Navigation
Search
|
Feds Warn SMS Authentication Is Unsafe
Thursday December 19, 2024. 10:33 PM , from Slashdot
'Do not use SMS as a second factor for authentication. SMS messages are not encrypted—a threat actor with access to a telecommunication provider's network who intercepts these messages can read them. SMS MFA is not phishing-resistant and is therefore not strong authentication for accounts of highly targeted individuals,' the guidance, which has been posted online, reads. Not every service even allows for multi-factor authentication and sometimes text messages are the only option. But when you have a choice, it's better to use phishing-resistant methods like passkeys or authenticator apps. CISA prefaces its guidance by insisting it's only really speaking about high-value targets. The telecommunications hack mentioned above has been called the 'worst hack in our nation's history,' according to Sen. Mark Warner (D-VA). Read more of this story at Slashdot.
https://tech.slashdot.org/story/24/12/19/2132228/feds-warn-sms-authentication-is-unsafe?utm_source=r...
Related News |
25 sources
Current Date
Dec, Fri 20 - 18:26 CET
|