TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

It’s time to stop using SMS for security

174 点作者 andyjih_大约 4 年前

14 条评论

slovette大约 4 年前
So, I work in telecom and dabble a bit in software.<p>I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale?<p>At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”.<p>I’d love a parable of how using SMS as part of a layered security verification is somehow unacceptably vulnerable.
评论 #26474349 未加载
评论 #26473855 未加载
评论 #26475237 未加载
评论 #26474677 未加载
评论 #26474212 未加载
评论 #26474146 未加载
评论 #26476167 未加载
评论 #26475040 未加载
评论 #26474615 未加载
评论 #26474560 未加载
评论 #26475014 未加载
评论 #26473689 未加载
评论 #26475283 未加载
评论 #26474624 未加载
评论 #26475789 未加载
评论 #26475292 未加载
评论 #26473330 未加载
评论 #26476118 未加载
评论 #26477723 未加载
评论 #26485005 未加载
评论 #26475319 未加载
评论 #26475103 未加载
lholden大约 4 年前
The URL is giving an empty page for me, so I&#x27;m afraid I can&#x27;t really comment on the content of the article itself.<p>With that said, people should fear any site&#x2F;service that uses SMS for anything security related. SMS 2fa is a fairly common vector for compromise.<p>It can be nice for a &quot;data feed&quot; though. Like, getting an update on the status of your delivery driver. Though, this can also be really annoying when say... your old college starts spamming you with stuff... which I got to experience this weekend at 1am. :)
dgellow大约 4 年前
Living in Germany, I don&#x27;t remember the last time I used an SMS. When I was in south-east Asia I don&#x27;t think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?
评论 #26474273 未加载
评论 #26474305 未加载
评论 #26475506 未加载
评论 #26475253 未加载
评论 #26475889 未加载
评论 #26474411 未加载
评论 #26474610 未加载
评论 #26474455 未加载
评论 #26474294 未加载
评论 #26474419 未加载
评论 #26474580 未加载
评论 #26474362 未加载
ddevault大约 4 年前
For the love of God, stop using Medium. I don&#x27;t understand how authors don&#x27;t know better by now.
评论 #26477308 未加载
评论 #26476065 未加载
upofadown大约 4 年前
&quot;Identity management is hard. I know, let&#x27;s just let the phone company deal with it!&quot;<p>Later...<p>&quot;Oh no! The phone company is doing a terrible job of solving our identity issue!&quot;
fomine3大约 4 年前
Yahoo! Japan, One of the most famous website in Japan, forces users to use insane auth method: SMS 1FA. It even accepts phone number as login ID. This is really stupid.
评论 #26474673 未加载
评论 #26474219 未加载
tjs8rj大约 4 年前
Why is this a download?<p>My covid project was an SMS news API completely controllable from your phone and delivers short news summaries on any topic scraped from across the web (www.zipnews.io). While fun and it has several paying customers, the SMS can be somewhat expensive to send. The strength is that everyone with a connected cell phone can access the API.
fwn大约 4 年前
The website does not currently work for me. Here&#x27;s a working archive.org mirror:<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20210316074533&#x2F;https:&#x2F;&#x2F;lucky225.medium.com&#x2F;its-time-to-stop-using-sms-for-anything-203c41361c80" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20210316074533&#x2F;https:&#x2F;&#x2F;lucky225....</a><p>If that mirror keeps hiding the text, blocking all inline scripts with uBlock Origin solved it for me.
评论 #26475157 未加载
zimbatm大约 4 年前
Did anybody experiment using Twillio (or similar) to receive 2FA SMS?<p>There are a few service that I use that mandate or only provide SMS as a 2FA. Using Twillio seems rather ideal since they have stricter control to porting numbers. The message probably is harder to intercept as well since it goes to their servers directly. And finally the phone number is harder for an attacker to find out since it&#x27;s not my day-to-day number.
评论 #26475476 未加载
评论 #26475473 未加载
评论 #26474697 未加载
givehimagun大约 4 年前
My bank (USAA) decided to switch their 2FA away from SMS a while ago. They only do email or the USAA app auth code. I love it and I feel much safer with them because of it. Let&#x27;s do start to move away - yes!
评论 #26475794 未加载
评论 #26472648 未加载
评论 #26474166 未加载
herbst大约 4 年前
As someone who does not keep a fixed phone number this reality really sucks. But i dont want security trough something i dont own, and there is no way to actually own a phone number
sdfhbdf大约 4 年前
The link is pointing to 0 content length page with no content type header so it behaves weirdly in for example Safari trying to download.
评论 #26475307 未加载
selfhoster11大约 4 年前
The title is misleading. This is not in fact &quot;stop using SMS for anything&quot;, but &quot;stop using SMS for security purposes&quot;. There is a great reason why SMS should still be in use: nothing interoperable exists with an equal adoption rate. I will not rehash the usual argument about WeChat and Whatsapp, there is plenty of discussion about them.
jfktktmgn大约 4 年前
When dis medium become a paywalled site?<p>Do writers on it know that you can only read 3 articles before you are required to create an account and login? (like pinterest)
评论 #26474384 未加载
评论 #26474660 未加载