Twitter to be fined $250M for using 2FA numbers for ads
techdirt.com
techdirt.com
Most people/groups who phish are pretty technically inept so they struggle to automate things like OTP capture/use, so they're stuck doing it live, and that obviously doesn't scale well.
It's better than nothing, but given that it's trivial to go from that to just an authenticator app, I would personally not have any of my accounts set up to accept sms 2FA.
Of course, the best thing would be for people to use actual passwords instead of "Watermelon23", but that's easier said than done.
When sites require this crap, I give them a phone number that forwards to my email. If my desktop computer gets owned, I've got much bigger problems than some fraudulent bank transactions.
Think about it this way: for an attacker trying to compromise more than one account, SMS-based 2FA makes it significantly more expensive to perform the attack. It certainly isn't much help as the victim of a targeted attack, but it makes account takeovers much more difficult in 99% of cases.
That's an interesting wording. I would say it's making money off your data than their content.
In other situations, we'd normally call this doxing.
No we wouldn't.
If you're going to complain about ads, but still want the content, then shutup and pay the website for it. You're not going to do that either, though. Want to have your cake and eat it too?
No, instead (generic) you just wants free content. (Generic) you isn't going to pay $12.99 monthly per website to support the content and operation costs. (Generic) you just wants free stuff.
How many people on HN complain about Paywalled websites and immediately seek ways to circumvent the paywall? Paywalls are the alternative.
There's real costs with running a website - even more-so with producing content people are interested in (clearly evidenced by front page of HN).
Or, just use an Ad Blocker and be on with your day. It's the complaining that's annoying - and petty. Solutions to your perceived problem are super easy and well within reach. It's literally 3 clicks to install uBlock Origin.
HN readers typically know how to deal with ad blockers, our less technical fellows don't, and we ultimately owe them to work against this bullshit, like we expect them to steer their respective fields and professions to the common benefit, that they make their products and services healthy and safe.
A computer literally heating up due to who knows what arbitrary javascript is executed on that person's computer is notable, and the advertising-tech-complex is very much on topic for HN.
Finally, there can be NO DEAL between a website visitor and a bunch of third party javascript that cannot be understood or audited, and if the operation is not profitable, tough. There were cool websites on the internet before ads and we will have websites in the future.
The overwhelming majority of Spotify accounts are Free Accounts, supported by... you guessed it... Ads.
People don't torrent music because Spotify is easier. Spotify earns money through advertisers paying them to advertise on their platform. Spotify pays part of that to artists who put music on their platform. Everyone is getting paid, and it costs the user nothing. That's why Spotify is so popular.
> There were cool websites on the internet before ads and we will have websites in the future
What is it your are arguing for? Charging $0.35 per every single page view? Or people running websites should just foot the bill out of the goodness of their hearts? Someone has to pay the hosting bill...
Some of the tech-elites on HN will pay this out of principle, but the overwhelming majority of people will not. Be realistic.
A world where you must pay for every page view is effectively antithetical to everything the web stood for. The _free_ distributions of knowledge to everyone simply would cease to exist.
It's actually amazingly clever. We've tricked 3rd party advertisers into footing the bill for literally _everything_ on the internet. You are free to consume content without paying a single penny - someone else is paying it for you. The trade? You gotta look at some ads once in a while. Oh the humanity!
If someone is this principled - they should run an Ad Blocker. Most people simply don't care. You can make a case that they should care, but then you'll need to come with with a robust system to pay content creators to ensure they aren't buried in expenses of running a website for a bunch of freeloaders.
There is also no contract, no trade. People go on a website, ignore any and all terms of services and privacy notes and try to read what's up. Presenting such terms of services etc. is acting in bad faith (as no layperson is able to understand it and no lawyer has time to read all of it). Third party code is executed on their computer. Could be bitcoin miners or even ransomware.
Your example with spotify may be true, but you can't ignore that Netflix and others are raking in a lot of money and provide a really expensive product (compared to website articles which yes, were produced for free by many people for years, on some level). I used to subscribe to The Athletic and will probably do so again if there's football in autumn.
I really wouldn't mind seeing some ads. On a shoe website, see a banner ad for shoes, with a hyper link to another shoe website. No tracking, no code, just a link.
I think the problem there is those types of ads aren't effective. And therefore, advertisers won't pay for them, which then goes back to the original problem of "who's paying the hosting bill"? Let alone paying the salaries of a dozen journalists or content creators.
If tastefully done, ads can be discrete and effective. There are bad apples out there, who plaster every pixel of page space with ads and more ads and more ads.
I don't think anyone enjoys that experience - but that's not the ads fault, it's the webmaster who did it! Eventually, that strategy won't pay for itself anymore as people stop using the website.
Netflix is a strange thing to relate to here, I think. People have always paid for movies - so I think it was a natural progression to pay for a movie streaming service.
Websites have mostly always been free - and the ones that successfully run a subscription model absolutely limit their market appeal and userbase. Making people pay for every page view (the effective equivalence of running impression-based ads) is simply not going to work; you'll have an immense challenge to convince people what was previously "free" is now going to cost them actual money directly from their bank account.
At the end of the day, there's two arguments going on here.
1) Tracking is a violation of expected privacy, and should not be done.
2) Ads are bad and should go away.
Number 1 is true! However, the result of stopping would be unrelated ads being shown to people with practically zero percent chance of converting into a transaction for the advertiser (showing diaper ads to a single man that lives by their self, for example). That could be fine, but again, reduces advertising effectiveness which means advertisers will pay less for the ad space. This could work... but will have ramifications that are potentially not great (more paywalls, for example).
Number 2, in my opinion, isn't true, and isn't realistic for the reasons laid out above.
You aren't new here. Whatever you said, I stopped reading here.
"Out of the box, these lists of filters are loaded and enforced:
- EasyList (ads)
- EasyPrivacy (tracking)
- Peter Lowe’s Ad server list (ads and tracking)
- Malware domains"
[0] https://chrome.google.com/webstore/detail/ublock-origin/cjpa...
[0] https://www.investopedia.com/ask/answers/102915/are-irs-pena...
https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
Comcast is just giving it to the highest bidder.
Start with maybe 3-6 months, then escalate for repeat offenders. That fact that these decisions were made internally to a business should not indemnify the executives who allowed it to happen from criminal charges with mandatory prison time that cannot be suspended or avoided.
I'm guessing that number has no protections the way 2FA ones do?
You can easily generator OTP codes the same as any of the "authenticator" apps using, for example, oathtool [1]
You don't even need the code to be stored on a computer. Just write it down somewhere safe if you're paranoid about getting hacked. The seed codes are usually 16 characters or so.
How exactly does this happen?
Or bribe company staff to give you the SIM card.
Phone company staff are error-prone humans just like you and me who in general don't earn well enough for their responsibilities.
That makes a lot more sense. Thanks!
Whether you consider the SIM swap attack a threat worth protecting from would depend on many factors, even though the threat itself is very real, and almost all phone numbers are vulnerable to the attack. I have yet to learn any phone service provider that is not vulnerable to this attack. I've heard people speculating that Google Fi might be one such provider, but I don't know if Fi customer service actually is not vulnerable.