TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Is there a security-centric US Mobile Carrier you'd recommend?

3 点作者 mdu将近 7 年前
Mobile Carrier is one of the biggest weak points for many 2FA.<p>Unfortunately, most of the sites I use do not leverage U2F or TOTP, and I&#x27;m forced to use SMS for 2FA.<p>Is there any mobile carrier that is more security and privacy centric? Such that someone can’t just impersonate me and gain access to my SMS through the phone carriers?

3 条评论

bronco21016将近 7 年前
I believe the insecurity of SMS comes from the design of mobile network protocols. Not from individual carrier’s implementation.<p>Can you change online services if you’re that paranoid? Can you compartmentalize in a fashion that if one site is compromised the rest will remain intact? The main services I would be concerned about are financial institutions and the e-mail accounts tied to them. Switching banks in the US is relatively easy. Also, good password practices would limit exposure to risk.
Eridrus将近 7 年前
As others have said, the protocols are kind of crap, but it sounds like your concern is more about account takeover through customer service.<p>Maybe Project Fi? I don&#x27;t know that they&#x27;re better, but Google takes security pretty seriously, and you can probably lock down your Google account.<p>There&#x27;s still a risk with phone number portability where someone tricks another carrier into porting your number somewhere else, and I kind of doubt that even Fi does anything here.
评论 #17473254 未加载
cremp将近 7 年前
None.<p>SS7 itself is bad, and proven time and time again that it can be used maliciously.