Hacker News new | ask | show | jobs
by guappa 738 days ago
My bank sends an SMS for OTP.

I know it isn't very secure. But certainly better than having a seed locally stored.

1 comments

I'd rather a seed on a device I own rather than being able to be smished.
If I can't see the seed and I have no way of exporting it. What do I have?
If I can't see the person in the telco being paid off to have my IMEI reattached arbitrarily, what do I have? A person who can MITM the SMS codes.
I wouldn't call an Android device "a device you own".
Why don't I own it, explain.