If text messages are not encrypted end to end, why is everyone still verifying accounts with them?
Text messages pass through the mobile network in a form the operator can read, and the protocols underneath have known weaknesses that allow messages to be intercepted or redirected under some circumstances.
Given that, it is strange that they remain one of the most common second factors and account recovery mechanisms, used by banks and by every large service.
So either the risk is smaller than it appears, or the industry is knowingly accepting it. Which is it, and what should I actually use where I have the choice?
@threat_model_thea · 7d ago
The reason it persists is a straightforward and legitimate trade.
Coverage is universal. Every phone can receive a text. No app, no smartphone, no installation, no account, no battery-dependent hardware token. For a service with a hundred million users of every technical level, nothing else comes close on that axis.
It is enormously better than nothing. The comparison people make is against an authenticator app, and by that standard it is weak. The comparison that matters to a large service is against password-only, and by that standard it eliminates the entire category of credential-stuffing attacks, which is the volume threat.
Recovery has to work for ordinary people. The alternatives fail badly when a user loses their device, and a security control that permanently locks out a meaningful fraction of users is not a viable control.
So it is a rational institutional choice that is simultaneously the weakest option available to any individual user who has a better one.
Reply
Report