Im on t-mobile, but still get many. Also, don't feed the botGet on T-Mobile![]()
Im on t-mobile, but still get many. Also, don't feed the botGet on T-Mobile![]()
It's ridiculous how widespread SMS 2FA is, given how awfully insecure the entire GSM stack is. In some countries anyone can ask for a duplicate of your SIM, with barely any ID checks. We have so many better alternatives to generate OTPs.I wish I can disable SMS 2FA across the board. Many financial institutions require it.
They need to stop robocalls, period.Now they need to stop robo calls from false local numbers.![]()
… and I wish all tech. support will be only within the boarders. So our personal information stays within the country.I wish I can disable SMS 2FA across the board. Many financial institutions require it.
It’s the same deal with email addresses aa login. So many companies won’t let you change that, ever. So you are stuck with an email address you would rather cancel being required for many businesses, or losing your account at ALL those businesses.I really wish SM 2FA would go away. Google, Apple, my bank, and my school plus others require it now. If I were to lose my phone number somehow, I would be in a terrible situation
Definitely....now I started receiving kobo/tele texts.Stop the ROBO/TELE-Markeing calls please.
The article is talking SMS not iMessage😱 I thought Apple had their devices secure. I’ve been told a complete lie.
Theirs is the best system by far. No matter how it's done, 2FA requires you to have a cred on you. If it's SMS, that cred is your SIM card. With Apple 2FA, it's all your devices, and it's easy to set up. New phone, just accept the 2FA on your old one or your Mac.
Google Authenticator (the OTP app) is awful. Perfect example of nerds designing things with only themselves in mind. It's unclear how you transfer the codes to a new device, and it's super easy to just perma lock yourself out of everything. I actually had to experiment with migrating phones because it's undocumented, or at least was.
I agree with everything you said, but I had to call out MS Authenticator too. This app is seriously underrated. I love how they give you a number, then send you a push and you have to pick the matching number. It's so simple and convenient compared to TOTP, where you're manually typing/copy-pasting codes all over the place. And they fully support Apple Watch!Microsoft Authenticator
Those are probably slightly more secure than what I do, but they're too cumbersome for me and impossible for less-techy family members. If you're using iCloud Keychain with randomized passwords, it's vaguely like the benefits of #2 and #3. My Apple 2FA is the gateway to all those websites with no 2FA. Or if they have it, I opt out. If they're able to steal my password as it goes from Keychain to site input, they're probably also able to trick the 2FA. Ofc this only works cause I mostly only use Apple devices, otherwise I'd be doing #4 + a password manager.Funny, I find Apple's MFA to be less desirable than most other MFA that others. Here is my preference, if I have a choice
1) Dedicated apps with push notifications and ability to respond to the notification directly on the device. Best examples are Microsoft Authenticator, Okta, and (surprisingly) Comcast. Regardless of what device I try to log on, i get a push notification to my phone (or iPad) and can approve the request immediately. No need to type a random number in to my computer. Bonus to Apps which allows me to approve on my watch. Plus "passwordless" login on Microsoft Authenticator is awesome when you have in to Microsoft hundreds of times a day for testing purpose.
2) TOTP based solutions integrated with a password manager. I know this is a little bit of preferences. I have my TOTP codes stored in my 1Password vault. Anytime I sign in using 1P, the code is automatically added to my clipboard so I can just type cmd-V to paste the correct code. (Yes, I understand there is a slight loss of security here, but I will take the a little convenience for a very minimal loss of security)
3) Apple 2FA - It works well. One feature I like is that it prompts you a location where the request is coming from. But, it is too cumbersome if you log in regularly. (Acknowledge the request, read the code, but don't hit enter by mistake, type the code again.) Plus, I wish Apple would allow us to designate which devices can receive notification. Maybe I don't want a notification to pop up on the same device I am trying to log in to. (Or do I really need the same notification on three different devices? Mac, iPad, and iPhone.)
4) TOTP based solutions with seperate app. There is no need to use Google Authenticator, there are better TOTP apps such as Authy and Microsoft Authenticator. Both allow you to back and restore your codes to a new device or share codes across devices.
Well there's not much else. TOTP isn't mainstream, and there's email, but many people aren't set up to check that on phones easily. Like TriBruin mentioned, the only good alternative that's widely used is a site-specific 2FA app.It's ridiculous how widespread SMS 2FA is, given how awfully insecure the entire GSM stack is. In some countries anyone can ask for a duplicate of your SIM, with barely any ID checks. We have so many better alternatives to generate OTPs.
I just tried to remove my phone number using this guide: https://support.apple.com/guide/iphone/manage-two-factor-authentication-iphd709a3c46/iosApple no longer requires SMS for 2FA as long as you upgraded from “2-step authentication,” which was deprecated many years ago.
Apple pushes a notification to your devices using APNS, which allows you to receive a six-digit verification code securely.
Time to make new friends. XDThey try to be useful with "scam likely" ID but still ringing anyway in case I'm feeling lucky. And how am I getting SMS messages from email addresses?? Why would I ever want that?
Btw, I just got a slew of 5 spam Facetime calls for the first time. Two were group calls.
I swear if my friend sent me an SMS from an email address, I'd think he's a spy, criminal, or something else I don't want to get involved with. Really they're just from spammers who – evidently – no longer even have to pay for a phone number to spam people over SMS.Time to make new friends. XD