Hacker News new | ask | show | jobs
by cryptonector 2405 days ago
What part of SIM-jacked did you not understand?

It's not about your password. It's about social engineering. Bad guys call their buddies at some mobile phone co. and get your number switched for a few minutes, then they call your bank and get them to change your password which they do because they trust SMS 2FA which now goes to the bad guys, and then they take your money, and you find out much later. Password quality has zero to do with any of this.

1 comments

You seem to have missed part of his comment: "the problem is when companies introduce recovery numbers and make it back into 1FA".