SMS Two Factor Authentication
SMS two factor authentication uses a text message as the second factor. It reaches almost any phone and needs no app, which is why it is everywhere. It also has well-known weaknesses. Spriv offers both one-way SMS codes and two-way SMS verification, and uses them where they fit best: activation, fallback and confirmations, not as the everyday login factor.
One-way SMS codes vs two-way SMS verification
"SMS 2FA" covers two different interactions. The difference is which way the important information travels.
One-way SMS OTP
The service texts a one-time code and the user types it into the login page. Familiar and universal, but the code passes through the user's hands, so whoever controls the page they type it into can capture it.
Two-way SMS verification
The service texts a question and the user replies, for example YES or NO. Spriv posts the reply to your endpoint over HTTP POST, so the decision travels back on the phone network, separate from the login session.
Is SMS 2FA secure?
It is far better than a password alone: an attacker who only has the password still has to get the text message. But SMS is the weakest of the common second factors, for reasons that have nothing to do with the user.
SIM swap
An attacker persuades or bribes a mobile carrier to move the victim's number to a SIM card they control. From then on, every SMS code goes to the attacker, and the victim's phone simply loses service.
SS7 and network interception
SMS was not designed to carry secrets. Weaknesses in the signalling networks that route messages between carriers, known as SS7, have been used to intercept or redirect texts without touching the victim's phone.
Phishing
A fake login page asks for the password and then for the SMS code, and replays both to the real site within seconds. The code is genuine, so the login succeeds.
What NIST says
NIST's digital identity guidelines, SP 800-63B, treat out-of-band codes sent over the phone network, including SMS, as a restricted authenticator. Organisations that use it are expected to understand the risks and offer users an alternative. SMS is allowed, but it is not the recommended long-term choice.
Where SMS two factor authentication still earns its place
SMS works on any phone, needs no app and reaches users in more than 200 countries. Those strengths make it the right tool for specific jobs.
Phone verification
Before a phone is trusted, Spriv texts it a seven-digit PIN and the user types it in, proving the number really belongs to them.
Account activation
A one-way SMS code gets a new user started before the Spriv app is installed and paired.
Users who can't install apps
Feature phones, shared devices or policies that forbid personal apps. Two-way SMS gives these users a second factor anyway.
Fallback
When the app has no data connection but the phone still has carrier signal, an SMS keeps the user moving. With no signal at all, use TOTP.
Order and transaction confirmation
Two-way SMS asks the customer to confirm a purchase or change before it goes through. Transaction verification.
Windows, RDP and SSH logins
Two-way SMS is one of the four options at the login prompt on Spriv-protected Windows and RDP logins, and it is available over SSH.
How SMS is billed on Spriv
Unlike adaptive, Allow/Deny and TOTP, SMS has a real cost per message, because every text goes through a carrier. Spriv bills it per message and gives each Business account a monthly credit.
-
Billed per message
You pay for the texts you send, at the per-SMS rate.
-
$0.25 credit every month
Each Business account gets $0.25 of SMS credit per month.
-
Pooled at company level
Credit is shared across the company, so light and heavy SMS users balance out.
-
Free plan needs a card for SMS
The Startup plan is free with no card, but sending SMS requires one on file.
SMS two factor authentication questions
Should I turn off SMS 2FA?
Not if the alternative is a password alone. The better move is to make a stronger method the default, such as Spriv's adaptive authentication, and keep SMS for activation, fallback and users who cannot install the app.
Is two-way SMS safer than a one-way code?
It removes the code a phishing page could ask for, because the user replies to the text instead of typing anything into a website. It still depends on the phone network, so a SIM swap remains a risk.
Which countries does Spriv SMS reach?
More than 200. Weak carrier reception can delay delivery, so users in poor coverage areas are better served by TOTP, which needs no signal.
How does my application receive the reply?
Spriv posts the user's reply to your endpoint by HTTP POST, or your system can poll for the answer. 2FA API overview.
Do users need the Spriv app for SMS?
No. Both SMS methods work on any phone that can receive text messages.
Related pages
SMS where it helps, adaptive everywhere else
Two free users and two free servers, no credit card. Add a card when you are ready to send SMS.