this post was submitted on 12 Sep 2026
164 points (95.1% liked)

Technology

87980 readers
2518 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] SnotFlickerman@lemmy.blahaj.zone 66 points 8 hours ago (2 children)

Open source FIDO2 keys, KeePassXC, and Aegis.

SMS 2fa has always been a bad deal

[–] urushitan@kakera.kintsugi.moe 5 points 3 hours ago* (last edited 3 hours ago) (2 children)

Signal doesn’t offer anything except sms 2fa and requires a phone number. It’s a terrible choice considering LEO can do what they did here and just get legal access to MITM your sms messages, spoof the 2fa, and take over your account, impersonating you. The other ones aren’t encrypted. So none of these they broke into are great choices for truly secure messaging.

[–] jungle@lemmy.world 1 points 13 minutes ago

The other ones aren’t encrypted.

Whatsapp is encrypted as far as I know. But then again, it's Meta, so my trust in that is near zero.

[–] Zak@lemmy.world 4 points 3 hours ago

They can only impersonate you that way if your contacts dismiss the warning about your safety number changing. If you're being directly targeted by the government of a wealthy country, using a specific app isn't enough to prevent surveillance; you'll need some actual opsec.

[–] Brewchin@lemmy.world 37 points 8 hours ago (1 children)

I'll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

[–] Crumpled6273@lemmy.ca 35 points 7 hours ago* (last edited 7 hours ago) (2 children)

Because many services only have SMS as 2FA option. Especially government services.

Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying "unable to verify".

[–] Yaky@slrpnk.net 3 points 5 hours ago (1 children)

You can have a Google account without 2FA, but you need to create it using a factory-reset old Android phone (Android 8 or so).

[–] Imgonnatrythis@sh.itjust.works 2 points 4 hours ago

Why are people even complaining about this then?!

[–] cmnybo@discuss.tchncs.de 5 points 7 hours ago (1 children)

I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn't ask for a phone number to sign up back then.

I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it's still an option though.

[–] Zarobi@aussie.zone 4 points 4 hours ago

Watch out, if those accounts are ever "locked", you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn't work but it broke the account. Secondary recovery email address and correct password wasn't good enough. Support basically told me to give up and make a new account (???).