Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Take a modified attackers point of view.

Could you convince a cell phone store rep that you are who you say you are without your drivers license?

Or, for a million bucks, could you make a cell phone store rep think you were someone else?

The answer is why SMS 2fa isn't such a great idea. Because your security checkpoint is owned by a (underpaid) store representative.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: