Skip to main content

Tag: authentication

SMS OTP

Have you ever switched phone providers? Maybe you walked into a store, found that shiny new phone you’ve always wanted (or just learned that you always wanted). The store employees are super happy with your choice. They get your information, you give them your phone number, and the next thing you know you have a new phone and a new provider. Easy, right?

Now imagine someone else — who is not you — decides they want a new phone too. Only they want access to some of your accounts. They pretend they are you. They tell the store your phone number. The store activates your phone number on their device. They can now receive text messages intended for you. That trick is called SIM swapping. There are other ways attackers get SMS messages too: forwarding numbers, account-port abuse, or social engineering someone at the carrier.

SIM swap
Your number, their device — SMS codes included
Port / forward
Other ways attackers redirect texts

Cost of Passwords

I keep coming back to a blunt fact: passwords are expensive. Not just annoying — expensive in support time, abandoned checkouts, and breach cleanup.

It has been observed that many companies’ support teams are overloaded with password reset calls. According to research from Forrester, the average cost for a single password reset is about $70. Another report by Gartner estimates that 20% to 50% of all help desk calls are for password resets.

$70
Average cost of one help-desk password reset
20–50%
Of help desk calls are password resets

On top of all this, according to a report from IBM, 20% of all breaches came from compromised credentials.