NewsBite

Just how safe is that two-factor login code?

Just how safe is that two-factor login code?

An investigation into the complexity of the global telecom system has revealed weaknesses in the transmission of secret codes sent via text messages.

When companies generate verification code messages, they usually outsource the job, passing the codes through a thicket of intermediaries.  Bethany Rae

Every day, millions of people sign in to their email, banking app or social media accounts with both their password and a one-time login code they receive by text message. The codes often arrive with a warning: “Do not share this with anyone.” The recipients of those warnings, though, have no way of knowing who saw it before it got to them.

When companies generate messages with one of these so-called two-factor authentication codes, they almost never send them directly. Instead, they outsource the job, passing the codes through a thicket of intermediaries before they arrive at their destinations. Because of inherent weaknesses in SMS – the decades-old technology standard used for text messages – it is possible for entities that handle such messages to see their content. But the complexity of the system means neither the sender nor the recipient can be sure exactly who’s handled them along the way.

Loading...

Bloomberg Businessweek

Read More

Latest In Telecommunications

Fetching latest articles

Original URL: https://www.afr.com/companies/telecommunications/just-how-safe-is-that-two-factor-login-code-20250619-p5m8uk