• axx@slrpnk.net
        link
        fedilink
        arrow-up
        7
        ·
        2 months ago

        Briefly: look into sim swapping, which is the most obvious, day to day risk.

        Then there’s SS7 and how inherently trusting the whole system is.

        Then depending on where you are, some mobile networks still have terrible link encryption (were talking so bad a normal laptop is enough these days to break it on the fly). Granted, this is rare these days, in part thanks to the efforts of Karsten Knohl, SRLabs and other security researchers who did a lot to shine a light on this and SS7

        Not sure how up to date it still is, but https://gsmmap.srlabs.de/ shows how unequal networks are.

        • Hawke@lemmy.world
          link
          fedilink
          arrow-up
          2
          arrow-down
          4
          ·
          2 months ago

          That’s all sms though, not 2fa in general.

          All valid points and good information within that scope.

          • Appoxo@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            2 months ago

            (…) and sms is an insecure system to begin with.

            citation needed on the second half

            That’s all sms though, not 2fa in general.

            Are you an LLM?

              • Appoxo@lemmy.dbzer0.com
                link
                fedilink
                arrow-up
                2
                ·
                edit-2
                2 months ago

                The edit icon is a bit not-obvious in Voyager…
                And I can’t view the original text.

                Edit: Speeling on a phone is hard (read: annyoing)

  • Tomtits@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 months ago

    Logged into what?

    What’s a Sprint store?

    If it’s a shop that sells electronics like Currys or Mediamarkt then why would this person log into anything on display?

    • jayands@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      2 months ago

      Sprint is was a phone carrier in North America (pretty sure just the US, but they may have been in Canadia, too)

      • kboos1@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        edit-2
        2 months ago

        They’re called T-Mobile now they merged or bought them, I don’t remember. T-Mobile is owned by Deutsche Telekom

      • BurntWits@sh.itjust.works
        link
        fedilink
        arrow-up
        5
        ·
        2 months ago

        No it was USA only. We have three mobile carriers that own all the cell towers here. You’re either with Rogers, Bell, or Telus, or one of their derivatives. There’s zero competition here, it’s ridiculous.

    • TORFdot0@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 months ago

      Do you blame the locksmith if you lose your keys?

      I could take the locks off the door to my house but then I can’t be mad when I get robbed

      Edit: I hope that the lesson learned is about needing to have multiple forms of MFA and a safe location for back up codes, like you would have multiple sets of keys and maybe a key box hidden in a safe place. Not blaming you for not realizing it at the time, it’s not something one would think about until it’s too late. It’s not like we had our parents to teach us about MFA best practices like you might have for house keys

    • theunknownmuncher@lemmy.world
      link
      fedilink
      arrow-up
      6
      arrow-down
      2
      ·
      2 months ago

      You didn’t print out or write down the codes they give you for this exact situation? 100% your fault and not 2FA’s

      • PotatoesFall@discuss.tchncs.de
        link
        fedilink
        arrow-up
        3
        arrow-down
        2
        ·
        2 months ago

        Google doesn’t give you codes. They don’t even tell you that they enabled 2FA. If you log in on an android device, they will automatically enable it for 2FA, and for some reason they assume you will have access to this phone until the end of time, even if you haven’t turned it on in months. The only way to go around this is to set up 2FA manually.

        Google has locked so many people I know out of their accounts it’s ridiculous.

          • PotatoesFall@discuss.tchncs.de
            link
            fedilink
            arrow-up
            1
            ·
            2 months ago

            Yeah if you’re smart with the computor like me and you then you keep your 2FA backup somewhere. But if you’re just a normal person, it doesn’t occur to you. Google doesn’t even do a very good job reminding you to properly set up 2FA in the first place.

      • Herbal Gamer@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        True but also I wasn’t there when other people had to clear out my apartment so I didn’t have much of a clue wether or not it would be saved.

        Still know my pw managers pw by heart and have my gmail account pw written down but not that actual code, no.

  • MidsizedSedan@lemmy.world
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    2 months ago

    A non-tech store had some iPhones and iPads on display. No internet. But it COULD connect to my phone hotspot. Wish I did something more than just download a rainbow six siege pic and set it as the wallpaper, but they took down that demo for I think close to a month.

  • spacegoat@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    2 months ago

    Timmy was later arrested and charged with violations of the CFAA, SCA, and ECPA. He faces 20 to life.

  • FudgyMcTubbs@lemmy.world
    link
    fedilink
    arrow-up
    6
    arrow-down
    4
    ·
    2 months ago

    I dont care for 2fa. Not interested in having my phone connected to my computer, and i dont like having an extra step when logging into stuff – especially an extra step that needs me to use a second device. Id honestly rather risk getting hacked over ever having to use 2fa again.

    • chloroken@lemmy.ml
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 months ago

      This makes me mad but I have absolutely no justification. Like, it’s your life. But I am incensed. Godspeed.

    • greenMeanHoppinMachine@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      2 months ago

      Use a Yubikey. It’s a small USB Device you can put on a keychain. It is still a second device, but it’s not your phone. And you always have your keys with you, anyway.

    • Honytawk@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      2 months ago

      Why do you think you need to connect your phone to your computer?

      You do know you can just generate codes and neither device will know of the others existence, right?

      • FudgyMcTubbs@lemmy.world
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        2 months ago

        I have no reason to believe that the google authenticator app on my google phone doesn’t register and record that it’s being used to log into XYZ website, and further that XYZ website is not then sending back unique identifying info to Google about me when ive used the code to log in.

        I’ve lived with tech long enough to know that if they say “we absolutely don’t,” it really means they probably do.

        Like when they swore up and down and gaslit us that our phones aren’t listening to us to generate ads.

        How many lies can I believe before I begin assuming everything is just another lie from a liar?

        Guess im paranoid.

        But that whole thing ignores that it’s an annoying second step with another device. Like “you want to log in? Thread a needle with the string in your pocket first…”

        • hoppolito@mander.xyz
          link
          fedilink
          English
          arrow-up
          6
          ·
          2 months ago

          But then just don’t use google authenticator and instead one of the FOSS alternatives? Aegis comes to mind.

          Like the original reply to your situation said, you do you - but this seems a weird threat model to me, extra-step point notwithstanding.

    • axx@slrpnk.net
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      2 months ago

      MFA (a better term IMO for this) has nothing to go with phones, per se.

      It’s just about reducing risk by adding more proofs that the person claiming to have the right to do something has indeed the right to do something.

      Unless you have excellent password hygiene (long, random, different for every single site and service) the likelihood of having an account taken over goes up quite fast. The overwhelming majority of the population doesn’t, so forcing a second factor is a good way to limit damage.

      If you don’tt like the multi step process, look at psskeys. They aren’t perfect, but they offer nearly all the security benefits of MFA without having to go throughthrough multiple steps.