SECURITY: Message to all sites that use SMS two-factor authentication

Sunday, September 27, 2026

*** begin quote ***

Many services have moved away from text-based SMS two-factor authentication in favor of email, authenticator apps, and other, more secure solutions (i.e., authenticator apps, passkeys).

Your site drove me nuts when forced to change my password with multiple screens and multiple SMS messages. Do it again and I’ll be forced to cancel. It’s security theater; not real security.

*** end quote ***

Let’s see if the {Privacy Invoked} responds.

Every time I get into this nonsense, I’m sending this message.

You should too. 

Line the TSA at airports, it’s “security theater”!

# – # – # – # – #

*** begin quote ***

Agent09-27-2026 – 4:50 PM

Hello Ferdinand,

We understand that you are looking to bypass the Password and One Time Passcode when accessing your online account. Currently, Manage my Target Circle Card does not use facial or fingerprint identification methods. We know you count on the ease of managing your account online and are always working to make enhancements, however this isn’t currently an available feature.

For your security, we’re unable to disable this security feature. We know you count on the ease of managing your account online. Please make sure your phone number and email are up to date so you can request a One Time Passcode, if necessary. To update and verify your contact information, select Menu, then Manage profile.

We know your time is valuable and we’ll be sure to keep your comments in mind as we work toward making the online experience better for every guest.

Have a great day.

Thanks for contacting us,
Vee
Target Card Services, servicer to TD Bank USA, N.A.

*** end quote ***

Nope.  Didn’t get the message. Sigh!

— 30 —


SECURITY: The old style secondary security authorization questions are dumb

Friday, February 27, 2026

I’ve often heard people struggle with the old style secondary security authorization questions.  You know: “What’s your favoite color”, or pets name, or school street.

I, long ago, decided that it was a “stupid control”.  So, in my passwrd manager, I’d record the questions and give absurd answers.  So, “what’s your favorite color”, became red158, pet’s name, red247, and street, red532.

Solved that problem.  

I still object to 2FA that rely on an SMS message and prefer Google Authenticator.  

But what do I know.

And, I don’t care for PASSKEYS either.  Not good for sites where I may have multiple ids or different Users.

Argh!

I also don’t like using my email for a User id.

Argh!

— 30 —


SECURITY: A static social security number is the flaw in EVERY financial security scheme

Saturday, October 12, 2024

https://www.theregister.com/2024/10/04/comcast_fcbs_ransomware_theft/

Cybersecurity Month
About a quarter million Comcast subscribers had their data stolen from debt collector

  • Cable giant says ransomware involved, FBCS keeps schtum

Connor Jones
Fri 4 Oct 2024 // 20:13 UTC

*** begin quote ***

Among the data types stolen were names, addresses, Social Security numbers, dates of birth, and the Comcast account numbers and ID numbers used internally at FBCS. The data pertains to those registered as customers at “around 2021.” Comcast stopped using FBCS for debt collection services in 2020.

*** end quote ***

As with ALL problems, digging down for who’s at fault, eventually end at the Gooferment.

I remember n=my original Social Security card as saying in big red font all caps “NOT FOR IDENTIFICATION PURPOSES”.

I’m sure that the tin foil hats of that era would have opposed it for either “THE MARK OF THE DEVIL” or “where is your papers please” or just the enumeration of privacy concerns.  And they, like almost all Conspiracy Theorists, would have been correct.  Look what a mess SSN has created.

At the root of the problem is the SSN.  

Fundamentally insecure!  Medicare abandoned the SSN on its own medicare cards.  Never explained but probably due to fraud.  Which still is a huge problem.

I suggest that the SSN be abandoned.  Credit cards use a 16 digit number with error correction in it and the “secret” card code on the back.  Why can’t the same be done to replace SSN.

Sure “credit reporting agencies”, banks, brokers, and all would have to retool.  

So what.

No one ever voted to approve this Universal Identifier.  

So let’s unvote it out.

Surely SCIENCE can come up with a better one.  Maybe based on our DNA, or biometric, or maybe nothing is best.

Google and Apple now have passkeys based on their device’s “biometric”.  

Even that would be better than SSN!

# – # – # – # – # 

FOOTNOTE: The word schtum means to remain silent. Specifically, it means not sharing any information, or telling anyone what you know. Schtum is most often used when referring to information that is harmful or sensitive in nature.

—30—