SMS 2FA

SMS Two Factor Authentication

SMS two factor authentication uses a text message as the second factor. It reaches almost any phone and needs no app, which is why it is everywhere. It also has well-known weaknesses. Spriv offers both one-way SMS codes and two-way SMS verification, and uses them where they fit best: activation, fallback and confirmations, not as the everyday login factor.

Two-way SMS asking the customer to reply yes to confirm a purchase
Two-way SMS · Reply yes to confirm the order
0+
Countries where Spriv delivers SMS
0
Digits in the phone verification PIN
0
Apps to install for SMS methods
0
SMS methods: one-way code and two-way reply
The basics

One-way SMS codes vs two-way SMS verification

"SMS 2FA" covers two different interactions. The difference is which way the important information travels.

One-way SMS OTP

The service texts a one-time code and the user types it into the login page. Familiar and universal, but the code passes through the user's hands, so whoever controls the page they type it into can capture it.

Two-way SMS verification

The service texts a question and the user replies, for example YES or NO. Spriv posts the reply to your endpoint over HTTP POST, so the decision travels back on the phone network, separate from the login session.

Example two-way message. "Did you buy a laptop from 'examplecompany' for $476? Reply yes and we ship it. Reply no and we cancel the order." The customer's answer is the confirmation, and there is no code for a fake page to ask for.
Honest answer

Is SMS 2FA secure?

It is far better than a password alone: an attacker who only has the password still has to get the text message. But SMS is the weakest of the common second factors, for reasons that have nothing to do with the user.

SIM swap

An attacker persuades or bribes a mobile carrier to move the victim's number to a SIM card they control. From then on, every SMS code goes to the attacker, and the victim's phone simply loses service.

SS7 and network interception

SMS was not designed to carry secrets. Weaknesses in the signalling networks that route messages between carriers, known as SS7, have been used to intercept or redirect texts without touching the victim's phone.

Phishing

A fake login page asks for the password and then for the SMS code, and replays both to the real site within seconds. The code is genuine, so the login succeeds.

What NIST says

NIST's digital identity guidelines, SP 800-63B, treat out-of-band codes sent over the phone network, including SMS, as a restricted authenticator. Organisations that use it are expected to understand the risks and offer users an alternative. SMS is allowed, but it is not the recommended long-term choice.

How it scores. In the MFA comparison table, SMS covers brute force, key logging and static page authentication, and little else. Spriv's adaptive method covers all eleven checks, which is why it is the default and SMS is the supporting cast.
Where SMS fits

Where SMS two factor authentication still earns its place

SMS works on any phone, needs no app and reaches users in more than 200 countries. Those strengths make it the right tool for specific jobs.

Phone verification

Before a phone is trusted, Spriv texts it a seven-digit PIN and the user types it in, proving the number really belongs to them.

Account activation

A one-way SMS code gets a new user started before the Spriv app is installed and paired.

Users who can't install apps

Feature phones, shared devices or policies that forbid personal apps. Two-way SMS gives these users a second factor anyway.

Fallback

When the app has no data connection but the phone still has carrier signal, an SMS keeps the user moving. With no signal at all, use TOTP.

Order and transaction confirmation

Two-way SMS asks the customer to confirm a purchase or change before it goes through. Transaction verification.

Windows, RDP and SSH logins

Two-way SMS is one of the four options at the login prompt on Spriv-protected Windows and RDP logins, and it is available over SSH.

Pricing

How SMS is billed on Spriv

Unlike adaptive, Allow/Deny and TOTP, SMS has a real cost per message, because every text goes through a carrier. Spriv bills it per message and gives each Business account a monthly credit.

  • Billed per message

    You pay for the texts you send, at the per-SMS rate.

  • $0.25 credit every month

    Each Business account gets $0.25 of SMS credit per month.

  • Pooled at company level

    Credit is shared across the company, so light and heavy SMS users balance out.

  • Free plan needs a card for SMS

    The Startup plan is free with no card, but sending SMS requires one on file.

Questions

SMS two factor authentication questions

Should I turn off SMS 2FA?

Not if the alternative is a password alone. The better move is to make a stronger method the default, such as Spriv's adaptive authentication, and keep SMS for activation, fallback and users who cannot install the app.

Is two-way SMS safer than a one-way code?

It removes the code a phishing page could ask for, because the user replies to the text instead of typing anything into a website. It still depends on the phone network, so a SIM swap remains a risk.

Which countries does Spriv SMS reach?

More than 200. Weak carrier reception can delay delivery, so users in poor coverage areas are better served by TOTP, which needs no signal.

How does my application receive the reply?

Spriv posts the user's reply to your endpoint by HTTP POST, or your system can poll for the answer. 2FA API overview.

Do users need the Spriv app for SMS?

No. Both SMS methods work on any phone that can receive text messages.

Checkit!

SMS where it helps, adaptive everywhere else

Two free users and two free servers, no credit card. Add a card when you are ready to send SMS.