
In the latest draft of the Digital Authentication Guideline, the rules by which authentication software must abide, the US National Institute for Standards and Technology is preparing to get rid of SMS-based two-factor authentication. The reason for this is that SMS is relatively insecure. The phone may not be in the original owner's possession, or the SMS may be hijacked by a VoIP service, Softpedia notes.
The relevant paragraph reads: "If the out of band verification is to be made using a SMS message on a public mobile telephone network, the verifier SHALL verify that the pre-registered telephone number being used is actually associated with a mobile network and not with a VoIP (or other software-based) service. It then sends the SMS message to the pre-registered telephone number. Changing the pre-registered telephone number SHALL NOT be possible without two-factor authentication at the time of the change. OOB using SMS is deprecated, and will no longer be allowed in future releases of this guidance." (Emphasis is NIST's.)
However, the guideline notes that two-factor authentication via a secure application or biometrics, such as a fingerprint scaer, may still be used.
برچسب:
نویسنده: استخدام کار