Skip Navigation

Feds Warn SMS Authentication Is Unsafe After ‘Worst Hack in Our Nation’s History’

151 comments
  • I wish Signal stopped using it. I know you can set a Signal PIN but a lot of the non-techy friends I speak to on Signal probably wouldn't think to, or look through the settings (not that you need to be "techy" to set it, but you know the kind of learned helplessness most people have about tech). At least a prompt for all users to set an account PIN so their account can't just be stolen by anyone with their SIM card.

    • I thought they abandoned SMS a couple years ago??

      • They abandoned letting you use the Signal app to send and recieve SMS. You still need to get a code via SMS to activate your Signal account. I believe this is what they are referring to.

    • Another thing is that even if you set a PIN, you'd still have to log into your account relatively regularly so that if you lose access to your number, you wouldn't lose an account. It's logical, given that numbers are reused... But that means that if you want to register without effectively tying your account to your ID (KYC when buying numbers is mandatory in a lot of the world, remember!), you'd have to pay for another phone bill (expensive given that the number's practically doing nothing!) or use a one-time rental... Which guess what, puts your account at constant risk!

  • So many services still don't even offer 2FA at all. Any service that stores payment information and PII without any 2FA options, let alone a secure one, at this point are a disgrace.

151 comments