Malicious SS7 activity and why SMS should never by used for 2FA

John Levine johnl at iecc.com
Mon Apr 19 18:11:18 UTC 2021


It appears that William Herrin <bill at herrin.us> said:
>> If a key fob can be sent to them - preferably for free - that would help.
>
>Hint: carrying around a separate hardware fob for each important
>Internet-based service is a non-starter. Users might do it for their
>one or two most important services but yours isn't one of them.

You think?

https://obvious.services.net/2013/07/better-have-big-pockets-if-you-want.html

R's,
John


More information about the NANOG mailing list