| Australian Politics Forum | |
|
http://www.ozpolitic.com/forum/YaBB.pl
General Discussion >> Technically Speaking >> Is 2FA safe for SMS on your mobile? http://www.ozpolitic.com/forum/YaBB.pl?num=1782802391 Message started by Bobby. on Jun 30th, 2026 at 4:53pm |
|
|
Title: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jun 30th, 2026 at 4:53pm
Two factor authentication is not safe when using SMS on your mobile.
The banks etc send you an SMS with a code number but dozens of programs can read it. :o Jun 30, 2026 2 Pre-Installed Apps Are Spying on Your Texts (Stop Them) Did you know your Android phone comes with pre-installed apps that are spying on your texts? In this video, we expose how to find the hidden receipt proving these system apps are reading your private SMS messages—including your bank's 2FA security codes. I'll walk you through a simple step-by-step tutorial to stop them right now. You'll learn how to uncover the hidden Android permission manager, reveal the invisible system apps nobody shows you, and instantly block them from accessing your messages. https://www.youtube.com/watch?v=-t25tgI819w |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jun 30th, 2026 at 5:08pm The ANZ App Your money, your control. Take command of your personal and business banking, instantly and securely from the palm of your hand with the ANZ App. https://www.anz.com.au/support/online-banking/anz-app/ |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Carl D on Jun 30th, 2026 at 8:19pm
The 2FA codes sent to your phone can only be used once and if they're not used they expire after 10 or 15 minutes anyway so I don't see a problem here?
The only problem is when someone changes their phone number and don't update their number with banks and other places and the new owner of the number receives the 2FA codes meant for the previous owner, especially if the codes can be used to reset passwords and the new password is sent to the phone. Since I got my "new" mobile number from Telstra last September I've so far managed to resist the temptation to try and access Kirsten in Victoria's VicRoads, Facebook and Snapchat accounts after receiving 2FA codes for all of them over a period of several months (the latest one - Snapchat - was about 3 weeks ago). I've also had to set up a call blocker app to only allow calls from those on my contact list and any 08 (WA) numbers. All others (including Private numbers) are blocked which is probably annoying the heck out of debt collectors in Victoria who keep trying to call my "new" number (using different numbers each time) regarding Kirsten's unpaid bills. Gee, I wonder why she changed her number? ::) I Google the numbers when I check my calls log and it's always the debt collectors. They started off by sending a text message giving details of the debt (I've had 3 different ones so far) before they started trying to call, that's how I know what's going on. And, I did reply to those text messages telling them that Kirsten is no longer on this number but they obviously haven't read my replies or they're ignoring them. Which is why I couldn't give a stuff if they're annoyed because their calls can never get through to me. I've heard that even if you do answer one of their calls and explain the situation they don't believe you and think you're 'covering' for the debtor and keep calling anyway. I've also heard that if you do manage to convince them that the person they're looking for is no longer on this number they usually stop calling but if they end up selling the debt to another company all of their original information (including your "new" phone number) gets passed on and the calls start again. Edit: Now I remember - I posted about this in another thread back in March. ;D |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Carl D on Jun 30th, 2026 at 11:00pm
Oh, and by the way...
... there is no way I would EVER do banking or any financial transaction on my phone, 2FA or no 2FA. It would have to be one of the most, if not THE most insecure device to do something like banking on. It is also the reason why I will NEVER have any sort of Digital ID on my phone as well. And, I always keep my phone disconnected from the Internet unless I need to check for security updates or update my call blocker and a few other apps. |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jul 2nd, 2026 at 12:42am Carl D wrote on Jun 30th, 2026 at 11:00pm:
You might have to eventually - it's not only ANZ that has a banking App for mobiles - other Banks are planning it. I prefer a desktop when it's about my money. |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by tallowood on Jul 2nd, 2026 at 9:01am
It isn't too smart to have a "smart" phone, pushbutton phones are safer.
|
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Captain Nemo on Jul 2nd, 2026 at 9:28am Carl D wrote on Jun 30th, 2026 at 11:00pm:
On the other hand, if you use a payment app on your smartphone your card details are never known by the payee. Unlike handing over a physical card. ;) |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jul 3rd, 2026 at 8:04am tallowood wrote on Jul 2nd, 2026 at 9:01am:
Unfortunately we are slowly being forced to use our mobile phones for everything. example - you need a mobile phone to buy or sell property. I remember having to read a code number they gave me while being videoed with my own mobile phone. They have a recording of my face and my voice with live video. It's the same for everyone. BTW - there are no Title Deeds anymore - it's all digital. Google AI: You generally need a mobile phone to complete a property transfer using PEXA. Your mobile device is essential for security, verification, and document signing throughout the digital settlement process: Identity & Security (MFA): You will use your mobile number to receive secure SMS activation codes and for multi-factor authentication (MFA) to securely access your transaction Secure Data Sharing: Buyers and sellers are invited to download the free PEXA Key App (available on the Australian Apple App Store or Google Play Store). This app is used to securely verify and share your bank account details with your legal representative. Digital Signing: If you are required to sign documents electronically, you will use the PEXA Mobile Signing solution. This requires a compatible smartphone (or tablet) to authorize requests and securely apply your digital signature. |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jul 3rd, 2026 at 8:24am Notice PEXA is using an American company for all that ultra secure info? So does the ANZ app. Apple Inc. is an American multinational technology company. It is headquartered in Cupertino, California, in the heart of Silicon Valley Also: PEXA (Property Exchange Australia) is an Australian ASX-listed digital prop tech company. Headquartered in Melbourne, Victoria , it operates a world-first electronic conveyancing platform that facilitates the majority of property settlements, refinances, and lodgments across Australia's property market. So - all our most private information is in the hands of private companies and their employees - some of them based overseas. They all seem to use Apple. ::) |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by tallowood on Jul 3rd, 2026 at 9:01am Quote:
There is still plenty of space where they can't get you ;) |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jul 3rd, 2026 at 9:54am It's all about facial recognition technology. https://www.aclu.org/news/privacy-technology/more-than-a-dozen-wrongful-arrests-due-to-police-reliance-on-facial-recognition-technology One ACLU client spent six months in jail, because police relied on facial recognition technology to incorrectly identify her as a suspect. She’s the fourteenth person known to be wrongfully arrested due to the technology’s failures. When police arrested Kimberlee Williams, a grandmother living in Oklahoma, because of a warrant from Maryland, she was shocked. She had never been to Maryland in her life. Ms. Williams later learned that Maryland police had relied on an incorrect result from facial recognition technology that falsely flagged her as a suspect. She is the fourteenth person in the U.S. to join a growing list of people wrongfully arrested because police let flawed facial recognition technology taint their investigations. Police use of facial recognition technology is dangerous, and stories of people wrongfully arrested because of police reliance on incorrect facial recognition results continue to surface. Today, the ACLU and ACLU of Maryland sent letters to three Maryland police departments on behalf of Ms. Williams, who was wrongfully arrested and jailed for six months because Maryland police relied on a false facial recognition result and concealed their reliance on that unreliable technology from the court when applying for an arrest warrant. Ms. Williams will never get back the six months she spent in jail for a crime she clearly had nothing to do with. In our letters to Maryland police today, we are seeking both accountability and serious policy changes to minimize the chance of this happening to anyone in the future. One wrongful arrest from this dangerous technology is an outrage. More than a dozen, and counting, is a complete travesty that lawmakers and police must take immediate action to end. |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Bobby. on Jul 5th, 2026 at 9:44am
PEXA?
In order to transfer the title of property - you can only do it via your mobile phone - you have to read out a code number they provide while a video of your face and the sound is sent off to PEXA. Will our video samples ever be used for mass surveillance? What would Snowden say? The company called Apple has all those videos stored away for at least 7 years - no set limit is applied. Apple is in the USA - does the NSA have access? https://www.pexaclear.com.au/privacy-policy/ 6. Disclosures of personal information We disclose personal information to: Regulators and law enforcement where required or authorised by law (for example, to AUSTRAC or a State/Territory police service following a lawful demand), or to respond to subpoenas, warrants or court orders. https://www.arnecc.gov.au/wp-content/uploads/2021/08/mpr-guidance-note-5-retention-of-evidence.pdf WHEN MUST EVIDENCE BE RETAINED? Evidence must be retained whenever a Conveyancing Transaction is undertaken. It must be retained for at least seven years from the date of Lodgment of the Registry Instrument or Document. |
|
Title: Re: Is 2FA safe for SMS on your mobile? Post by Carl D on Jul 9th, 2026 at 10:50am
lol... in addition to Kirsten I also have the 'ghost' of Lauren 'haunting' my phone.
I'm guessing they may have shared the phone (or they're the same person) up until the point where they had to quickly get rid of it to avoid debt collectors? Now I'll just sit back and wait for all the attempted debt collector calls for Lauren, my call blocker will dutifully block them and keep a log of them all, of course. They seem to have given up with Kirsten for now (or they found her) because they haven't tried to call for over 2 weeks. They obviously didn't read or ignored the reply I sent to the first SMS in March. Oh, well - sucks to be them right now, I guess? ;D Oh, and I do hope Kirsten got in touch with Family Support Services and Centrelink before July 1st. I received an SMS (final reminder) for her on June 24th from Family Support telling her she needed to go to myGov and update all CCS (Child Care Support) income information by June 30th or her payments will stop. :-[ debt.jpg (70 KB | 3
) |
|
Australian Politics Forum » Powered by YaBB 2.5.2! YaBB Forum Software © 2000-2026. All Rights Reserved. |