Article Image

IPFS News Link • Hacking, Cyber Security

So Hey You Should Stop Using Texts for Two-Factor Authentication

• https://www.wired.com, Andy Greenberg

But a two-factor setup—which for most users requires a temporary code generated on, or sent to, your phone in addition to a password—isn't an invincibility spell. Especially if that second factor is delivered via text message.

The last few months have demonstrated that SMS text messages are often the weakest link in two-step logins: Attacks on political activists in Iran, Russia, and even here in the US have shown that determined hackers can sometimes hijack the SMS messages meant to keep you safe. Whenever possible, it's worth taking a minute to switch to a better system, like an authentication smartphone app or a physical token that generates one-time codes. And for services like Twitter that only offer text messages as a second factor, it's time to wake up, smell the targeted attacks, and give users better options.


PurePatriot