Yes, I have my own internal DNS server which is a Pi Hole. It is configured to use DNSSEC with Cloudflare for Upstream DNS queries if my own Pi Hole cannot answer the DNS query internally.
Yes, I have my own internal DNS server which is a Pi Hole. It is configured to use DNSSEC with Cloudflare for Upstream DNS queries if my own Pi Hole cannot answer the DNS query internally.
Yes, I had smartphones for a while but decided they were more trouble than they were worth and I've moved back to a 'feature phone'. It does all I need, lasts several days on one charge and isn't very 'nickable'.
Why do they want me to confirm the mobile number they already have on my account and sent this message to.
Worth noting it is possible for determined scammers to get your mobile diverted to them - it's how Twitters 2FA was bypassed a while back.
I prefer code generators myself.
Which is where I leave it. But no good then for receiving calls wherever I am in the house.
They want a separate channel to conform that it's YOU interacting with them. They might steal a laptop and get access, but can't do anythimg without your phone.
If I'm doing on-line banking, I'll use a desktop. I can't imagine doing any serious work on a pissy little screen.
In these Covid 19 days, where else can we be but at home?
It is a reminder to check that your mobile number that they have on file is correct before they switch on two factor authentication. Otherwise you will find yourself having to go through a much more complicated procedure to prove to them that you are the genuine account holder.
A surprising number of people have old mobile phone numbers and defunct email addresses on their accounts so it isn't as daft as you think.
Same problem arises if you have to change your email address because your ISP decided to axe its email service. If the authentication passcode and confirmation emails are bouncing then they will assume the worst and lock the account for future transactions.
possibly to make sure that it's still in your posession. Rather like my pension provider asking me, from time to time, to prove that I'm still alaive.
For certain transactions you initiate, or for random login events, they will send you a code via SMS that you must enter before you can proceed further. So you now need a user name, password and a pre-registered device (SMS, email, voice call). Any hacker may have your user name and password but its possibly very much more difficult to remotely get the one time (6 digit) code sent to a device in your home or on your person.
For instance with my bank if I want to set up a new outgoing payment I first set up all the details and then the bank sends me a code to my previously set up device[1] that I must then enter before they will proceed with my instructions. This replaces the card reader I had to use previously with my debit card. [1] In the case of my bank I have the choice of where to send the code at the time of the transaction.
you might have gone for a walk
Ah yes, its called SIM swap fraud.
AIUI, a scammer who knows your mobile number rings you provider pretending to be you and is ordering a replacement SIM using some ruse.
Its intercepted before it arrives at your house.
The scammer then inserts new SIM into one of their phones and activates the new SIM. the old one gets deactivated.
Then the scammer can get your text messages and hence the OTP codes.
Not seen that, but then I do not use any Paypal on the phone!
Brian
Unlikely. I notice that there have been official covid texts and spoof covid texts and on dumb mobiles you just get a little ping and you have to go and find the text, but of course on my Iphone it not only pings but reads part of the message if its not on silent. Brian
On the landline this does work, but few dumb mobiles do this is because there is no native text handling on landlines. Brian
Much better, then, to stick to the card reader the bank provides and the card they provide.
You could set a forward on the mobile to redirect calls to the landline to get voice calls.
If you have an android phone, then enable "messages for web", and then you get real time interaction with your SMS in a web browser.
That makes doing things with transactional SMS much simpler... code arrives, and you can copy and paste it straight from the web page without needing to touch the phone. You can also send texts with a proper keyboard, and paste stuff into them easily.
(there are also app based commercial equivalents like "MightyTest")
In order to manage your bank account?
This is a classic authentication problem - they need to talk to you, but can't know if the person on the phone is actually you, and you don't know if they are actually them!
What they normally do it start building layers of trust by exchange of information that is not sensitive or particularly useful for malicious purposes, but can give both sides confidence that both sides are legit.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required