<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>mfa on SpartanAuth Blog</title>
    <link>https://blog.spartanauth.com/tags/mfa/</link>
    <description>SpartanAuth Blog (mfa)</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 17 May 2022 15:46:07 -0600</lastBuildDate>
    
    <atom:link href="https://blog.spartanauth.com/tags/mfa/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>SMS OTP</title>
      <link>https://blog.spartanauth.com/posts/sms-otp/</link>
      <pubDate>Tue, 17 May 2022 15:46:07 -0600</pubDate>
      
      <guid>https://blog.spartanauth.com/posts/sms-otp/</guid>
      <description>&lt;p&gt;Have you ever switched phone providers? Maybe you walked into a store, found that shiny new phone you&amp;rsquo;ve always wanted (or just learned that you always wanted). The store employees are super happy with your choice. They get your information, you give them your phone number, and the next thing you know you have a new phone and a new provider. Easy, right?&lt;/p&gt;
&lt;p&gt;Now imagine someone else — who is not you — decides they want a new phone too. Only they want access to some of your accounts. They pretend they are you. They tell the store your phone number. The store activates &lt;em&gt;your&lt;/em&gt; phone number on &lt;em&gt;their&lt;/em&gt; device. They can now receive text messages intended for you. That trick is called &lt;strong&gt;SIM swapping&lt;/strong&gt;. There are other ways attackers get SMS messages too: forwarding numbers, account-port abuse, or social engineering someone at the carrier.&lt;/p&gt;
&lt;div class=&#34;stat-row&#34;&gt;

&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;SIM swap&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Your number, their device — SMS codes included&lt;/figcaption&gt;&lt;/figure&gt;

&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;Port / forward&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Other ways attackers redirect texts&lt;/figcaption&gt;&lt;/figure&gt;


&lt;/div&gt;

&lt;p&gt;All this to say: SMS and phone numbers are weak channels for security-sensitive messages. For something so easy to redirect, it is surprising how often we still use them as a &amp;ldquo;second factor&amp;rdquo; protecting real accounts. Microsoft has even &lt;a href=&#34;https://www.thurrott.com/cloud/243821/microsoft-stop-using-sms-for-mfa#:~:text=SMS%2Dbased%20authentication%2C%20he,an%20authentication%20attempt%20fails.&#34;&gt;suggested&lt;/a&gt; that SMS-based MFA is a bad idea.&lt;/p&gt;
&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;Avoid SMS MFA&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Even major vendors have warned against SMS as a second factor&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.thurrott.com/cloud/243821/microsoft-stop-using-sms-for-mfa&#34; rel=&#34;noopener&#34;&gt;Microsoft (via Thurrott)&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;

&lt;p&gt;That is why &lt;strong&gt;I am not implementing SMS 2FA in &lt;a href=&#34;https://www.spartanauth.com&#34;&gt;SpartanAuth&lt;/a&gt;&lt;/strong&gt;. I would rather push people toward stronger factors and clearer UX than paper over account recovery with a channel attackers already know how to steal. SpartanAuth focuses on better options instead.&lt;/p&gt;
&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;No SMS 2FA&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;By design in SpartanAuth — stronger factors instead&lt;/figcaption&gt;&lt;/figure&gt;

&lt;p&gt;If you have feature requests or opinions on which factors matter most in practice, I want to hear them. Reach me at &lt;a href=&#34;mailto:feedback@spartanauth.com&#34;&gt;feedback@spartanauth.com&lt;/a&gt;.&lt;/p&gt;
&lt;aside class=&#34;waitlist-cta&#34; aria-label=&#34;SpartanAuth updates&#34;&gt;
  &lt;p class=&#34;waitlist-cta-kicker&#34;&gt;Stay in the loop&lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-text&#34;&gt;
    Get occasional notes from me on authentication and SpartanAuth — plus early access as new things ship.
  &lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-action&#34;&gt;
    &lt;a class=&#34;waitlist-cta-button&#34; href=&#34;https://lc.spartanauth.com/q/waitlist-sa/start&#34; rel=&#34;noopener&#34;&gt;Get updates&lt;/a&gt;
  &lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-note&#34;&gt;Low volume. No spam. Unsubscribe anytime.&lt;/p&gt;
&lt;/aside&gt;</description>
    </item>
    
  </channel>
</rss>
