Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Text messages are incredibly insecure because of how easy it is for someone to take over your phone number.


Yet another reason to use SMS encryption (which seems oddly rare) like SilenceIM (formerly SMSSecure, formerly the dropped SMS code in TextSecure [now Signal]).


So Google and Microsoft use 2FA cause texts are more insecure? If I lose control of my phone they're into all my websites anyway.


Yes, texts are insecure for 2FA. It's better to use Google Authenticator or similar.

https://www.wired.com/2016/06/hey-stop-using-texts-two-facto...


Not losing control of your phone. Losing control of your phone _number_.

There's plenty of stories around of spear phishing attacks involving attackers taking over the victim's phone number. Mobile operators are notoriously vulnerable to that sort of shenanigans.


Losing control of your actual phone is not the same as losing control of your phone number.

I'm not sure about Microsoft, but Google supports several other 2FA mechanisms in addition to SMS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: