Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. Web
  5. News

Could two-step verification through texts go the way of the dodo?

Add as a preferred source on Google

The number of websites and services using two-step verification to secure accounts has increased over the years — yet the National Institute of Standards and Technology’s latest proposal might put a halt to the verification method.

In its mainstream incarnation, two-step verification (also known as multi-factor authentication and two-factor authentication) works by sending you a one-time code through SMS when logging into one of your digital accounts. In theory, even if someone has your username and password, they cannot access your account without access to your phone. Two-step verification is not the end-all, be-all solution that will forever safeguard your accounts, but it has certainly proven resilient over time.

Recommended Videos

Unfortunately, recent malware like HummingBad and Stagefright shows that folks are finding more ways to remotely access your phone and your messages, thus raising concerns over two-step verification. Furthermore, as Slate points out, services like Skype and Google Voice have become more popular over the years, putting into question how secure transmission protocols used by two-step verification systems are.

As a result, NIST suggests the use of alternative authenticators to ensure the integrity of such systems.

“Due to the risk that SMS messages may be intercepted or redirected, implementers of new systems should carefully consider alternative authenticators,” reads the government agency’s draft.

Based on the language of the draft, NIST wants agencies to avoid making new investments into two-step verification systems that use SMS messages, and instead invest in alternative solutions like biometrics and apps that create one-time codes. However, the agency also warns that the use of SMS messages “may no longer be allowed in future releases of this guidance,” putting into question whether there will be an expiration date on such uses.

Michael Garcia, deputy director of authentication research program NSTIC at NIST, reaffirmed the draft’s language regarding SMS-based two-step verification systems, saying that alternative solutions should be considered if entities are at a point of reinvestment.

“We’re not saying federal agencies drop SMS, don’t use it anymore,” Garcia told Slate. “But, we are saying, if you’re making new investments, you should consider that in your decision-making.”

Overall, NIST’s draft does not mean much for people with digital accounts right now, but do not be surprised if, in time, companies like Google and Apple no longer want to send you one-time codes and, instead, opt for different, more secure methods of accessing your accounts.

Williams Pelegrin
Williams is an avid New York Yankees fan, speaks Spanish, resides in Colorado, and has an affinity for Frosted Flakes. Send…
Google has to play fair with AI rivals on Android, and that could be good news for your wallet
A new ruling strips Gemini of its exclusive access to deep Android integration, opening the door for cheaper AI models to offer similar functionality for less.
A person using Google Gemini on the Google Pixel 9a.

After forcing Google to open up Android to third-party app stores, the EU is back with a new target, and this time it's Gemini's home-field advantage. The European Commission ordered Google on July 16 to give rival AI apps the same deep access to Android that's currently exclusive to Gemini. The order falls under the EU's Digital Markets Act (DMA), and it directs Google to stop treating its own assistant as a first-class citizen on a platform it controls.

What Google now has to hand over

Read more
Top phone brands should learn how to deck out a flagship without nuking our wallets
Red Magic 11S Pro Full Rear Design

I've always had a soft spot for devices that lean heavily into one aspect as their main identity. From phones that aim to replace a dedicated camera to devices with batteries larger than some power banks, these products know exactly what they were made for. They do not chase the same all-rounder brief as a typical flagship.

The Red Magic 11S Pro is a great example of this. I've always had a soft spot for devices that lean heavily into one aspect as their main identity. From phones that aim to replace a dedicated camera to devices with batteries larger than some power banks, these products know exactly what they were made for. They do not chase the same all-rounder brief as a typical flagship.

Read more
Apple is finally removing AI apps that can digitally undress anyone
Apple and Google told by court by court to remove undressing apps
Apple App Store

Apple has removed several AI-powered "nudify" apps from the App Store after coming under legal pressure from San Francisco's city attorney, but the episode raises a much bigger question than whether a handful of apps violated App Store rules.

The real issue is why these apps made it onto one of the world's most tightly controlled app marketplaces in the first place.

Read more