Hacker News new | ask | show | jobs
by heavymark 2473 days ago
Because then in most cases you bypass 2 factor authentication through sms for people's accounts. And then steal their social media handles or anything. Sites like Twitter only allow SMS 2 factor authentication, so currently no way to avoid the issue, which is why even the CEO was just hacked. One has to assume they are working on real 2 factor authentication. That will help people in the know stay protected, but the average person or simply enables sms 2 factor authentication will still be vulnerable until a company like Apple or something automatically offers 2 factor app for all sites that support 2fa.
1 comments

I've been mitigating this vector best I can by associating any of my accounts that only offer 2FA via SMS to a Google Voice number / Google account that can only be accessed via Token/Backup codes.