this post was submitted on 12 Sep 2026
58 points (98.3% liked)

Technology

87972 readers
2775 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] SnotFlickerman@lemmy.blahaj.zone 34 points 2 hours ago (1 children)

Open source FIDO2 keys, KeePassXC, and Aegis.

SMS 2fa has always been a bad deal

[–] Brewchin@lemmy.world 22 points 2 hours ago (1 children)

I'll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

[–] Crumpled6273@lemmy.ca 12 points 2 hours ago* (last edited 2 hours ago) (1 children)

Because many services only have SMS as 2FA option. Especially government services.

Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying "unable to verify".

[–] cmnybo@discuss.tchncs.de 2 points 1 hour ago

I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn't ask for a phone number to sign up back then.

I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it's still an option though.