Asked and answered: How to avoid SMS multi-factor hacks (2024)

Top insights for IT pros

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

Multi-factor authentication has frequently been described as a security trifecta: something you know (passwords), something you have (tokens), and something you are (fingerprints).

Increasingly, IT practitioners want to make sure one of the factors isn’t something you text. Hacking the unique numeric code inside an SMS message, after all, can be as easy as 81312.

“SMS text message is not a strong third factor, and we really want to try to move the industry away from using it,” said Jameeka Green Aaron, CISO at the authentication provider Okta, in September.

Some SMS weak spots:

  • Hackers can redirect (and receive for themselves) the two-factor codes and login links intended for a targeted user.
  • SIM swappers, who convince a mobile provider to move a target’s number to their new memory card, can then receive any SMS-based authentication prompts.
  • Malware, like Android code found in 2020, can extract two-factor authentication codes from SMS messages.
  • SMS communications can be intercepted and manipulated by “machine-in-the-middle” attacks or surveillance tools.

So, what’s the next move? How do you avoid the issue of compromised two-factor authentication due to SMS hacks?

IT Brew posed these questions to IT professionals, and received the following responses:

An obvious one, but don’t click! One of the best ways to avoid an SMS hack is to never open a message from an unknown sender, and to never hit the links. “You cannot be assured that they are the person whom they claim to be,” said Steve Wertheim, director of cybersecurity, MorganFranklin Consulting.

Use other authenticators—like, authenticators! An authenticator app, installed on a mobile device, generates a six- to eight-digit security key within a tight time window. QR codes often initiate the setup between authenticator and application. “The mobile devices these days make it easy to enroll in them to map to your organization…the users can effectively do the install themselves,” said Jason Stading, consulting manager at ISG.

Let’s put a pin in that for now. When stuck with SMS two-factor, work with a mobile provider to require a multi-digit PIN for any account changes, to prevent an attacker impersonating and SIM swapping, said Jason Rebholz, CISO at Corvus Insurance.

Call me (virtually). Hackers can trick customer-service reps into thinking their PIN got lost, or employees at the phone provider could be in on the scam, too. To take full control, Rebholz recommends registering for a virtual phone number through an option like Google Voice, which provides a (free) legitimate phone number and the ability to text.

“Use that number for that second factor, and then you are in control of who can access Google Voice because it’s protected behind your Google account,” Rebholz told IT Brew.—BH

Asked and answered: How to avoid SMS multi-factor hacks (2024)
Top Articles
What do I do if I become pregnant while studying?  · Student Services Online
10 Facts About Ambergris - Harbor Breeze Cruises
Automated refuse, recycling for most residences; schedule announced | Lehigh Valley Press
Places 5 Hours Away From Me
Craigslist Benton Harbor Michigan
What's New on Hulu in October 2023
State Of Illinois Comptroller Salary Database
Red Heeler Dog Breed Info, Pictures, Facts, Puppy Price & FAQs
Taylor Swift Seating Chart Nashville
Huge Boobs Images
iOS 18 Hadir, Tapi Mana Fitur AI Apple?
boohoo group plc Stock (BOO) - Quote London S.E.- MarketScreener
Mals Crazy Crab
Yakimacraigslist
The best TV and film to watch this week - A Very Royal Scandal to Tulsa King
Carson Municipal Code
No Hard Feelings - Stream: Jetzt Film online anschauen
Strange World Showtimes Near Roxy Stadium 14
Craigslist Southern Oregon Coast
Costco Great Oaks Gas Price
Gayla Glenn Harris County Texas Update
Project, Time & Expense Tracking Software for Business
Gina Wilson All Things Algebra Unit 2 Homework 8
U Of Arizona Phonebook
Tips and Walkthrough: Candy Crush Level 9795
Shreveport City Warrants Lookup
Cookie Clicker Advanced Method Unblocked
When Does Subway Open And Close
Obituaries Milwaukee Journal Sentinel
Kirsten Hatfield Crime Junkie
Dmv In Anoka
Watson 853 White Oval
Wolfwalkers 123Movies
Uncovering the Enigmatic Trish Stratus: From Net Worth to Personal Life
Japanese Emoticons Stars
Emuaid Max First Aid Ointment 2 Ounce Fake Review Analysis
Courtney Roberson Rob Dyrdek
Chadrad Swap Shop
2487872771
Back to the Future Part III | Rotten Tomatoes
Arcadia Lesson Plan | Day 4: Crossword Puzzle | GradeSaver
Section 212 at MetLife Stadium
Callie Gullickson Eye Patches
Sdn Fertitta 2024
3 Zodiac Signs Whose Wishes Come True After The Pisces Moon On September 16
bot .com Project by super soph
Bellelement.com Review: Real Store or A Scam? Read This
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Call2Recycle Sites At The Home Depot
Game Akin To Bingo Nyt
Craigslist Cars And Trucks For Sale By Owner Indianapolis
Latest Posts
Article information

Author: Dan Stracke

Last Updated:

Views: 5895

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Dan Stracke

Birthday: 1992-08-25

Address: 2253 Brown Springs, East Alla, OH 38634-0309

Phone: +398735162064

Job: Investor Government Associate

Hobby: Shopping, LARPing, Scrapbooking, Surfing, Slacklining, Dance, Glassblowing

Introduction: My name is Dan Stracke, I am a homely, gleaming, glamorous, inquisitive, homely, gorgeous, light person who loves writing and wants to share my knowledge and understanding with you.