🚨 #CoSoSec 🚨
Hackers Are Breaking Directly Into Telecom Companies to Take Over Customer Phone Numbers
SIM swappers have escalated from bribing employees to using remote desktop software to get direct access to internal T-Mobile, AT&T, and Sprint tools.
@jordicusmaximus
Absolutely, but a surprising number of very large companies only support MFA via SMS.
@th3j35t3r @voltronic I mean, to be fair, CoSo ain't your typical IT picnic basket when it comes to infosec. 😉
@jordicusmaximus @th3j35t3r
Yup, I've got Authy enabled here, and CoSo also lets me use my preferred 128 random-character generated passwords as well. Stick that in your rainbow table and smoke it.
Oddly enough Google supports passwords of that length, but one of my banks is only 32 (and only SMS or email for MFA).
@voltronic @jordicusmaximus
Not here! In fact, we don't support SMS MFA at all here.