Skip to main content

Could two-step verification through texts go the way of the dodo?

nest two step verification
Image used with permission by copyright holder
The number of websites and services using two-step verification to secure accounts has increased over the years — yet the National Institute of Standards and Technology’s latest proposal might put a halt to the verification method.

In its mainstream incarnation, two-step verification (also known as multi-factor authentication and two-factor authentication) works by sending you a one-time code through SMS when logging into one of your digital accounts. In theory, even if someone has your username and password, they cannot access your account without access to your phone. Two-step verification is not the end-all, be-all solution that will forever safeguard your accounts, but it has certainly proven resilient over time.

Unfortunately, recent malware like HummingBad and Stagefright shows that folks are finding more ways to remotely access your phone and your messages, thus raising concerns over two-step verification. Furthermore, as Slate points out, services like Skype and Google Voice have become more popular over the years, putting into question how secure transmission protocols used by two-step verification systems are.

As a result, NIST suggests the use of alternative authenticators to ensure the integrity of such systems.

“Due to the risk that SMS messages may be intercepted or redirected, implementers of new systems should carefully consider alternative authenticators,” reads the government agency’s draft.

Based on the language of the draft, NIST wants agencies to avoid making new investments into two-step verification systems that use SMS messages, and instead invest in alternative solutions like biometrics and apps that create one-time codes. However, the agency also warns that the use of SMS messages “may no longer be allowed in future releases of this guidance,” putting into question whether there will be an expiration date on such uses.

Michael Garcia, deputy director of authentication research program NSTIC at NIST, reaffirmed the draft’s language regarding SMS-based two-step verification systems, saying that alternative solutions should be considered if entities are at a point of reinvestment.

“We’re not saying federal agencies drop SMS, don’t use it anymore,” Garcia told Slate. “But, we are saying, if you’re making new investments, you should consider that in your decision-making.”

Overall, NIST’s draft does not mean much for people with digital accounts right now, but do not be surprised if, in time, companies like Google and Apple no longer want to send you one-time codes and, instead, opt for different, more secure methods of accessing your accounts.

Editors' Recommendations

Williams Pelegrin
Former Digital Trends Contributor
Williams is an avid New York Yankees fan, speaks Spanish, resides in Colorado, and has an affinity for Frosted Flakes. Send…
5 phones you should buy instead of the Samsung Galaxy S24 Plus
A Samsung Galaxy S24 Plus laying on concrete.

Looking to upgrade your phone this year? You may be considering Samsung’s new Galaxy S24 Plus, which is the middle child of the S24 lineup. Given how solid the S24 Plus is, that's not a bad idea at all.

But is the Galaxy S24 Plus the best phone you can get? Maybe not, as there are plenty of other great choices that you can choose from as well. Here are some of the best alternatives to the Galaxy S24 Plus that you should take a look at before spending your hard-earned dollars.
Samsung Galaxy S24 Ultra

Read more
Samsung Galaxy Watch 7 Ultra: news, rumored price, release date, and more
Taking a blood pressure measurement on the Samsung Galaxy Watch 6 Classic.

Samsung has a strong presence in the smartwatch market with its Galaxy Watch series, which includes the Galaxy Watch 6 and the Galaxy Watch 6 Classic. The company is expected to launch the Galaxy Watch 7 and Galaxy Watch 7 Classic later this year. However, rumors suggest that Samsung is also working on a new addition to its smartwatch lineup — the Samsung Galaxy Watch 7 Ultra.

Information about this watch is sparse at the moment. However, that should change as we approach a launch date. Here's the latest information on the Galaxy Watch 7 Ultra.
Samsung Galaxy Watch 7 Ultra: release date

Read more
AT&T now makes you pay even more for its fastest 5G speeds
A photo of the AT&T logo on a building.

We have bad news for AT&T customers who always expect to get the fastest 5G speeds. The second-largest carrier in the U.S. will now make you pay extra for the fastest option. On Thursday, AT&T announced its new “Turbo” add-on, which it says will provide “enhanced data connectivity for real-time responsiveness.”

What this means in terms of network speeds compared to what everyday AT&T 5G customers get isn’t exactly clear.

Read more