view the rest of the comments
Android
DROID DOES
Welcome to the Android community on Lemmy. Here you can participate in amazing discussions and events relating to all things Android.
The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:
Rules
1. All posts must be relevant to Android devices/operating system.
2. Posts cannot be illegal or NSFW material.
3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.
4. Non-whitelisted bots will be banned.
5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.
6. Memes are not allowed to be posts, but are allowed in the comments.
7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.
8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.
Community Resources:
SMS/MMS is famously possible to intercept, by anyone, what are you talking about?
Otherwise it would be sufficient 2FA and we wouldn't have to bother devising other methods.
Intercept how? SMS is overwhelmingly the default 2FA. So much so that many banks and companies won't let you not use it.
One of the first links that came up: https://arstechnica.com/information-technology/2021/03/16-attack-let-hacker-intercept-a-t-mobile-users-text-messages/
Is SMS insecure? Absolutely. Is Apple, Google, et all maliciously SIM swapping users? Absolutely not. What are you talking about?
That was an example, the point is it is possible to intercept it. It's been done in the wild - again that's why there's such need for other methods of 2FA.
Re: Apple or Google That's even easier for them, because, you know, they've got access to the phone. Heck, famously Apple had a bug/feature where it stored text of notifications which affected Signal, too. In that case it was law enforcement who took advantage of that, though.
I wouldn't go around sounding the alarm about SMS, because I don't think many people send stuff that shouldn't be plaintext via SMS. I like using SMS, actually, because how simple it is and you don't need 4G for that.
But the fact is messages can be read one way or another. If you want to conspire, definitely use something else.
Okay, so no mobile chat apps are safe?
The point here is that Apple and (especially) Google are most certainly collecting your data when using RCS. And only the carriers and the govt are collecting your data in SMS, not Google or Apple.
In that way, I don't think any RCS is superior in any way outside of functionality.
Okay, one last time. Those are two different issues.
The whole point of this thread was that it was possible to intercept the messages. That's all. I doubt the OP needs to worry about that. But it's possible as was stated by the other poster.
It's like claiming that mail can't be intercepted. Of course it can, but generally speaking you don't have to worry about that. Though it would be foolish to claim otherwise (especially when one quick web search can show you cases when someone successfully pulled it off)
Good day.
Edit: typos
the default in america
Developed countries use literally anything else. TOTP apps, encrypted apps, Card reader code generation, identity providers, 3rd party verification programs, etc...
America uses it because it is cheap and easy and it pushes the infrastructure cost to someone else, not because it is secure. My american bank I keep only had SMS from american numbers to start, now they have TOTP app support, passkey support, and are going to phase out their SMS because of security.
Also, SIM phishing is pretty common... There doesn't have to be any physical access to the phone. It is a standard phishing attack and they get all your SIM details and spoof it in an automated system.
No.
No one was discussing security.