NIST directive against SMS Two Factor Authentication

The National Institute of Standards and Technology (NIST) released the latest version of the Digital Authentication Plan, including guidelines for more safety on the Internet. The new version announces the future ban on the two-factor authentication method using SMS (SMS Two Factor Authentication or 2FA).

The new Digital Authentication Guideline (DAG) is a set of rules used by manufacturers to build secure services, as well as by government and private entities to assess the security of services and software.2fa NIST

NIST experts constantly update the guidelines in an effort to keep up with the changes in the IT field.

According to the latest version of the Digital Authentication Guideline (DAG), NIST officials seem to discourage companies from using two-way authentication via SMS, saying SMS 2FA could be considered unsafe in future versions of DAG.

The NIST DAG claims that the Two-factor authentication using SMS is a risky process because the phone may not always be in the possession of its owner.

Also because some VoIP services allow SMS messages to be intercepted, NIST officials encourage software vendors that use SMS 2FA systems to audit VoIP connections before one 2FA.

SMS as a protocol is widely considered unsafe. From time to time we have read many weaknesses in the SMS protocol that allow data to be intercepted.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).