• BTC Dominance: %
XBT.Market
Advertisement
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us
No Result
View All Result
XBT.Market
No Result
View All Result
Home Bitcoin

CertiK says SMS is the ‘most vulnerable’ form of 2FA in use

Jon Hartney by Jon Hartney
September 28, 2022
in Bitcoin, Blockchain, Business, Market
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

The level of security provided by SMS pales in comparison to authenticators or physical security keys, CertiK’s Jesse Leclere says in an interview.

Using SMS as a form of two-factor authentication has always been popular among crypto enthusiasts. After all, many users are already trading their cryptos or managing social pages on their phones, so why not simply use SMS to verify when accessing sensitive financial content?

Unfortunately, con artists have lately caught on to exploiting the wealth buried under this layer of security via SIM-swapping, or the process of rerouting a person’s SIM card to a phone that is in possession of a hacker. In many jurisdictions worldwide, telecom employees won’t ask for government ID, facial identification, or social security numbers to handle a simple porting request.

Related articles

Bitcoin derivatives data shows room for BTC price to move higher this week

January 23, 2023

Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher

January 22, 2023

Combined with a quick search for publicly available personal information (quite common for Web 3.0 stakeholders) and easy-to-guess recovery questions, impersonators can quickly port an account’s SMS 2FA to their phone and begin using it for nefarious means. Earlier this year, many crypto Youtubers fell victim to a SIM-swap attack where hackers posted scam videos on their channel with text directing viewers to send money to the hacker’s wallet. In June Solana NFT project Duppies had its official Twitter account breached via a SIM-Swap with hackers tweeting links to a fake stealth mint.

With regards to this matter, Cointelegraph spoke with CertiK’s security expert Jesse Leclere. Known as a leader in the blockchain security space, CertiK has helped over 3,600 projects secure $360 billion worth of digital assets and detected over 66,000 vulnerabilities since 2018. Here’s what Leclere had to say:

“SMS 2FA is better than nothing, but it is the most vulnerable form of 2FA currently in use. Its appeal comes from its ease of use: most people are either on their phone or have it close at hand when they’re logging in to online platforms. But its vulnerability to SIM card swaps cannot be underestimated.”

Leclerc explained that dedicated authenticator apps, such as Google Authenticator, Authy, or Duo, offer nearly all the convenience of SMS 2FA while removing the risk of SIM-swapping. When asked if virtual or eSIM cards can hedge away the risk of SIM-swap-related phishing attacks, for Leclerc, the answer is a clear no:

“One has to keep in mind that SIM-swap attacks rely on identity fraud and social engineering. If a bad actor can trick an employee at a telecom firm into thinking that they are the legitimate owner of a number attached to a physical SIM, they can do so for an eSIM as well.

Though it is possible to deter such attacks by locking the SIM card to one’s phone (Telecom companies can also unlock phones), Leclere nevertheless points to the gold standard of using physical security keys. “These keys plug into your computer’s USB port, and some are near-field communication (NFC) enabled for easier use with mobile devices,” explains Leclere. “An attacker would need to not only know your password but physically take possession of this key in order to get into your account.”

Leclere points out that after mandating the use of security keys for employees in 2017, Google has experienced zero successful phishing attacks. “However, they’re so effective that if you lose the one key that is tied to your account, you will most likely not be able to regain access to it. Keeping multiple keys in safe locations is important,” he added.

Finally Leclere sa that in addition to using an authenticator app or a security key, a good password manager makes it easy to create strong passwords without reusing them across multiple sites. “A strong, unique password paired with non-SMS 2FA is the best form of account security,” he stated.

Read Entire Article
Tags: CointelegraphCryptocurrencyInvestmentMining Bitcoin
Share76Tweet47

Related Posts

Bitcoin derivatives data shows room for BTC price to move higher this week

by Jon Hartney
January 23, 2023
0

BTC options data suggest that the Bitcoin price rally still has legs, even with wider economic concerns growing and the

Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher

by Jon Hartney
January 22, 2023
0

BTC could take a break from its sharp rally and if BTC price bounces off underlying support, APE, MANA, AAVE...

Genesis bankruptcy case scheduled for first hearing

by Jon Hartney
January 22, 2023
0

The first hearing in Genesis Capital's bankruptcy case will be held on January 23, according to court filings

Terra lending protocol Mars to launch mainnet

by Jon Hartney
January 22, 2023
0

The Mars Hub will launch an independent Cosmos application chain and issue MARS to users who hold the token during...

Central African Republic eyes legal framework for crypto adoption

by Jon Hartney
January 22, 2023
0

A 15-member committee is tasked with working on a legal framework that will allow cryptocurrencies to operate in

Load More
  • Trending
  • Comments
  • Latest

Ethereum Classic gets ‘endorsement’ from Vitalik Buterin, but ETC price still risks 50% crash

July 27, 2022

Critique on Helium’s $6.5K monthly revenue causes a stir

July 28, 2022

All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

July 7, 2022

Cardano Vasil hard fork hit with another delay for several weeks

July 29, 2022

All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

0

Crypto owners banned from working on US Government crypto policies

0

Korean startup Uprise lost $20M shorting LUNC

0

Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

0

Bitcoin derivatives data shows room for BTC price to move higher this week

January 23, 2023

Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher

January 22, 2023

Genesis bankruptcy case scheduled for first hearing

January 22, 2023

Terra lending protocol Mars to launch mainnet

January 22, 2023

XBT.Market

This website is an automated news feed powered by the Nebulome cloud system. The site is made possible by YYC TECH Consulting and Alberta Digital Mining Company. As a team with major crypto and bitcoin enthusiasm, we have curated major sources of news, trading and financial data to bring you, our viewer, an unbiased source of truth.

Recent Posts

  • Bitcoin derivatives data shows room for BTC price to move higher this week January 23, 2023
  • Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher January 22, 2023
  • Genesis bankruptcy case scheduled for first hearing January 22, 2023
  • Terra lending protocol Mars to launch mainnet January 22, 2023
  • Central African Republic eyes legal framework for crypto adoption January 22, 2023

News Categories

  • Bitcoin
  • Blockchain
  • Business
  • Market

Tags

bitcoinMagzine Cointelegraph Cryptocurrency insidebitcoins Investment Mining Bitcoin NewsBTC

Quicklinks

  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market - Powered by YYC Tech Consulting & ADMCO.

No Result
View All Result
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market by Nebulome.

  • bitcoinBitcoin(BTC)$28,509.003.60%
  • ethereumEthereum(ETH)$1,827.654.35%
  • USDEXUSDEX(USDEX)$1.07-0.53%
  • tetherTether(USDT)$1.01-0.01%
  • binancecoinBNB(BNB)$331.572.49%
  • usd-coinUSD Coin(USDC)$1.00-0.02%
  • rippleXRP(XRP)$0.4465184.76%
  • cardanoCardano(ADA)$0.3746782.86%
  • dogecoinDogecoin(DOGE)$0.0778474.11%
  • Lido Staked EtherLido Staked Ether(STETH)$1,819.574.19%
  • matic-networkPolygon(MATIC)$1.142.18%
  • SolanaSolana(SOL)$22.343.34%
  • Binance USDBinance USD(BUSD)$1.01-0.07%
  • polkadotPolkadot(DOT)$6.364.06%
  • litecoinLitecoin(LTC)$93.746.00%
  • Shiba InuShiba Inu(SHIB)$0.0000111.91%
  • tronTRON(TRX)$0.0658239.17%
  • AvalancheAvalanche(AVAX)$17.684.43%
  • daiDai(DAI)$1.000.09%
  • UniswapUniswap(UNI)$6.282.44%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$28,552.003.64%
  • chainlinkChainlink(LINK)$7.696.46%
  • cosmosCosmos Hub(ATOM)$11.762.96%
  • ToncoinToncoin(TON)$2.19-8.32%
  • leo-tokenLEO Token(LEO)$3.390.88%
  • ethereum-classicEthereum Classic(ETC)$20.953.02%
  • moneroMonero(XMR)$157.844.62%
  • OKBOKB(OKB)$45.22-0.53%
  • bitcoin-cashBitcoin Cash(BCH)$129.251.96%
  • Aerarium FiAerarium Fi(AERA)$7.14-13.09%
  • stellarStellar(XLM)$0.0932102.13%
  • filecoinFilecoin(FIL)$5.954.34%
  • AptosAptos(APT)$13.240.77%
  • true-usdTrueUSD(TUSD)$1.01-0.07%
  • Lido DAOLido DAO(LDO)$2.32-3.69%
  • HederaHedera(HBAR)$0.0628392.84%
  • QuantQuant(QNT)$127.841.77%
  • NEAR ProtocolNEAR Protocol(NEAR)$2.064.65%
  • CronosCronos(CRO)$0.0705062.22%
  • ArbitrumArbitrum(ARB)$1.37-72.91%
  • vechainVeChain(VET)$0.0238674.73%
  • StacksStacks(STX)$1.17-2.83%
  • algorandAlgorand(ALGO)$0.2211882.33%
  • Internet ComputerInternet Computer(ICP)$5.222.41%
  • ApeCoinApeCoin(APE)$4.183.53%
  • FantomFantom(FTM)$0.4973844.66%
  • The GraphThe Graph(GRT)$0.1531695.97%
  • eosEOS(EOS)$1.175.69%
  • The SandboxThe Sandbox(SAND)$0.673.99%
  • decentralandDecentraland(MANA)$0.624.95%
  • AaveAave(AAVE)$77.562.47%
  • ImmutableXImmutableX(IMX)$1.211.00%
  • MultiversXMultiversX(EGLD)$43.923.82%
  • tezosTezos(XTZ)$1.183.72%
  • FlowFlow(FLOW)$1.032.83%
  • theta-tokenTheta Network(THETA)$1.065.26%
  • FraxFrax(FRAX)$1.000.00%
  • Axie InfinityAxie Infinity(AXS)$8.733.49%
  • neoNEO(NEO)$12.956.59%
  • kucoin-sharesKuCoin(KCS)$9.101.12%
  • havvenSynthetix Network(SNX)$2.720.13%
  • ConfluxConflux(CFX)$0.377986-2.34%
  • OptimismOptimism(OP)$2.49-2.54%
  • Rocket PoolRocket Pool(RPL)$40.334.11%
  • Mina ProtocolMina Protocol(MINA)$0.888.12%
  • BitDAOBitDAO(BIT)$0.531.04%
  • GateGate(GT)$5.413.54%
  • paxos-standardPax Dollar(USDP)$1.01-0.36%
  • Curve DAOCurve DAO(CRV)$0.972.28%
  • Terra Luna ClassicTerra Luna Classic(LUNC)$0.0001271.02%
  • bitcoin-cash-svBitcoin SV(BSV)$37.704.47%
  • KlaytnKlaytn(KLAY)$0.2350193.67%
  • USDDUSDD(USDD)$1.000.12%
  • dashDash(DASH)$63.917.86%
  • WhiteBIT TokenWhiteBIT Token(WBT)$4.953.14%
  • PancakeSwapPancakeSwap(CAKE)$3.791.38%
  • ChilizChiliz(CHZ)$0.1232302.97%
  • GMXGMX(GMX)$75.73-3.29%
  • eCasheCash(XEC)$0.0000324.40%
  • CloutContractsCloutContracts(CCS)$52.461,000.00%
  • makerMaker(MKR)$686.981.26%
  • Frax ShareFrax Share(FXS)$8.232.27%
  • iotaIOTA(MIOTA)$0.2184053.66%
  • BitTorrentBitTorrent(BTT)$0.0000012.36%
  • singularitynetSingularityNET(AGIX)$0.491704-2.25%
  • huobi-tokenHuobi(HT)$3.651.43%
  • cETHcETH(CETH)$36.634.39%
  • Bitget TokenBitget Token(BGB)$0.3967371.01%
  • EdgecoinEdgecoin(EDGT)$1.010.15%
  • XDC NetworkXDC Network(XDC)$0.038049-3.19%
  • Tokenize XchangeTokenize Xchange(TKX)$6.533.47%
  • PAX GoldPAX Gold(PAXG)$2,000.370.73%
  • Trust WalletTrust Wallet(TWT)$1.211.14%
  • Tether GoldTether Gold(XAUT)$2,003.252.02%
  • RenderRender(RNDR)$1.35-3.23%
  • Mask NetworkMask Network(MASK)$6.4019.51%
  • zilliqaZilliqa(ZIL)$0.0286644.07%
  • RadixRadix(XRD)$0.04577315.53%
  • BinaryXBinaryX(BNX)$23.94-86.46%
  • loopringLoopring(LRC)$0.3695219.31%