Jump to content

Google: Compromised passwords notification


NanLaew

Recommended Posts

Banks and financial institutions seem to be using OTPs as standard now, not just for cash transfers but simply logging on. I'm fine with that, getting an SMS, but one of my backward banks wants to make an automated phone call which costs money everytime

Link to comment
Share on other sites

OTP in SMS is insecure as well because any Nigerian mobile phone operator could announce your phone number in ANY country and city, not only within Nigeria borders, and could intercept your SMS's.

google:// ss7 otp interception

 

the funny thing is - many years ago banks were giving dedicated OTP devices (like a small flash drive) or cards filled with printed one-time-passwords but somewhy it became considered insecure and banks switched to OTP in SMS instead. But in fact the dedicated OTP devices or printed OTP cards are secure and [almost] unbreakable.

  • Haha 1
Link to comment
Share on other sites

On 5/4/2021 at 1:59 PM, l4ml4m said:

 

 

yes this is stupid, but who is idiot enough to use website name + 12345 ?

maybe it is what you would use ?

 

 

 

 

You should consider more that kind of people use this forum...

 

 

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.




×
×
  • Create New...