Navigation
Recherche
|
Feds Warn SMS Authentication Is Unsafe
jeudi 19 décembre 2024, 22:33 , par Slashdot
'Do not use SMS as a second factor for authentication. SMS messages are not encrypted—a threat actor with access to a telecommunication provider's network who intercepts these messages can read them. SMS MFA is not phishing-resistant and is therefore not strong authentication for accounts of highly targeted individuals,' the guidance, which has been posted online, reads. Not every service even allows for multi-factor authentication and sometimes text messages are the only option. But when you have a choice, it's better to use phishing-resistant methods like passkeys or authenticator apps. CISA prefaces its guidance by insisting it's only really speaking about high-value targets. The telecommunications hack mentioned above has been called the 'worst hack in our nation's history,' according to Sen. Mark Warner (D-VA). Read more of this story at Slashdot.
https://tech.slashdot.org/story/24/12/19/2132228/feds-warn-sms-authentication-is-unsafe?utm_source=r...
Voir aussi |
56 sources (32 en français)
Date Actuelle
ven. 20 déc. - 12:26 CET
|