@return2ozma @technology
10 years ago, the Feds wanted backdoors to all of phones so they could read all of our text messages. Now, the Feds want everyone not to use software that has backdoors so the Chinese cannot read our phones. The Feds don’t want competition.So many services still don’t even offer 2FA at all. Any service that stores payment information and PII without any 2FA options, let alone a secure one, at this point are a disgrace.
Why the hell is this in 4K HDR?
We here at Lemmy are professionals
Oh man it sure would be nice if the feds had the power to regulate something like this /s
They did. That’s the reason for this hack, they wanted Lawful Interception, they got their backdoor. It’s what professionals and privacy advocates said all along, if it exists it will be abused.
Do you have a source for this claim? I’d like to repeat it elsewhere…
I.e. this article from October: https://www.techradar.com/pro/chinese-hackers-allegedly-hit-us-wiretap-systems-to-hit-broadband-networks
In an all too predictable turn of events, Salt Typhoon, an infamous Chinese state actor, has reportedly hijacked government systems to breach several American broadband providers and gain access to the interception portals required by US law.
Thanks for bringing receipts. In stark contrast to my experience on Reddit, Lemmings usually seem allergic to showing their work for some reason.
Yeah, I don’t get it. I go out of my way to provide sources even before being asked.
What’s really frustrating is when others users criticize me for providing evidence that could be used to counter my claim. I’m not trying to win arguments, I’m trying to show my work so others can correct me if I missed something. I’m here to learn and educate, in that order, yet so many only seem interested in engaging in discussion that jives w/ their existing opinions. That was a problem on Reddit too, but at least someone would chime in w/ sources much of the time.
@capital @sugar_in_your_tea I’m entering a conversation without reading the other posts, so I apologise. I just want to say that I deeply admire your approach. It is mine as well. I will begin a discussion with a view that I hold, but if someone is able to prove me wrong, I will admit it and thank him. And if my sources should be used to prove his point, then either I didn’t read well enough or it’s simply a line of thought that I hadn’t considered. But I love civil discussions without wasting time on personal attacks and whatnot, and it seems you’re the same way.
Join us, there are dozens of us! 😀
NIST has been saying since 2016 not to use SMS for MFA. It’s always been horribly insecure.
The problem for me is that most Canadian Banks give you the choice of SMS or their shitty adware filled bank app that relies on Google Play Services and wont implement TOTP so I can use a true MFA app. And Im done with being forced to accept user policies I don’t agree with to do shit, and most of all done with Google Play Services on my device 😑
Even Bank of America doesn’t support MFA apps.
They support USB hardware tokens… but only for the website. Everything else is SMS which kinda defeats the point.
Annoyingly, other than Vanguard, they are the only financial institution to support USB FIDO tokens
in my experience, FIDO tokens suck. I have to around 10 times every time I use one to log in.
Are your USB ports broken? I’ve never had issues other than physical port problems
I don’t think so. It was on three seperate computers. I also used two FIDO keys, both identical. Maybe they’re of poor quality, so it could be that. Any recommendations on a reliable FIDO key?
No idea. I just use the yubikey ones. I have an old usb-a oneb and a newer small usbc one
I hate forced 2FA that you can’t disable anyway. I don’t want to waste time waiting for an insecure text, I don’t want to input an unencrypted code you sent to my email, I don’t want to click your damn notification that runs through Play Services, and no I’m not enrolling in passwordless auth. I don’t need to be babied into securing my accounts. Any account I do actively and willingly secure is already using TOTP. Let me put in my username and password, then kindly fuck off.
Yeah. So you, myself, and some others are the exception to the rule. But, you can’t look at it that way because its a ‘lowest common denominator’ problem. The least secure of us means we are all only as secure. Others need to be hand held.
It’s definitely time to raise all boats and drop SMS 2fa like a hot rock.