[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=”dark” text_align=”left” row_border_radius=”none” row_border_radius_applies=”bg” overlay_strength=”0.3″ gradient_direction=”left_to_right” shape_divider_position=”bottom” bg_image_animation=”none”][vc_column column_padding=”no-extra-padding” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”all” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/1″ tablet_width_inherit=”default” tablet_text_alignment=”default” phone_text_alignment=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][vc_row_inner column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” text_align=”left”][vc_column_inner column_padding=”no-extra-padding” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”all” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/2″ tablet_width_inherit=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][vc_column_text]
Lee Suker, director of Market Development at XConnect makes the case for SMS ‘One Time Passwords’ (OTPs) as part of a set of security controls, but urges caution when choosing providers.
If you have been tuning into the Mobile Ecosystem Forum (MEF) Privacy and Identity Working Group, you would have heard all about the ‘UserID & Password’ being broken. This isn’t quite the case, but what the headline points out is that the over reliance on a single knowledge factor presents a significant security risk.
Multi Factor Authentication will soon be the normality for online lives:[/vc_column_text][/vc_column_inner][vc_column_inner column_padding=”padding-2-percent” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”left-right” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/2″ tablet_width_inherit=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][image_with_animation image_url=”31903″ animation=”Fade In” hover_animation=”none” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”default” max_width=”100%” max_width_mobile=”default”][/vc_column_inner][/vc_row_inner][vc_row_inner column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” top_padding=”20″ text_align=”left”][vc_column_inner column_padding=”no-extra-padding” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”all” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/1″ tablet_width_inherit=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][vc_column_text]
[icon color=”Accent-Color” size=”small” image=”fa-quote-left”] But…not all providers of SMS are the same. Choosing suppliers poorly may leave end users and your business with little more than just a sense of security, or it could result in end-users failing to adopt 2FA due to poor user experiences.”
These are familiar security themes which elevate authentication assurance. Yet some of these questions are difficult, sensitive or risky to answer.
Two Factor Authentication (something you know, something you have) using SMS One-Time-Passcodes has become the go-to solution to improve security. It has been successful for good reason – it’s simple to use and the public is fully trained in how to use it, enterprises that deploy it observe a significant reduction in account takeovers and fraud, and it’s readily available from SMS service providers.
But…not all providers of SMS are the same. Choosing suppliers poorly may leave end users and your business with little more than just a sense of security, or it could result in end-users failing to adopt 2FA due to poor user experiences.
So, what are the things to look for when choosing a provider?
Another consideration is not to over use SMS 2FA. It is not always necessary and it will become cumbersome for your subscribers and costly for you. Too much SMS 2FA could result in choosing a supplier on cost and defeating your original security objectives. So, consider SMS 2FA as a proof of possession at the time of asking, which should then enable you to trust some other possession factor that persists over time e.g. the same laptop or mobile device logging in.
SMS OTP has been unfairly derided in the press because it has been relied upon to secure very high value accounts like bitcoin wallets, bank accounts and VIP social media account. For high value transactions it’s worth hackers going to the effort of conducting simswap fraud or other social engineering techniques to takeover a user’s mobile number and intercept these transactions – whereas this sort of hack doesn’t scale up to support a broad attack.[/vc_column_text][/vc_column_inner][/vc_row_inner][/vc_column][/vc_row][vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=”dark” text_align=”left” row_border_radius=”none” row_border_radius_applies=”bg” overlay_strength=”0.3″ gradient_direction=”left_to_right” shape_divider_position=”bottom” bg_image_animation=”none”][vc_column column_padding=”no-extra-padding” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”all” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/1″ tablet_width_inherit=”default” tablet_text_alignment=”default” phone_text_alignment=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][vc_row_inner column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” text_align=”left”][vc_column_inner column_padding=”padding-2-percent” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”right” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”5/6″ tablet_width_inherit=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][vc_column_text]These threats are being mitigated, as MNOs are improving their procedures. At a recent briefing from the GSMA it was interesting to hear from Europol that criminals are shifting focus away from simswap attacks, because it’s getting too hard, and focusing efforts on phishing victims direct and asking for OTP codes over the phone.
What is clear from this is that securing any relationship with high-net-worths, VIPs, high value transactions or sensitive data requires more than just 2FA using a one-time-code. Other great methods are available to protect subscribers in these use-cases.
However, for the day to day, SMS 2FA is still a valuable tool in your armoury to secure your customer’s details and engender trust with them. Just ensure that you select a provider that will ensure fast and secure delivery of those OTPs to your customer base.[/vc_column_text][divider line_type=”No Line” custom_height=”30″][/vc_column_inner][vc_column_inner column_padding=”no-extra-padding” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”left” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/6″ tablet_width_inherit=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][vc_text_separator title=”Lee Suker” title_align=”separator_align_left” color=”blue”][image_with_animation image_url=”84856″ animation=”Fade In” hover_animation=”none” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”default” max_width=”100%” max_width_mobile=”default”][vc_column_text]
[icon color=”Accent-Color” animation_speed=”Slow” size=”regular” icon_size=”” animation_delay=”” image=”fa-linkedin-square”] [icon color=”Accent-Color” animation_speed=”Slow” size=”regular” icon_size=”” animation_delay=”” image=”fa-twitter-square”] [icon color=”Accent-Color” animation_speed=”Slow” size=”regular” icon_size=”” animation_delay=”” image=”fa-envelope-square”] [icon color=”Accent-Color” animation_speed=”Slow” size=”regular” icon_size=”” animation_delay=”” image=”fa-share-square”]
[/vc_column_text][/vc_column_inner][/vc_row_inner][/vc_column][/vc_row][vc_row type=”full_width_content” full_screen_row_position=”middle” column_margin=”default” equal_height=”yes” content_placement=”middle” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” bg_color=”#2681c3″ scene_position=”center” top_padding=”2″ bottom_padding=”5″ text_color=”light” text_align=”left” row_border_radius=”none” row_border_radius_applies=”bg” overlay_strength=”0.3″ gradient_direction=”left_to_right” shape_divider_position=”bottom” bg_image_animation=”none” shape_type=””][vc_column column_padding=”padding-3-percent” column_padding_tablet=”inherit” column_padding_phone=”inherit” column_padding_position=”left-right” background_color_opacity=”1″ background_hover_color_opacity=”1″ column_shadow=”none” column_border_radius=”none” column_link_target=”_self” gradient_direction=”left_to_right” overlay_strength=”0.3″ width=”1/1″ tablet_width_inherit=”default” tablet_text_alignment=”default” phone_text_alignment=”default” column_border_width=”none” column_border_style=”solid” bg_image_animation=”none”][/vc_column][/vc_row]