Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you have your phone set to wake-up/show notifications on new messages, and your bank simply sends an SMS code as verification, then the thief can just read the message(s) when they come in and input them.


You have the option to hide the actual message, at least on Android.


Last I checked this was opt-in on Android; it's been default on iOS since I think 2017ish?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: