Skip to main content

Could two-step verification through texts go the way of the dodo?

nest two step verification
Image used with permission by copyright holder
The number of websites and services using two-step verification to secure accounts has increased over the years — yet the National Institute of Standards and Technology’s latest proposal might put a halt to the verification method.

In its mainstream incarnation, two-step verification (also known as multi-factor authentication and two-factor authentication) works by sending you a one-time code through SMS when logging into one of your digital accounts. In theory, even if someone has your username and password, they cannot access your account without access to your phone. Two-step verification is not the end-all, be-all solution that will forever safeguard your accounts, but it has certainly proven resilient over time.

Unfortunately, recent malware like HummingBad and Stagefright shows that folks are finding more ways to remotely access your phone and your messages, thus raising concerns over two-step verification. Furthermore, as Slate points out, services like Skype and Google Voice have become more popular over the years, putting into question how secure transmission protocols used by two-step verification systems are.

As a result, NIST suggests the use of alternative authenticators to ensure the integrity of such systems.

“Due to the risk that SMS messages may be intercepted or redirected, implementers of new systems should carefully consider alternative authenticators,” reads the government agency’s draft.

Based on the language of the draft, NIST wants agencies to avoid making new investments into two-step verification systems that use SMS messages, and instead invest in alternative solutions like biometrics and apps that create one-time codes. However, the agency also warns that the use of SMS messages “may no longer be allowed in future releases of this guidance,” putting into question whether there will be an expiration date on such uses.

Michael Garcia, deputy director of authentication research program NSTIC at NIST, reaffirmed the draft’s language regarding SMS-based two-step verification systems, saying that alternative solutions should be considered if entities are at a point of reinvestment.

“We’re not saying federal agencies drop SMS, don’t use it anymore,” Garcia told Slate. “But, we are saying, if you’re making new investments, you should consider that in your decision-making.”

Overall, NIST’s draft does not mean much for people with digital accounts right now, but do not be surprised if, in time, companies like Google and Apple no longer want to send you one-time codes and, instead, opt for different, more secure methods of accessing your accounts.

Editors' Recommendations

Williams Pelegrin
Former Digital Trends Contributor
Williams is an avid New York Yankees fan, speaks Spanish, resides in Colorado, and has an affinity for Frosted Flakes. Send…
The 6 best tablets for travel in 2024
The back of the iPad Air 5.

With the world opening up once again for tourists, you're going to want to buy a tablet to beat the boredom of long flights and waiting times. Not all models will be able to serve this purpose though, so to help you decide what to purchase, we've rounded up our recommendations for the best tablets for travel. We acknowledge that there are different types of travelers, so we picked devices that will cater to each of them, while considering a specific set of criteria when making our selections.

While you can also use your smartphone during your trips, the larger screen of tablets will help provide more amusing entertainment when you need it. The best tablets for travel will let you catch up on work, watch streaming shows, check social media, and whatever else you may think of doing while you're on the way to your destination, or while you're taking a break from all the sights and sounds. Read onward to figure out the best tablet for travel for you, then go ahead and purchase it so that the device will be ready and waiting for your next adventure.
The best tablets for travel in 2024

Read more
Samsung Galaxy S24 vs. Galaxy S22: Do you really need to upgrade?
Renders of the Samsung Galaxy S24 and Galaxy S22 next to each other.

Your Samsung Galaxy S22 is now at least two years old. Are you thinking about upgrading your smartphone to the Galaxy S24? The newer processor, the introduction of Galaxy AI, fresh colors, and other upgrades can make it a tempting offer.

However, is it really worth the $800 price tag if you already have a Galaxy S22? Here's what you need to know before making a decision.
Samsung Galaxy S24 vs. Galaxy S22: specs

Read more
The most common Skype problems and how to fix them
best mac apps for small business skype

Skype is an excellent option for video chats with your friends and family or conducting a videoconference call with your colleagues.  However, Skype is not without its bugs, hiccups, and issues that can make getting face-to-face with someone seem like an ordeal. To make things easier on everyone, we've compiled a selection of the most common Skype problems and how to fix them.
Video not working
If you can't get your camera to work or experience issues seeing other's connections, you might as well be using an actual telephone instead of Skype. Thankfully, these issues can usually be resolved with a bit of tinkering on your end, or they may just be service disruptions on Skype's end.

One of the more common problems that crop up is visual issues due to Skype not having access to your PC or phone's camera. For desktop users, open the Skype application and select the Three horizontal dots near the notification bell icon to access the Skype menu. Select Settings > Audio and video. If your picture fails to appear in the Skype camera preview window, you'll know there's a connection issue.

Read more