Skip to main content

SMS OTP

Have you ever switched phone providers? Maybe you walked into a store, found that shiny new phone you’ve always wanted (or just learned that you always wanted). The store employees are super happy with your choice. They get your information, you give them your phone number, and the next thing you know you have a new phone and a new provider. Easy, right?

Now imagine someone else — who is not you — decides they want a new phone too. Only they want access to some of your accounts. They pretend they are you. They tell the store your phone number. The store activates your phone number on their device. They can now receive text messages intended for you. That trick is called SIM swapping. There are other ways attackers get SMS messages too: forwarding numbers, account-port abuse, or social engineering someone at the carrier.

SIM swap
Your number, their device — SMS codes included
Port / forward
Other ways attackers redirect texts

All this to say: SMS and phone numbers are weak channels for security-sensitive messages. For something so easy to redirect, it is surprising how often we still use them as a “second factor” protecting real accounts. Microsoft has even suggested that SMS-based MFA is a bad idea.

Avoid SMS MFA
Even major vendors have warned against SMS as a second factor

That is why I am not implementing SMS 2FA in SpartanAuth. I would rather push people toward stronger factors and clearer UX than paper over account recovery with a channel attackers already know how to steal. SpartanAuth focuses on better options instead.

No SMS 2FA
By design in SpartanAuth — stronger factors instead

If you have feature requests or opinions on which factors matter most in practice, I want to hear them. Reach me at [email protected].