{"id":1461,"date":"2016-11-29T14:46:21","date_gmt":"2016-11-29T18:46:21","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=1461"},"modified":"2016-11-29T14:46:21","modified_gmt":"2016-11-29T18:46:21","slug":"why-using-sms-in-your-authentication-chain-is-risky-appsec-2016","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/","title":{"rendered":"Why Using SMS in Your Authentication Chain is Risky, AppSec 2016"},"content":{"rendered":"<p style=\"text-align: justify\"><em>Passwords are horrible for security. Over the past 20 <\/em>years<em> we\u2019ve bolstered the password with other factors, the most common being a <\/em>one time<em> password (OTP, TOTP, HOTP) that is either generated on a physical device the user holds, in a smartphone app or most commonly sent via SMS. Using SMS for authentication is not secure. We\u2019ve known this for years, but recently we\u2019ve been reminded of this with problems with Google and Apple SMS security. <\/em><\/p>\n<p><em>SMS is important to ensure we have a backup way of allowing people to <\/em>login<em> to systems, but it should always be a last resort. So what\u2019s the first resort? Second factors to the password need a different communications channel to the one a user is authenticating to. SMS is not secure, but push notification methods are. It is possible to initiate a communication channel via Apple, Google and Microsoft mobile notification networks. At the end of these push notifications is a secured app that in turn securely communicates with the 2FA back end. Not only is this method more secure, it\u2019s actually a far improved user experience that can be extended beyond the login to secure in application transactions.<\/em><\/p>\n<p><em>This presentation will go over the limitations of traditional two-factor methods and introduce the improved approach using a push notification channel to achieve the same goal, i.e. authenticate a user identity by validating the initiating request comes from a person who has something in their possession which is trusted.<\/em><\/p>\n<p><iframe loading=\"lazy\" title=\"Simon Thorpe - Why using SMS in the authentication chain is risky - AppSecUSA 2016\" width=\"500\" height=\"375\" src=\"https:\/\/www.youtube.com\/embed\/M5r4xo7VyRY?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" allowfullscreen><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Passwords are horrible for security. Over the past 20 years we\u2019ve bolstered the password with other factors, the most common being a one time password (OTP, TOTP, HOTP) that is either generated on a physical device the user holds, in a smartphone app or most commonly sent via SMS. Using SMS for authentication is not [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":1462,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[7],"tags":[146,448,125,145,451,147,447,449,450],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Why Using SMS in Your Authentication Chain is Risky, AppSec 2016 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/\",\"name\":\"Why Using SMS in Your Authentication Chain is Risky, AppSec 2016 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2016\/11\/SMS-Authentication-Chain-Risky.jpg\",\"datePublished\":\"2016-11-29T18:46:21+00:00\",\"dateModified\":\"2016-11-29T18:46:21+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2016\/11\/SMS-Authentication-Chain-Risky.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2016\/11\/SMS-Authentication-Chain-Risky.jpg\",\"width\":632,\"height\":278},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why Using SMS in Your Authentication Chain is Risky, AppSec 2016\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why Using SMS in Your Authentication Chain is Risky, AppSec 2016 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/","url":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/","name":"Why Using SMS in Your Authentication Chain is Risky, AppSec 2016 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2016\/11\/SMS-Authentication-Chain-Risky.jpg","datePublished":"2016-11-29T18:46:21+00:00","dateModified":"2016-11-29T18:46:21+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2016\/11\/SMS-Authentication-Chain-Risky.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2016\/11\/SMS-Authentication-Chain-Risky.jpg","width":632,"height":278},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/why-using-sms-in-your-authentication-chain-is-risky-appsec-2016\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Why Using SMS in Your Authentication Chain is Risky, AppSec 2016"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/1461"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=1461"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/1461\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/1462"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=1461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=1461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=1461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}