Join the Mozilla’s Test Days event from Dec 2–8 to test the new Firefox address bar on Firefox Beta 134 and get a chance to win Mozilla swag vouchers! 🎁

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

Why not 2FA via SMS?

more options

Why can't 2-step authentication (for my Firefox Account) be done via SMS instead of requiring me to download another app? Isn't that how most other web apps handle it?

Why can't 2-step authentication (for my Firefox Account) be done via SMS instead of requiring me to download another app? Isn't that how most other web apps handle it?

被采纳的解决方案

Originally two factor authentication was done via an SMS message with a code (not specifically by Mozilla, but in general). The reason that most companies are transitioning to using two factor authentication apps instead is for security.

As it turns out, it's fairly easy to hijack SMS text messages, which would make it easy for an attacker to gain access to your account, even though it's protected with two factor authentication.

Authentication apps don't suffer from this security flaw and since the majority of mobile devices are smart devices, it's usually not a big deal.

Another good thing about using an authentication app instead of SMS is that you can use a variety of devices, not just those that have a SIM card. It also allows you to use multiple different devices to authenticate your account. For example, if you don't have access to your smartphone, you can unlock your account with a computer if you have an authentication app setup on there.

定位到答案原位置 👍 0

所有回复 (1)

more options

选择的解决方案

Originally two factor authentication was done via an SMS message with a code (not specifically by Mozilla, but in general). The reason that most companies are transitioning to using two factor authentication apps instead is for security.

As it turns out, it's fairly easy to hijack SMS text messages, which would make it easy for an attacker to gain access to your account, even though it's protected with two factor authentication.

Authentication apps don't suffer from this security flaw and since the majority of mobile devices are smart devices, it's usually not a big deal.

Another good thing about using an authentication app instead of SMS is that you can use a variety of devices, not just those that have a SIM card. It also allows you to use multiple different devices to authenticate your account. For example, if you don't have access to your smartphone, you can unlock your account with a computer if you have an authentication app setup on there.