🚨 #CoSoSec 🚨
Hackers Are Breaking Directly Into Telecom Companies to Take Over Customer Phone Numbers
SIM swappers have escalated from bribing employees to using remote desktop software to get direct access to internal T-Mobile, AT&T, and Sprint tools.
This is a good reminder to not use text messing to your cellphone for two factor authentication on your accounts, and always use an authenticator app.
@jordicusmaximus
Absolutely, but a surprising number of very large companies only support MFA via SMS.
Not here! In fact, we don't support SMS MFA at all here.
@jordicusmaximus @th3j35t3r
Yup, I've got Authy enabled here, and CoSo also lets me use my preferred 128 random-character generated passwords as well. Stick that in your rainbow table and smoke it.
Oddly enough Google supports passwords of that length, but one of my banks is only 32 (and only SMS or email for MFA).