[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

since two-factor authentication is not recommended anymore how

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 17
Thread images: 1

File: sms-two-factor-authentication.png (41KB, 728x380px) Image search: [Google]
sms-two-factor-authentication.png
41KB, 728x380px
since two-factor authentication is not recommended anymore how do you protect your accounts?
>>
>>60342721
why is it suddenly dead?
>>
>>60342721
Not recommended by who?
>>
>>60342721
tell me why i need two factor authentication
>>
>>60342744
Because it's suddenly a common knowledge you can spoof ss7 packets to intercept SMS.
>>
>>60342744
>>60342751
>>60342764
in January, attackers exploited well-known SS7 weaknesses to bypass two-factor authentication banks used to prevent unauthorized withdrawals from online accounts. After first using traditional Banking Trojan implants to perform the first stage of account compromise, and learning the account balances, they then selectively compromised the SS7 system to redirect the text messages banks used to send one-time passwords. Instead of being delivered to the phones of designated account holders, the text messages were diverted to numbers controlled by the attackers. The attackers then used the mobile transaction authentication numbers to transfer money out of the accounts.
>>
Carrier pigeons and smoke signals.
>>
2FA is not limited to SMS, you dum
>>
>>60342788
So for this to be effective the malicious party needs to first infect a bank with a trojan; that surely cant be too easy. otherwise theyre just taking a random shot in the dark
>>
>>60342764
2fa can be done with a lot more than sms..email(which is usually stupid if you can reset your password with the same email account), apps on your phone (steam for example), physical devices like rsa keyfobs and ubikeys. I think blizzard has a ohysical rsa like device you can order.
>>
>>60342850
yes, but most banks use SMS 2FA only and that's a huge security risk
>>
>>60342896
Doesn't mean you shouldn't enable it. Anyone know if chase has a 2fa app instead of SMS? My credit union doesn't have any 2fa at all lol.
>>
>>60342806
This my bank's method include taking a selfie in order to generate a qr code
>>
That's funny. I still have a paper list of numbers, and for every payment I'm asked for a specific number. My bank has been pushing SMS verification lately, meaning they'd text the number instead. When did the possession-factor in MFA change from "something you have" into "something we send you"?
>>
>>60342721
SMS 2FA has always been shit, telecomm providers are niggers and will give your number to anyone who pretends they're you
You do TOPT 2FA, and keep your shit safe just like you would with your passwords, or >>60343886
>>60342896
Most banks have shit security, there was this small bank in the US that was susceptible to heartbleed for weeks
>>
>not using a card reader for banking 2fa
>not using a dedicated secure app such as Authy for other 2fa

Why do people do this?
>>
>>60344944
people do all kind of stupid shit. most people don't even use 2fa unless forced on them
Thread posts: 17
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.