535 karma · joined June 18, 2009
- how many sales you need per day - how many sales you need per month - monthly traffic
There’s a lot more at play here, and “just don’t” isn’t a nuanced enough answer to 2FA by SMS.
* Applications that take a phone number for one reason (2FA or otherwise) and also use it as a single factor for account reset are less secure in the case of number recyling.
* Applications that do 2FA via SMS do not necessarily do account resets via SMS
* 2FA over SMS is more secure than just having a password to secure an account.
I am sorry your girlfriend had this problem. I would have hoped a business like Facebook would better understand phone number usage. Their penchant for taking as much data as they can and using it however they like clearly burned some of their users here. I hope they have tightened up this hole and that this didn't affect too many people.
You shouldn't find yourself in too much trouble in a browser if you add an attribute to an element that it doesn't understand though, it will just ignore it.
But if building and maintaining app based TOTP using a library is good enough for you, then go for it. I'm certainly not going to make you use Twilio's APIs, but plenty of businesses do see the benefit.
I've updated the post, thank you for your help!
I'm not advocating for poorly implemented 2FA, just that SMS 2FA is more secure than just a password.
If a site required you to have a 32 character length password, but kept the passwords in plain text, that wouldn't make your password any less strong. It just opens a different attack vector. If a site implements 2FA via SMS, but allows password reset via SMS it doesn't make SMS 2FA less secure, it makes that sites implementation incorrect.
The nice thing about using autocomplete with username and current-password is that it can help your password manager auto fill these fields across pages if they are implemented like this.
At Twilio, we have APIs for two factor authentication and we recommend implementing via push notification to the Authy app with “approve” and “deny” buttons. This is more secure and a better experience than SMS. The API also allows for regular app based 2FA, with a TOTP code, which is more secure than SMS. But it also allows you to fallback to SMS, which is still more secure than no 2FA.
You do have to consider the threat model for your own application when considering these sort of security measures. If the value of an account takeover is high then a targeted attack can, and will, break SMS 2FA. Which is why the Twilio 2FA API allows you to turn off SMS 2FA if you choose.
Ultimately I’d prefer SMS over nothing when it comes to 2FA, but I also encourage developers to use more secure options that can also have a better experience.
In this case the desktopCapture API was introduced in Chrome 34 but arrow functions only turned up in version 45 onwards.
You can set a minimum Chrome version in the extension manifest though, which would mean you can set a version that guarantees the JS support that you want.
* Copy/paste (holding on an article gives the options to email or report)
* Pinch to zoom
* Double tap to zoom (opens links instead)
* iOS swipe forwards and backwards (renders the page swipe animation twice, at 60fps I guess)
* iOS Reader View (go on, try it, I laughed)
And most importantly
* Any sort of accessibility
60fps doesn't matter to someone who can't see the screen.
60fps doesn't matter to someone who relies on assistive technologies to surf the web.
60fps doesn't really matter.
I'm disappointed they're dropping the Raptor name, it just sounds so much better than "Phusion Passenger".