Technology

Two-way authentication via SMS is simply insecure

Sending security tokens via SMS is often still considered a secure method in two-way authentication. However, US authorities are warning against using this method after serious attacks on critical infrastructure.

Experience from Salt Typhoon

A recent cyberattack, dubbed the “Salt Typhoon,” has exposed serious vulnerabilities in the U.S. telecommunications infrastructure. Hackers believed to be close to the Chinese government have reportedly gained access to unencrypted communications such as phone calls and text messages.

The attack is considered one of the worst in US history. The US agency Cybersecurity and Infrastructure Security Agency (CISA) warned Therefore, this week we expressly caution against using SMS as a method for multi-factor authentication (MFA). Their current policy states: “SMS messages are not encrypted. An attacker with access to a telecommunications network can intercept and read these messages.” SMS-MFA is not a safe option, especially for high-ranking targets.

CISA’s recommendation is to use phishing-resistant methods such as authentication apps or passkeys instead. While not all services offer alternative MFA options, users should switch to more secure alternatives when possible.

FBI open to crypto

Salt Typhoon certainly left an impression on the security authorities. This is reflected, among other things, in the fact that even the FBI, which has traditionally taken a skeptical stance towards strong encryption, now recommends its use.

The agency has advocated for using apps like Signal that offer end-to-end encryption. These guarantee secure communication and are compatible with common operating systems such as iOS, Android, Windows and MacOS. CISA highlights that encrypted messaging apps are critical not only for individuals but also for government agencies. The goal is, after all, to protect communication channels from potential eavesdropping attempts.

Recent Posts

Multikernel Linux: Multiple Linux systems without a VM on one device

Multikernel Technologies has a public version of its multikernel Linux for the first time with…

3 days ago

Memory crisis makes you creative: New MSI laptop with DDR4 or DDR5

The world's PC manufacturers are in a bind when it comes to memory. DDR4 RAM…

3 days ago

Gamescom 2026: Series of thefts hit small indie developers hard

How safe are the protected halls of Gamescom 2026 really? After the night-time theft of…

3 days ago

GrapheneOS: No secure Android for the Pixel 11 because Google is sloppy?

Google has apparently made changes to the security features of the Pixel 11 series, which…

3 days ago

The Smart Girl’s Guide to Staying Safe Online While Shopping

Bagging a bargain online has never been easier - or riskier. Between dodgy "influencer" deals…

3 days ago

Google against website operators: AI overview in search even larger

Google is expanding its AI overviews and is now displaying even more information and details…

3 days ago