New Carrier-Based Authentication System Seeks To Replace SMS 2FA

Two years ago, the National Institute of Standards and Technology (NIST) proposed the deprecation of SMS two-factor authentication (2FA) because it was getting too easy for attackers to steal authentication codes from victims. The U.S. carriers AT&T, Verizon, Sprint, and T-Mobile announced a new, supposedly more secure solution to replace SMS 2FA.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Snipergod87
    And what happens when someone walk's into your local Verizon store, claims to be you and uses social engineering to get a new SIM card issued in your name to their phone? Its not like that hasn't happened before.
    Reply
  • Druidsmark
    Main reason I don't use sms is I have a pay as you go phone. This means I pay for every minute I talk on the phone as well as I pay for every text message I receive and send. So unless the mobile phone carriers here in canada want to start making it free for me to receive sms messages are will continue to avoid this service as much as possible. As this news article points out this is added layer of security is vulnerable to hacking as well so I see no reason to use a service that costs me money every time I use it.

    I use my phone primarily as door buzzer and spend less then $100 a year for the phone.
    Reply
  • bollwerk
    Note that this article is only about SMS 2FA. Other forms of 2FA are perhaps more secure? i.e. Google Authenticator, Duo, etc...
    Reply
  • SoNic67
    Google and Microsoft authentication moved away from SMS already
    Reply
  • alextheblue
    20753867 said:
    Main reason I don't use sms is I have a pay as you go phone. This means I pay for every minute I talk on the phone as well as I pay for every text message I receive and send. So unless the mobile phone carriers here in canada want to start making it free for me to receive sms messages are will continue to avoid this service as much as possible. As this news article points out this is added layer of security is vulnerable to hacking as well so I see no reason to use a service that costs me money every time I use it.

    I use my phone primarily as door buzzer and spend less then $100 a year for the phone.

    I use smoke signals, but some days the range is really limiting. I demand the carriers offer me free carrier pigeons for 2FA purposes.
    Reply