this post was submitted on 12 Sep 2026
408 points (96.2% liked)

Technology

88590 readers
3177 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] Natanael@infosec.pub 1 points 3 weeks ago (2 children)

You can remove SMS 2FA from a Google account if you have passkeys or hardware security keys registered

[–] Crumpled6273@lemmy.ca 4 points 3 weeks ago

But with a always on VPN they constantly ask to verify our identity, even with passkey or phone number.

Even when I successfully verify my passkey, they will still sent a SMS code to my recovery number. It's almost impossible to bypass that step and try another method button redirect again to the same phone verification page. If I didn't give my number, then this message appears, "there is not enough information to prove this is your account. try again later."

Maybe VPN is a factor that triggering their security system.

[–] overstep8556@jlai.lu 1 points 3 weeks ago (1 children)

Does it also include TOTP 2FA?

[–] Natanael@infosec.pub 1 points 3 weeks ago

Not sure. You need att least one form registrerad. I do recommend using multiple.