That was an example, the point is it is possible to intercept it. It’s been done in the wild - again that’s why there’s such need for other methods of 2FA.
Re: Apple or Google
That’s even easier for them, because, you know, they’ve got access to the phone. Heck, famously Apple had a bug/feature where it stored text of notifications which affected Signal, too. In that case it was law enforcement who took advantage of that, though.
I wouldn’t go around sounding the alarm about SMS, because I don’t think many people send stuff that shouldn’t be plaintext via SMS. I like using SMS, actually, because how simple it is and you don’t need 4G for that.
But the fact is messages can be read one way or another. If you want to conspire, definitely use something else.
Re: Apple or Google. That’s even easier for them, because, you know, they’ve got access to the phone.
Okay, so no mobile chat apps are safe?
The point here is that Apple and (especially) Google are most certainly collecting your data when using RCS. And only the carriers and the govt are collecting your data in SMS, not Google or Apple.
In that way, I don’t think any RCS is superior in any way outside of functionality.
Okay, one last time. Those are two different issues.
The whole point of this thread was that it was possible to intercept the messages. That’s all. I doubt the OP needs to worry about that. But it’s possible as was stated by the other poster.
It’s like claiming that mail can’t be intercepted. Of course it can, but generally speaking you don’t have to worry about that. Though it would be foolish to claim otherwise (especially when one quick web search can show you cases when someone successfully pulled it off)
Developed countries use literally anything else. TOTP apps, encrypted apps, Card reader code generation, identity providers, 3rd party verification programs, etc…
America uses it because it is cheap and easy and it pushes the infrastructure cost to someone else, not because it is secure. My american bank I keep only had SMS from american numbers to start, now they have TOTP app support, passkey support, and are going to phase out their SMS because of security.
Also, SIM phishing is pretty common… There doesn’t have to be any physical access to the phone. It is a standard phishing attack and they get all your SIM details and spoof it in an automated system.
Uhhhh nope, just the carrier(s) (and the government)
SMS/MMS is famously possible to intercept, by anyone, what are you talking about?
Otherwise it would be sufficient 2FA and we wouldn’t have to bother devising other methods.
Intercept how? SMS is overwhelmingly the default 2FA. So much so that many banks and companies won’t let you not use it.
One of the first links that came up: https://arstechnica.com/information-technology/2021/03/16-attack-let-hacker-intercept-a-t-mobile-users-text-messages/
Is SMS insecure? Absolutely. Is Apple, Google, et all maliciously SIM swapping users? Absolutely not. What are you talking about?
That was an example, the point is it is possible to intercept it. It’s been done in the wild - again that’s why there’s such need for other methods of 2FA.
Re: Apple or Google That’s even easier for them, because, you know, they’ve got access to the phone. Heck, famously Apple had a bug/feature where it stored text of notifications which affected Signal, too. In that case it was law enforcement who took advantage of that, though.
I wouldn’t go around sounding the alarm about SMS, because I don’t think many people send stuff that shouldn’t be plaintext via SMS. I like using SMS, actually, because how simple it is and you don’t need 4G for that.
But the fact is messages can be read one way or another. If you want to conspire, definitely use something else.
Okay, so no mobile chat apps are safe?
The point here is that Apple and (especially) Google are most certainly collecting your data when using RCS. And only the carriers and the govt are collecting your data in SMS, not Google or Apple.
In that way, I don’t think any RCS is superior in any way outside of functionality.
Okay, one last time. Those are two different issues.
The whole point of this thread was that it was possible to intercept the messages. That’s all. I doubt the OP needs to worry about that. But it’s possible as was stated by the other poster.
It’s like claiming that mail can’t be intercepted. Of course it can, but generally speaking you don’t have to worry about that. Though it would be foolish to claim otherwise (especially when one quick web search can show you cases when someone successfully pulled it off)
Good day.
Edit: typos
the default in america
Developed countries use literally anything else. TOTP apps, encrypted apps, Card reader code generation, identity providers, 3rd party verification programs, etc…
America uses it because it is cheap and easy and it pushes the infrastructure cost to someone else, not because it is secure. My american bank I keep only had SMS from american numbers to start, now they have TOTP app support, passkey support, and are going to phase out their SMS because of security.
Also, SIM phishing is pretty common… There doesn’t have to be any physical access to the phone. It is a standard phishing attack and they get all your SIM details and spoof it in an automated system.
No.
No one was discussing security.