Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
sabreW4K3 ( sabreW4K3@lazysoci.al )  to Technology · 2 years ago

Google binning SMS MFA and replacing it with QR codes • The Register

www.theregister.com

external-link
message-square
11
link
fedilink
38
external-link

Google binning SMS MFA and replacing it with QR codes • The Register

www.theregister.com

sabreW4K3 ( sabreW4K3@lazysoci.al )  to Technology · 2 years ago
message-square
11
link
fedilink
Google binning SMS MFA and replacing it with QR codes
www.theregister.com
external-link
Everyone knew texted OTPs were a dud back in 2016
alert-triangle
You must log in or # to comment.
  • Moonrise2473 ( Moonrise2473@feddit.it ) 
    link
    fedilink
    arrow-up
    24
    ·
    2 years ago

    The real reason is that they want to save money on the text messages (outside of the US they need to pay $0.05 each time), not because they actually care about user security.

    Like when xitter ran out of money and didn’t pay their sms bills and people were locked out of their accounts

    • lime! ( lime@feddit.nu ) 
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 years ago

      i mean, it’s also a security issue. sms is plaintext all the way from them to you.

      • t3rmit3 ( t3rmit3@beehaw.org ) 
        link
        fedilink
        arrow-up
        4
        ·
        2 years ago

        Also, it’s dead simple to send someone else (or tell them over the phone) 6 numbers, when you’re being phished. Much harder for people to send someone a QR code.

  • smeg ( smeg@feddit.uk ) 
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 years ago

    Sadly the article is very light on how this actually works. I’m guessing it involves setting up an authenticator on the phone (something they encourage anyway) and just using a QR code as a new way of interacting with it?

  • megopie ( megopie@beehaw.org ) 
    link
    fedilink
    arrow-up
    8
    ·
    2 years ago

    How am I supposed to scan a QR code sent to my phone… with my phone?

    • JackOverlord ( JackOverlord@beehaw.org ) 
      link
      fedilink
      arrow-up
      3
      ·
      2 years ago

      On Android you can use Google Lens or, if you don’t want to use Google products, any random QR code scanner app.

      No idea about iPhone as I’ve never owned one, but I’d assume most QR code scanners can do that there as well.

  • Hazelnoot [she/her] ( hazelnoot@beehaw.org ) 
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 years ago

    I’m confused about how this is supposed to act as a second authentication factor 🤔

    • FiskFisk33 ( FiskFisk33@startrek.website ) 
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      2 years ago

      A guess/suggestion:

      You have an app with a private key. The qr code contains data encrypted with the corresponding public key. Your app decrypts the data and transmits it to googles servers, proving you are in possession of the secret key.

      • Hazelnoot [she/her] ( hazelnoot@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 years ago

        oh so it would just be app-based MFA but without using TOTP. That makes sense

  • Visikde ( Visikde@beehaw.org ) 
    link
    fedilink
    arrow-up
    6
    ·
    2 years ago

    Qrs don’t seem safe to me
    Scanning a Qr allows the installation of malware apps so I can look at a restaurant menu, & ding my card for recurring charges?

    • Hirom ( Hirom@beehaw.org ) 
      link
      fedilink
      arrow-up
      2
      ·
      2 years ago

      The devil’s in the details. And there aren’t much details in this article.

Technology

technology

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@beehaw.org

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 166 users / day
  • 1.05K users / week
  • 2.2K users / month
  • 5.22K users / 6 months
  • 5.11K local subscribers
  • 43.6K subscribers
  • 6.39K Posts
  • 107K Comments
  • Modlog
  • mods:
  • Chris Remington ( remington@beehaw.org ) 
  • alyaza [they/she] ( alyaza@beehaw.org ) 
  • TheRtRevKaiser ( TheRtRevKaiser@beehaw.org ) 
  • gyrfalcon ( gyrfalcon@beehaw.org ) 
  • rs5th ( rs5th@beehaw.org ) 
  • coldredlight ( coldredlight@beehaw.org ) 
  • Leigh ( SemioticStandard@beehaw.org ) 
  • TheRtRevKaiser ( TheRtRevKaiser@kbin.social ) 
  • BE: 0.19.15
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code