• Pycorax@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    10 hours ago

    I’m not sure how it works the way where you live but where I live, the way the banking apps are implemented completely violate MFA. They rely on SMS verification which is absurd since if you’re phone is already compromised, no doubt your SMSes are too. There’s no true multi-device authentication in place and this has led to a huge number of victims being scammed after their devices get compromised by a phishing attack.

    The desktop and phone are both insecure, proper security should not have all your eggs in one basket.