Vietnam.vn - Nền tảng quảng bá Việt Nam

SMS login authentication is very risky, what is the alternative?

(NLDO) - SMS authentication is considered one of the weakest security methods today.

Người Lao ĐộngNgười Lao Động22/06/2025

According to Yahoo, one-time authentication codes (OTP) sent via SMS messages are still widely used as a second layer of protection in the two-factor authentication process, helping users log in to banking, email or social networking applications.

However, Yahoo warns that SMS is one of the weakest security methods because it is very vulnerable to phishing attacks.

A recent investigation by Bloomberg Businessweek and Lighthouse Reports revealed a bigger risk: these OTP codes could be accessed by third parties. Specifically, little-known Swiss telecom company Fink Telecom Services had access to more than 1 million messages containing two-factor authentication codes in June 2023.

As an intermediary between the companies that generate the authentication codes and the end users, Fink Telecom Services has the right to process and view the content of the messages. What is worrying is that this company has been suspected of participating in user monitoring activities and interfering with personal accounts.

Vì sao xác thực hai yếu tố qua SMS không còn an toàn? - Ảnh 1.

SMS is considered one of the weakest security methods because it can be accessed by third parties.

The leaked OTP codes came from many big companies such as Google, Meta, Amazon, Tinder, Snapchat, Binance, Signal, WhatsApp and many banks in Europe. The messages were sent to users in more than 100 countries.

According to Yahoo, the main reason why SMS two-factor authentication is not secure is because companies often hire intermediaries to send SMS messages at a lower cost, through large contracts with multiple carriers and a system of “global titles” - network addresses used to connect across countries. The weakness of this system is that the hiring companies do not work directly with units like Fink Telecom Services, but through layers of subcontractors, making it more complicated to ensure data security.

Mr. Pham Manh Cuong, founder of Wischain Company Limited, explained that the two-factor authentication method via SMS messages is no longer safe today because cyber attackers are increasingly sophisticated, easily taking advantage of vulnerabilities in the security system to gain access.

One of the most common forms of phishing attacks is where seemingly reputable messages, emails, or websites are used to trick users into providing sensitive information such as usernames, passwords, or OTP codes.

Not only that, SIM swapping is also a serious threat. Fraudsters can steal the victim's phone number, from which they can receive authentication codes sent via SMS.

In addition, many users still have the habit of installing software of unknown origin, especially on Android devices, leading to spyware or keyloggers that can secretly record keyboard typing, thereby stealing access information.

While SMS authentication is still considered a certain layer of protection, compared to modern methods like Google Authenticator - an application that generates random authentication codes that change every 30 seconds and is independent of mobile networks - SMS is increasingly showing its weaknesses.

Source: https://nld.com.vn/xac-thuc-hai-yeu-to-qua-sms-rat-rui-ro-nen-dung-ung-dung-nao-196250621114624897.htm


Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

Notre Dame Cathedral in Ho Chi Minh City is brightly lit to welcome Christmas 2025
Hanoi girls "dress up" beautifully for Christmas season
Brightened after the storm and flood, the Tet chrysanthemum village in Gia Lai hopes there will be no power outages to save the plants.
The capital of yellow apricot in the Central region suffered heavy losses after double natural disasters

Same author

Heritage

Figure

Enterprise

Pho 'flying' 100,000 VND/bowl causes controversy, still crowded with customers

News

Political System

Destination

Product