• Jul (they/she)@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    I was talking about sms. All types of cryptographic code generation uses one or more keys. The sms type just uses one that only the sender holds, it’s never shared with anyone which can cause it to be more easily lost.

    The sim cards and their cryptographic keys are just built into the phones, and the codes are swapped when you sign up, same concept as renovable sim cards.

    And again, it doesn’t matter of a sms code is intercepted as much as the entire login method. If you dont have the username and password, what good does an sms code do for anything? The issue in the article is that there’s nothing else to know, just the current format of the set of codes being generated by the system. Then you can randomly guess a similar code and get access to a random person’s account. Much, much different from the use MFA which is worthless without ALL of the factors, not just a single one.

    • artyom@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      If you dont have the username and password, what good does an sms code do for anything?

      The entire point of MFA is to protect against someone who does have your username and password…

      • Jul (they/she)@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Exactly, so it does that job because it requires an entirely different and complex skill-set to intercept sms messages and you have to do both things now if sms 2FA is in place. With the issue in the article you dont even need to intercept sms meant for a particular user to get access to random users’ accounts, thus totally different issue.

        I asked, what is better for a second factor than SMS?

        • artyom@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          so it does that job

          It does, really poorly, for the reasons I’ve listed, and for the reasons in the OP.

          With the issue in the article you dont even need to intercept sms meant for a particular user to get access to random users’ accounts, thus totally different issue.

          Not a different issue at all. Exact same issue, with lower risk.

          I asked, what is better for a second factor than SMS?

          I answered this like 12 comments ago.

          We’re going around in circles now so I’ll bid you good night.