paulhutch
Master Poster
I asked the guys I work with (its lunchtime atm) who uses their phone to check emails- all 5 of us do
I am the only one with a password (4 digit pin no actually) on my phone
all of us have our emails open (without asking for a password) when our email apps start up
So I am the only one of 5 that if I lost my phone, would stand a (small) chance of not having their emails compromised
I checked and I can change my password on my email without having to know the old one- so having any of the other 4 phones, I could easily change their email passwords to a new one.
Using sms's as a second layer of defence wouldnt help as the sms would go to the phone I am using, so I would have that too
Same if the forum introduced an sms required to change password- I could go to the forum (like most I have it in my favs on the browser), change the password on the email(hence lockig out the true poster) change the password on the forum (via access to the email) and introducing sms verification would do nothing (as an sms would be sent to the very phone I am using!!!)
Interesting conundrum- at best it would provide a very small (tiny really) level of extra security, and with the number of people that regularly swap providers and often getting a new phone number, an sms could actually prove to be quite a turn off in user usefullness
Before the advent of smart phones- an sms would indeed been a useful security provision, these days- bah- its like providing an old skeleton lock on a brand new house- totally useless
Your IT is horribly setup and incredibly insecure, a second factor can't help if the basics aren't setup correctly (adding lipstick to a pig).
Using SMS as a second factor is only helpful when the first factors are setup, and you have a separate secure system setup to unlock the cell phone (fingerprint, iris or secure pass code).
In a normal situation where people use the most basic and obvious security measures adding a second factor increases security radically.
Basic and obvious equals:
- Secure unlock system on phone.
- Strong password on email.