SS7 protocol vulnerabilities and social engineering attacks on carriers allow attackers to port a phone number without physical access to the device. NIST SP 800-63B (2017) deprecated SMS as an authentication factor. Recommended alternatives: TOTP authenticator apps (RFC 6238) or FIDO2 hardware security keys which require physical possession and are phishing-resistant.
Sign in to join the conversation.
This insight is user-generated content for informational purposes only. It is not professional advice. Always consult a licensed professional before acting on information related to trades, health, finance, or any field where incorrect application could cause harm. KnowBoar assumes no liability for actions taken based on this content. Full terms.