Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The security advantage is that an attacker using a completely different device doesn’t have your phone.


Except that SMS messages can be intercepted, e.g. by having a proper access to the SS7 backbone, by abusing services provided for other reasons, or by SIM swapping attacks. All of this has already been done, so it's not just theory.

See e.g. https://arstechnica.com/information-technology/2021/03/16-at..., https://arstechnica.com/information-technology/2017/05/thiev..., https://arstechnica.com/information-technology/2016/08/congr...


Yes, of course, the Ask:HN is basically about that! The parent comment asserted that having an SMS in addition to a password is functionally no different from having a password only. Which is not the case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: