Hacker News new | ask | show | jobs
by robin_reala 1558 days ago
MITM isn’t common, but the big problem with SMS for 2FA is that mobile numbers are portable. If your number gets ported without your consent then your 2FA codes gets sent to a device you don’t control.[1] NIST stopped recommending SMS 2FA half a decade ago for this reason.[2]

[1] https://en.wikipedia.org/wiki/SIM_swap_scam

[2] https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo...