The Solicitors Regulation Authority has implemented MFA for its website, but uses only SMS-based TOTP.

So much for me bothering to give feedback when they asked about it...

It's even worse than I thought. You can give *any phone number you like*. As long as you can receive SMS / answer calls at it.

So I logged in with my username and password, and then gave a phone number. It called me, I pressed #, and it authenticated me.

But next time I can give a different phone number.

What is the point of this?!


@neil that's some serious . How did anyone think that was an improvement over just user and password) "please prove you have access to some form of phone number"

Sign in to participate in the conversation

A server for those involved in the web: Developers, Designers, Coders, Server Providers etc.