Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You know what's funny? LinkedIn is supposed to be a 'professional' social network (Microsoft owned) and a friend of mine was asked to add a phone number 'For security purposes'. I knew this was suspiciously involving 2FA SMS + a bonus of spam callers and I told him to press "Not Now". Whilst the world is moving to U2F and time-sensitive codes, a security system using SMS 2FA is now equivalent to a single PC running Windows XP in a bank.

But its not just LinkedIn. Its a huge list of major companies including some FAANG ones too. Oh dear.



Not true. Not true by far. That's an over statement. 2FA is only one of two factors, you need the the password, you need the mobile number and you need to obtain a duplicate or being close to your victim.

You should be worried if you are a POI or you are being targeted personally. And if it is so, SIM Swapping it's just one option and if it doesn't work there are other methods (breaking in, stealing yubikeys, mobiles...)


You don’t always know if you are a target.


LinkedIn is absolute scum in that regard. They pestered me for my number for ages until eventually they finally implemented TOTP 2FA which I then enabled.

They still ask for a phone number when applying to jobs through their platform. I always put zeros or random digits in the field and put the real one in the resume.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: