Vietnam.vn - Nền tảng quảng bá Việt Nam

SMS login authentication is very risky, what is the alternative?

(NLDO) - SMS authentication is considered one of the weakest security methods today.

Người Lao ĐộngNgười Lao Động22/06/2025

According to Yahoo, one-time authentication codes (OTP) sent via SMS are still widely used as a second layer of protection in the two-factor authentication process, helping users log in to banking, email or social networking applications.

However, Yahoo warns that SMS is one of the weakest security methods because it is very vulnerable to phishing attacks.

A recent investigation by Bloomberg Businessweek and Lighthouse Reports revealed a bigger risk: these OTPs could be accessed by third parties. Specifically, little-known Swiss telecommunications company Fink Telecom Services had access to more than 1 million messages containing two-factor authentication codes in June 2023.

As an intermediary between the companies that generate authentication codes and the end users, Fink Telecom Services has the right to process and view the content of messages. What is worrying is that this company has been suspected of participating in user surveillance and interfering with personal accounts.

Vì sao xác thực hai yếu tố qua SMS không còn an toàn? - Ảnh 1.

SMS is considered one of the weakest security methods because it can be accessed by third parties.

The leaked OTPs came from major companies such as Google, Meta, Amazon, Tinder, Snapchat, Binance, Signal, WhatsApp, and several European banks. The messages were sent to users in more than 100 countries.

According to Yahoo, the main reason why SMS two-factor authentication is not secure is because companies often outsource SMS sending at a lower cost, through large contracts with multiple carriers and a system of “global titles” - network addresses used to connect across countries. The weakness of this system is that the companies that hire them do not work directly with entities like Fink Telecom Services, but through layers of subcontractors, making it more complicated to ensure data security.

Mr. Pham Manh Cuong, founder of Wischain Company Limited, explained that the two-factor authentication method via SMS messages is no longer safe today because cyber attackers are increasingly sophisticated, easily taking advantage of vulnerabilities in the security system to gain access.

One of the most common forms of phishing attacks is where a seemingly reputable message, email, or website is used to trick users into providing sensitive information such as usernames, passwords, or OTP codes.

Not only that, SIM swapping is also a serious threat. Fraudsters can steal the victim's phone number, from which they receive authentication codes sent via SMS.

In addition, many users still have the habit of installing software of unknown origin, especially on Android devices, leading to spyware or keyloggers that can secretly record keyboard typing, thereby stealing access information.

While SMS authentication is still considered a certain layer of protection, compared to modern methods like Google Authenticator - an application that generates random authentication codes that change every 30 seconds and is independent of mobile networks - SMS is increasingly showing its weaknesses.

Source: https://nld.com.vn/xac-thuc-hai-yeu-to-qua-sms-rat-rui-ro-nen-dung-ung-dung-nao-196250621114624897.htm


Comment (0)

No data
No data

Same tag

Same category

Braised Pig's Feet with Fake Dog Meat - A Special Dish of Northern People
Peaceful mornings on the S-shaped strip of land
Fireworks explode, tourism accelerates, Da Nang scores in summer 2025
Experience night squid fishing and starfish watching in Phu Quoc pearl island

Same author

Heritage

Figure

Enterprise

No videos available

News

Political System

Destination

Product