Remove the 'add SMS as 2FA' banner when TOTP is in use
This is the banner I'm talking about:

Let me explain my reasoning behind removing this banner. While SMS as a 2FA method is awfully convenient compared to TOTP, it has security flaws. 2FA codes via SMS are sent over the internet AND can be received by a malicious actor through a SIM swap. Compare that to TOTP, which doesn't use internet and only needs the correct time. Having SMS enabled as a 2FA option removes the security benefits of TOTP entirely.
Now, not everyone is high profile enough to be the target of a SIM swap. Many people are probably unwilling to disable SMS because of its convenience. However, you should inform users anyways that having SMS as a backup 2FA method is less secure than TOTP alone. In fact, there should be another banner telling those who use SMS that they should disable it if they want their account to be as secure as possible.
TL;DR: SMS should not be recommended as a backup 2FA method, and those who use it should be told that it isn't secure.
Iniciar sesión para dejar un comentario.
Comentarios
0 comentarios