Close Menu
Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Subscribe
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Home»Tech»CCC: Please enable 2FA, but not via SMS
    Tech

    CCC: Please enable 2FA, but not via SMS

    Theodore MeeksBy Theodore MeeksJuly 12, 2024No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    CCC: Please enable 2FA, but not via SMS
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    The Chaos Computer Club (CCC) computer security association warns against using two-factor authentication (2FA) via SMS. In addition to the known attacks to intercept messages with one-time passwords, they now show another attack scenario.

    advertisement

    In order to effectively secure online accounts, you should enable two-factor authentication wherever possible. Due to this extra layer of protection, in addition to the password, you also need a login code, which is sent to the account holder via SMS or an authentication app. Accordingly, a leaked password is not enough for attackers to hack into an online account.

    But by swapping the SIM card or attacking the SS7 communications standard, attackers can intercept SMS messages and view the codes. By swapping the SIM card, attackers attempt to take over the SIM card and thus the victim’s phone number and identity. Now in a report, the CCC outlines another way SMS messages for one-time two-factor authentication (2FA) passwords are insecure.

    2FA codes are available online.

    Many companies that offer two-factor authentication to their customers rely on the service provider to send SMS messages. According to their own information, security researchers have now been able to view nearly 200 million 2FA codes from SMS service provider IDIDMobile. According to their statements, they were “in the right place at the right time.”

    Since the SMS sender shares 2FA codes in real time on the Internet, they were able to see one-time passwords and even phone numbers and senders’ names by guessing a subdomain (“idmdatastore”). In this case, it is clear that the service provider acted with gross negligence and did not provide adequate protection for sensitive customer data.

    The CCC says that over 200 companies including Amazon, DHL and Facebook work with DefateMobile. It is currently unclear whether criminals can also view the data.

    Conclusion

    Two-factor authentication certainly provides more security, but account holders should disable sending two-factor authentication codes via SMS and instead use an app like Google Authenticator, which generates codes locally on the device. Alternatively, you can also use a passkey for added account security.


    (to)

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Theodore Meeks

    Lifelong foodaholic. Professional twitter expert. Organizer. Award-winning internet geek. Coffee advocate.

    Related Posts

    Neodymium Magnet Uses and Safety Tips for 2025

    October 4, 2025

    Halifax Stanfield Airport Pilots Passenger Service Robots in Bid to Boost Traveler Experience

    August 25, 2025

    Battery miracle in test – HP Omnibook X AI: If it takes longer again

    August 29, 2024
    Navigate
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Pages
    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    STAY UPTODATE

    Get the Latest News With Aviationanalysis.net

    OFFICE

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    QUERIES?

    Do you have any queries? Feel free to contact us via our Contact Form

    Visit Our Office

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.