Skip to main content

Could two-step verification through texts go the way of the dodo?

nest two step verification
Image used with permission by copyright holder
The number of websites and services using two-step verification to secure accounts has increased over the years — yet the National Institute of Standards and Technology’s latest proposal might put a halt to the verification method.

In its mainstream incarnation, two-step verification (also known as multi-factor authentication and two-factor authentication) works by sending you a one-time code through SMS when logging into one of your digital accounts. In theory, even if someone has your username and password, they cannot access your account without access to your phone. Two-step verification is not the end-all, be-all solution that will forever safeguard your accounts, but it has certainly proven resilient over time.

Unfortunately, recent malware like HummingBad and Stagefright shows that folks are finding more ways to remotely access your phone and your messages, thus raising concerns over two-step verification. Furthermore, as Slate points out, services like Skype and Google Voice have become more popular over the years, putting into question how secure transmission protocols used by two-step verification systems are.

As a result, NIST suggests the use of alternative authenticators to ensure the integrity of such systems.

“Due to the risk that SMS messages may be intercepted or redirected, implementers of new systems should carefully consider alternative authenticators,” reads the government agency’s draft.

Based on the language of the draft, NIST wants agencies to avoid making new investments into two-step verification systems that use SMS messages, and instead invest in alternative solutions like biometrics and apps that create one-time codes. However, the agency also warns that the use of SMS messages “may no longer be allowed in future releases of this guidance,” putting into question whether there will be an expiration date on such uses.

Michael Garcia, deputy director of authentication research program NSTIC at NIST, reaffirmed the draft’s language regarding SMS-based two-step verification systems, saying that alternative solutions should be considered if entities are at a point of reinvestment.

“We’re not saying federal agencies drop SMS, don’t use it anymore,” Garcia told Slate. “But, we are saying, if you’re making new investments, you should consider that in your decision-making.”

Overall, NIST’s draft does not mean much for people with digital accounts right now, but do not be surprised if, in time, companies like Google and Apple no longer want to send you one-time codes and, instead, opt for different, more secure methods of accessing your accounts.

Editors' Recommendations

Williams Pelegrin
Former Digital Trends Contributor
Williams is an avid New York Yankees fan, speaks Spanish, resides in Colorado, and has an affinity for Frosted Flakes. Send…
Apple’s new iPad Air could be in trouble
iPad Air 5 seen from the back and held in hand.

If everything goes according to plan, Apple is set to unveil new iPads on Tuesday, May 7. It's been a while since the last iPad release in October 2022, so expectations are incredibly high for those eagerly waiting to buy a new Apple tablet.

I typically purchase the iPad Pro and own the current 11-inch model, and I am curious about Apple's plans for this product line. However, most people are probably more interested in the upcoming iPad Air lineup in 2024. Both lineups are getting a refresh next week. In recent years, the iPad Air has been positioned between the budget-priced iPad and the top-of-the-line iPad Pro, making it a popular choice for many.

Read more
Best Fitbit deals: Save on Versa 4, Charge 6, and Sense 2
The Fitbit Sense 2 in moss.

One of the best fitness trackers is a great way to up your workout, though they can get expensive. Even with the current Apple deals, Apple Watch deals, and Samsung Galaxy Watch deals things can get a little expensive. Fitbit is a good fitness tracker brand to turn to if you’re looking for affordability. It has a great lineup of options, and Fitbit watches are almost always seeing a deal. In fact, right now Fitbit deals make for some of the best smartwatch deals you can shop. Below you’ll find what we feel are the best Fitbit deals to shop right now. There are several models to choose from for some savings, as well as a great deal on the Fitbit Charge 4.
Today's best Fitbit deal
Fitbit Charge 4 -- $125, was $150

While there are newer Fitbit Charge models on the market that include both the Fitbit Charge 5 and the Fitbit Charge 6, the Fitbit Charge 4 still has a lot to offer. It has all sorts of fitness and activity tracking capabilities. It can measure your resting heart rate and calorie burn throughout the day, as well as your SpO2 nightly average. The Charge 4 also uses built-in GPS to see your pace and distance during outdoor runs, rides, hikes, and other activities. You can head out for a long hike with this smartwatch, as the Charge 5 can last up to seven days on a single battery charge, and up to five hours when GPS is being used.

Read more
Best Samsung deals: The Galaxy S24 Ultra is up to $750 off
Best Android Phone 2022 Galaxy S22 Ultra in hand with S Pen feat image.

Whether you’re looking to shop TV deals, phone deals, smartwatch deals, and even tablet deals, Samsung almost always has something we could direct your attention toward. It’s regularly regarded as one of the top electronics brands, and almost always places among the best TV brands. There are a lot of Samsung deals worth shopping right now, and they cross the full spectrum of tech. We’ve done some of the heavy lifting for you and have rounded up what we feel are the best Samsung deals to shop right now. You’ll find a little bit of everything with these deals, so read onward for more details.
Samsung Galaxy Watch 4 — $150, was $200

On the surface, the Samsung Galaxy Watch 4 may look like a watch with a cool digital screen. And, of course, that'd be quite nice. But it turns out to be more of a wearable health monitor, giving you access to info on your overall fitness, running capabilities, and sleep cycles. Our Samsung Galaxy Watch 4 review compliments it for its seamless pairing with Samsung devices and its compatibility with small wrists. As you're sure to be adventuring, running, and exploring with this watch, be sure to grab one of the best Samsung Galaxy Watch 4 screen protectors to preserve its longevity.

Read more