zlacker

[parent] [thread] 1 comments
1. renonc+(OP)[view] [source] 2023-11-16 17:43:03
For the purpose of 2FA and account registration let’s view it as a tax for fraud prevention, where the real value in SMS is in verifying someone’s identity rather than transmitting messages
replies(1): >>peanut+zd
2. peanut+zd[view] [source] 2023-11-16 18:47:07
>>renonc+(OP)
If SMS actually worked for this purpose, it would be acceptable. However, SMS provides no guarantees about: 1) If it actually gets delivered 2) If it is delivered to the intended recipient 3) 1 and 2 without anyone reading or tampering the message while in transit

Now, even if stars align, your SMS ends up on a route where nobody is mitm-ing or hijacking it, the telco systems work and it gets delivered, it is STILL not a guarantee of identity. It simply verifies that you have somehow got access to a particular phone number.

[go to top]