime.


Rules:

1. Be Respectful


Refrain from using harmful language pertaining to a protected characteristic: e.g. race, gender, sexuality, disability or religion.

Refrain from being argumentative when responding or commenting to posts/replies. Personal attacks are not welcome here.

...


2. No Illegal Content


Content that violates the law. Any post/comment found to be in breach of common law will be removed and given to the authorities if required.

That means: -No promoting violence/threats against any individuals

-No CSA content or Revenge Porn

-No sharing private/personal information (Doxxing)

...


3. No Spam


Posting the same post, no matter the intent is against the rules.

-If you have posted content, please refrain from re-posting said content within this community.

-Do not spam posts with intent to harass, annoy, bully, advertise, scam or harm this community.

-No posting Scams/Advertisements/Phishing Links/IP Grabbers

-No Bots, Bots will be banned from the community.

...


4. No Porn/ExplicitContent


-Do not post explicit content. Lemmy.World is not the instance for NSFW content.

-Do not post Gore or Shock Content.

...


5. No Enciting Harassment,Brigading, Doxxing or Witch Hunts


-Do not Brigade other Communities

-No calls to action against other communities/users within Lemmy or outside of Lemmy.

-No Witch Hunts against users/communities.

-No content that harasses members within or outside of the community.

...


6. NSFW should be behind NSFW tags.


-Content that is NSFW should be behind NSFW tags.

-Content that might be distressing should be kept behind NSFW tags.

...


7. Content should match the theme of this community.


-Content should be Mildly infuriating.

-At this time we permit content that is infuriating until an infuriating community is made available.

...


8. Reposting of Reddit content is permitted, try to credit the OC.


-Please consider crediting the OC when reposting content. A name of the user or a link to the original post is sufficient.

...

...


Also check out:

Partnered Communities:

1.Lemmy Review

2.Lemmy Be Wholesome

3.Lemmy Shitpost

4.No Stupid Questions

5.You Should Know

6.Credible Defense


Reach out to LillianVS for inclusion on the sidebar.

All communities included on the sidebar are to be made in compliance with the instance rules.

founded 1 year ago
MODERATORS