Tuesday, March 5, 2019

Facebook's 2-Factor Authentication Has Privacy Flaws



On Facebook, two-factor authentication with phone numbers has a two-factored problem. First: The phone number you give to Facebook to help keep your account safe from potential hackers isn't just being used for security. A tweet thread from Jeremy Burge, founder of Emojipedia, on Friday showed that people can find your profile from that same phone number, and you can't opt out of that setting. This comes almost a year after Facebook said it stopped allowing people to search for profiles by phone numbers, and about five months after Gizmodo found that the phone number being used for 2FA was also being provided to advertisers for targeted posts.

On Facebook, two-factor authentication with phone numbers has a two-factored problem. The tying of users' phone numbers with targeted advertising and searches puts security and privacy at odds, potentially driving people away from an important feature that protects accounts from takeovers. Facebook "can't credibly require 2FA for high-risk accounts without segmenting that from search & ads," Alex Stamos, Facebook's former chief information security officer said in a tweet on Saturday.



Credits:
https://www.cnet.com/news/facebooks-two-factor-authentication-with-phone-numbers-puts-security-and-privacy-at-odds/

No comments:

Post a Comment