Infosec.Pub
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
BeamBrain [he/him]@hexbear.net to technology@hexbear.netEnglish · 2 years ago

My personal conspiracy theory: the reason so many sites and services push for mandatory 2FA nowadays is to have an excuse to harvest phone numbers.

message-square
message-square
9
link
fedilink
76
message-square

My personal conspiracy theory: the reason so many sites and services push for mandatory 2FA nowadays is to have an excuse to harvest phone numbers.

BeamBrain [he/him]@hexbear.net to technology@hexbear.netEnglish · 2 years ago
message-square
9
link
fedilink
alert-triangle
You must log in or # to comment.
  • PorkrollPosadist [he/him, they/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    37
    ·
    2 years ago

    Any 2FA that sends you an authentication code though SMS is masturbation. That “secret” code is getting broadcasted over the air in cleartext. Time-based OTP is the only reasonable solution.

    • ColeSloth@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 years ago

      If you’re willing enough to intercept my text messenger data and hack my system to know my login credentials and password before doing it, I’ll just let you into my mcdonalds rewards account myself.

  • Yurt_Owl@hexbear.net
    link
    fedilink
    English
    arrow-up
    33
    ·
    2 years ago

    I hate the ones that push their shitty 2fa app for only their one service

  • FuckyWucky [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    25
    ·
    2 years ago

    yes that and the fact that phone numbers are more difficult to create and keep compared to emails. you can have a hundred gmail accounts but you can’t have 100 SIM cards (yes there are VOIP numbers but those cost money too).

    • snooggums@midwest.social
      link
      fedilink
      English
      arrow-up
      17
      ·
      2 years ago

      And companies frequently prohibit VOIP numbers from being used for 2fa.

  • BeanBoy [she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 years ago

    Surely they have our best interests in mind

  • ChaosMaterialist [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 years ago

    No conspiracy necessary. Facebook went and did it.

  • Tabitha ☢️[she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 years ago

    SMS is the least secure form of MFA that I’m aware of, so objectively, yes.

  • oscardejarjayes [comrade/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 years ago

    TOTP?

  • xor
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 year ago

    deleted by creator

technology@hexbear.net

technology@hexbear.net

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@hexbear.net

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

  • Ways to run Microsoft/Adobe and more on Linux
  • The Ultimate FOSS Guide For Android
  • Great libre software on Windows
  • Hey you, the lib still using Chrome. Read this post!

Rules:

  • 1. Obviously abide by the sitewide code of conduct. Bigotry will be met with an immediate ban
  • 2. This community is about technology. Offtopic is permitted as long as it is kept in the comment sections
  • 3. Although this is not /c/libre, FOSS related posting is tolerated, and even welcome in the case of effort posts
  • 4. We believe technology should be liberating. As such, avoid promoting proprietary and/or bourgeois technology
  • 5. Explanatory posts to correct the potential mistakes a comrade made in a post of their own are allowed, as long as they remain respectful
  • 6. No crypto (Bitcoin, NFT, etc.) speculation, unless it is purely informative and not too cringe
  • 7. Absolutely no tech bro shit. If you have a good opinion of Silicon Valley billionaires please manifest yourself so we can ban you.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 3 users / 6 months
  • 34 local subscribers
  • 23.2K subscribers
  • 1.01K Posts
  • 11.8K Comments
  • Modlog
  • mods:
  • Jadzia_Dax [she/her]@hexbear.net
  • blashork [she/her]@hexbear.net
  • context [fae/faer, fae/faer]@hexbear.net
  • EmmaGoldman [she/her, comrade/them]@hexbear.net
  • SexUnderSocialism [she/her]@hexbear.net
  • gaycomputeruser [she/her]@hexbear.net
  • ZoomeristLeninist [comrade/them, she/her]@hexbear.net
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org