619
(page 2) 50 comments
sorted by: hot top controversial new old
[-] rarbg@lemmy.zip 66 points 1 day ago

Oh man it sure would be nice if the feds had the power to regulate something like this /s

load more comments (7 replies)
[-] Phoenicianpirate@lemm.ee 15 points 1 day ago

Hollywood hacking has nothing on real hacking it seems.

[-] umbrella@lemmy.ml 27 points 1 day ago

of course it is. forced 2fa BY SMS OF ALL THINGS is one of the stupidest ideas

[-] capital@lemmy.world 13 points 1 day ago

I assume businesses only jumped at the chance to enable SMS 2FA to get their greedy little fingers on our phone numbers.

load more comments (1 replies)

Even stupider is supporting hardware keys for MFA, but having SMS fallback which can't be disabled (looking at you, Vanguard). I'd much rather have email as my second factor than SMS, and I literally abandoned a bank (Ally) for removing email as an alternative to SMS.

[-] bjoern_tantau@swg-empire.de 106 points 2 days ago
[-] Ugurcan@lemmy.world 13 points 1 day ago

Why the hell is this in 4K HDR?

[-] bjoern_tantau@swg-empire.de 13 points 1 day ago

Only the best for the worst hack in history.

load more comments (1 replies)
[-] shortwavesurfer@lemmy.zip 63 points 2 days ago

Been saying that for years. It's about damn time.

[-] Screen_Shatter@lemmy.world 16 points 1 day ago

SMS spoofing and SIM swapping have been around for ages. It was never secure and that's always been known. The number of companies that rely on it despite sending me a zillion other fucking useless emails is too damn high! Email, or better yet, an authenticator app, are far more secure. Not perfect, but better.

[-] frostysauce@lemmy.world 1 points 1 day ago

Wait, how is email more secure than SMS?

load more comments (3 replies)
[-] shortwavesurfer@lemmy.zip 5 points 1 day ago

One big reason I'm hesitant to keep my money in banks is because banks think the best form of two-factor authentication is text message based 2FA and I'm like that's barely any 2FA at all.

[-] Screen_Shatter@lemmy.world 5 points 1 day ago

My banks are like that too. Of course I can't speak to anyone who might influence that decision. Steam has better security than almost any other account I have. I appreciate them for that but it also seems ludicrous to me that my video games are more secure than my bank accounts.

[-] shortwavesurfer@lemmy.zip 4 points 1 day ago

I keep my money in Monero. That way, it's me who has to be targeted instead of an institution. And if I fuck up and lose it, it's my own damn fault.

load more comments (2 replies)
[-] 8000gnat@reddthat.com 5 points 1 day ago

I'm new to technology, is this good?

load more comments (2 replies)
[-] metaStatic@kbin.earth 37 points 2 days ago

in other news grass is green

It's brown in my area. Check mate!

load more comments (2 replies)
[-] phoneymouse@lemmy.world 27 points 2 days ago* (last edited 2 days ago)

Thank god, give me my HMAC hash please.

Nothing more terrifying than losing your phone number these days because of all the accounts tied to it via 2FA.

[-] Imgonnatrythis@sh.itjust.works 30 points 2 days ago

Didn't this happen quite awhile ago? I don't see anything new in this article

[-] Telorand@reddthat.com 50 points 2 days ago

The novelty is the fact that it's ongoing. They haven't mitigated the hack. The threat actors are still inside the networks, which is why the government is telling people to switch to E2EE apps.

[-] communism@lemmy.ml 23 points 2 days ago

I wish Signal stopped using it. I know you can set a Signal PIN but a lot of the non-techy friends I speak to on Signal probably wouldn't think to, or look through the settings (not that you need to be "techy" to set it, but you know the kind of learned helplessness most people have about tech). At least a prompt for all users to set an account PIN so their account can't just be stolen by anyone with their SIM card.

[-] EngineerGaming@feddit.nl 5 points 1 day ago

Another thing is that even if you set a PIN, you'd still have to log into your account relatively regularly so that if you lose access to your number, you wouldn't lose an account. It's logical, given that numbers are reused... But that means that if you want to register without effectively tying your account to your ID (KYC when buying numbers is mandatory in a lot of the world, remember!), you'd have to pay for another phone bill (expensive given that the number's practically doing nothing!) or use a one-time rental... Which guess what, puts your account at constant risk!

load more comments (3 replies)
load more comments
view more: ‹ prev next ›
this post was submitted on 20 Dec 2024
619 points (100.0% liked)

Technology

60023 readers
2274 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS