Malicious SS7 activity and why SMS should never by used for 2FA
jackson.tim at gmail.com
Sun Apr 18 01:25:03 UTC 2021
Every SMS 2FA should check the current carrier against the carrier when
enrolled and unenroll SMS for 2FA when a number is ported out. BofA and a
few others do this.
On Sat, Apr 17, 2021, 8:02 PM Eric Kuhnke <eric.kuhnke at gmail.com> wrote:
> Anecdotal: With the prior consent of the DID holders, I have successfully
> ported peoples' numbers using nothing more than a JPG scan of a signature
> that looks like an illegible 150 dpi black and white blob, pasted in an
> image editor on top of a generic looking 'phone bill'.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the NANOG