You are viewing a single thread.
View all comments View context
5 points

Not true. SMS is encrypted in 3G, LTE, 5G. Block cyphers like Kasumi and A/9 are used. SMS is reasonably secure, because it’s hard to infiltrate telecom systems like S7

permalink
report
parent
reply
5 points
*

because it’s hard to infiltrate telecom systems like S7

cough You can pay a few grand and get access to SS7 networks.

Might be out of reach for most of us, but we can rest assured that any and all security firms and goverrnment agencies have access to this information at a moment’s notice.

permalink
report
parent
reply
3 points

Simply paying is not sufficient. You need to be a telecom company, or a researcher afaik.

In what world would the US gov care to get into your bank account? Or your Facebook account when it’s already tightly controlled?

permalink
report
parent
reply
6 points
*

it’s hard to infiltrate telecom systems like S7

Telecom systems can be (and are) infiltrated though, which is what the FBI is warning about.

SS7 is very insecure. See this video, too: https://www.youtube.com/watch?v=wVyu7NB7W6Y

permalink
report
parent
reply
2 points

Watch the video again to see how hard it was for Derrick to get access. He got it via his telecom/academia researcher contact.

permalink
report
parent
reply
5 points

It’s hard, but not hard enough from what I’ve been able to gather. We should want something better IMO. I’m surprised that TOTP isn’t more common.

permalink
report
parent
reply
4 points

S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.

permalink
report
parent
reply
3 points
*

Nah what we need is good privacy-focussed companies getting into the public IAM space.

You know how you can sign into stuff with your Google or Facebook account? And get a 2FA push to your phone?

Like that. Except by a company with a shred of ethics and morality. Like Proton.

I do also think that we all should have a cryptographically secure federally issued identity for official uses such as signing documents or signing into financial accounts and other things that must use your official identity, and not an online pseudonym. Like SSN but on a smartcard. Basically CAC or ECA but for general civilian use.

permalink
report
parent
reply
1 point

You can use TOTP with multiple devices. For example with an app on your phone and something like KeePass on your laptop/desktop.

Still not convenient since you don’t walk around with this in your pocket - but it doesn’t have to be just one point of failure.

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 15K

    Monthly active users

  • 6.7K

    Posts

  • 153K

    Comments