• @Cocodapuf
    link
    English
    10
    edit-2
    5 hours ago

    Since when was sms ever secure? My understanding is that messages are sent in the clear, meaning your carrier and the recipient’s carrier both have the opportunity to intercept messages.

    I mean that’s the message content, not the authentication, but still, sms is the opposite of secure, always has been.

    • @[email protected]
      link
      fedilink
      English
      54 hours ago

      Not true. SMS is encrypted in 3G, LTE, 5G. Block cyphers like Kasumi and A/9 are used. SMS is reasonably secure, because it’s hard to infiltrate telecom systems like S7

      • @[email protected]
        link
        fedilink
        English
        44 hours ago

        It’s hard, but not hard enough from what I’ve been able to gather. We should want something better IMO. I’m surprised that TOTP isn’t more common.

        • @[email protected]
          link
          fedilink
          English
          33 hours ago

          S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.