Skip to main content
  1. Home
  2. Computing
  3. News

Google will replace unsafe Gmail SMS codes with QR scan verification

Add as a preferred source on Google
Receiving two-step security code via SMS.
Google / Digital Trends

Ever since Google enabled two-step verification for Gmail and other tied authentication protocols in its ecosystem, SMS codes have been a mainstay. But according to security analyses, SMS codes are notoriously unsafe, especially when the communication channel is not encrypted. That is finally about to change, as SMS codes will soon be replaced with QR codes for Gmail authentication.

When it comes to account security, SMS is not the most reliable choice for receiving sensitive verification codes, or one-time passwords (OTP) on phones. That is why, over the past few years, Google has steadily developed password alternatives such as on-device Google prompts, authenticator apps, hardware security keys, and the Passkey system to minimize the risks such as SMS phishing.

Recommended Videos

Now, Google is planning to phase out SMS-based verification completely for Gmail (and with it, Google account) authentication. “Just like we want to move past passwords with the use of things like passkeys. We want to move away from sending SMS messages for authentication,” Gmail spokesperson Ross Richendrfer, was quoted as saying by Forbes.

Why is SMS unsafe?

Trying to sign in from another device prompt from Google account.
Google implemented this device prompt system for account verification back in 2016. Google

Getting codes via a text message is convenient, but it’s not just the pathway and elaborate phishing techniques that make SMS an unsafe route. SIM swapping, social engineering, and impersonation attacks are also a fairly well-known techniques, and when those plans are executed, the legitimate owner never receives their SMS verification codes.

That leaves them locked out of their own Gmail account, and all the core services tied to it, which also include third-party services that require a Google account log-in. Moreover, in scenarios where users don’t have access to cellular networks, getting log-in codes via SMS becomes another challenge.

How QR codes can help?

Over the next few months, Google plans to replace the six-digit SMS codes and will show a QR code that users simply have to scan with the camera app on their phone. The company hasn’t shared many technical details about those plans, but it seems Google would likely create a protocol that would require a secure QR code handshake with a verified phone running the registered phone number.

Sample of an SDMQR code appearing on an iPhone screen.
Instead of blocky dots, SDMQR codes use ellipses. Nadeem Sarwar / Digital Trends

It is worth nothing here that QR codes are not inherently fool-proof. QR scams are also fairly common. But a QR scanning system that requires a local decode key, or a secure public key between only two trusted parties, is a lot safer and quicker.

We recently covered one such innovation called self-authenticating dual-modulated QR (SDMQR) code that has already received a government grant and might soon replace bar codes in various business and industrial applications.

Developed by experts at the University of Rochester, an SDMQR code relies on a cryptographic signature system that can only be unlocked with a digital private key. These specialized QR codes won’t require any special scanning app, and can be implemented on mobile devices across the world at an OS-level.

Nadeem Sarwar
Nadeem is the Managing Editor at Digital Trends.
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Google’s “uncopyable” passkeys may be easier to steal than promised
google-lawsuite-AI-Scams

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

Read more