SMS-based Two Factor Authentication is Insecure, What to Do to Secure Online Accounts?
SMS-based Two Factor Authentication is Insecure, What to Do to Secure Online Accounts? In today's digital age, ' Two-Factor Authentication ' (2FA) has become a must for securing online accounts. But the most popular and convenient medium used for this is SMS , which has proven to be the most insecure. SMS-based Two Factor Authentication (2FA) has serious security flaws, which are putting user accounts at risk. The biggest technical weakness of SMS is its outdated communication system. SMS uses a protocol called ' Signaling System No. 7 ' (SS7), which was developed in the 1970s and 80s. This system was created at a time when only a limited number of people had access to it and all users were considered trustworthy. It lacks ' cryptographic authentication ', which means that the system cannot distinguish whether a message comes from a legitimate source or not. This makes it easy for hackers to intercept, listen to, or modify messages. Since SMS messages are s...