https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • Complete 2023 MSP 501 Rankings
    • 2023 MSP 501 50-1
    • 2023 MSP 501 100-51
    • 2023 MSP 501 150-101
    • 2023 MSP 501 200-151
    • 2023 MSP 501 250-201
    • 2023 MSP 501 300-251
    • 2023 MSP 501 350-301
    • 2023 MSP 501 400-351
    • 2023 MSP 501 450-401
    • 2023 MSP 501 501-451
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2023 MSP 501
    • 2023 NextGen 101
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2024 CP Expo Call for Speakers
    • Channel Futures Leadership Summit
    • MSP Summit
    • CP Conference & Expo
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • Complete 2023 MSP 501 Rankings
    • 2023 MSP 501 50-1
    • 2023 MSP 501 100-51
    • 2023 MSP 501 150-101
    • 2023 MSP 501 200-151
    • 2023 MSP 501 250-201
    • 2023 MSP 501 300-251
    • 2023 MSP 501 350-301
    • 2023 MSP 501 400-351
    • 2023 MSP 501 450-401
    • 2023 MSP 501 501-451
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2023 MSP 501
    • 2023 NextGen 101
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2024 CP Expo Call for Speakers
    • Channel Futures Leadership Summit
    • MSP Summit
    • CP Conference & Expo
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

Microsoft: Authenticator More Secure than SMS for One-Time Passwords

  • Written by Jeffrey Schwartz
  • November 16, 2020
PINs sent via SMS can’t be encrypted, making them less secure than authentication apps.

Microsoft is pressing companies to move away from sending one-time passwords over PSTN and SMS networks for multi-factor authentication (MFA).

Texting or sending voice-based one-time passwords carries some risk, Microsoft’s director of security, Alex Weinert, warned. Hackers can intercept the one-time passwords and penetrate a network or take over an account, he said. Likewise, SMS and voice sent over PSTNs increase the risk of customers falling victim to phishing and social engineering attacks.

“I believe they’re the least secure of the MFA methods available today,” Weinert noted in a blog. “That gap will only widen as MFA adoption increases attackers’ interest in breaking these methods and purpose-built authenticators extend their security and usability advantages.”

Weinert said organizations that are using SMS and voice should transition to cryptographically protected credentials tools support Fast Identity Online (FIDO) Alliance standards. Nevertheless, Weinert emphasized that if you use SMS or PSTN-based one-time passwords, that’s still better than not using MFA. Likewise, he noted the risk is relatively low and that organizations that have not implemented MFA shouldn’t delay doing so.

“MFA is essential — we are discussing which MFA method to use, not whether to use MFA,” he noted.

Brian Sherman, a solutions engineer at Valeo Networks, a provider of managed security services, agreed.

Valeo Networks' Brian Sherman

Valeo Networks’ Brian Sherman

“Weaker MFA is always better than no MFA,” Sherman said. “Unfortunately, SMS was never intended to be used as a means of authentication.”

App-Based Authentication with Encryption

Rather than SMS or voice, organizations should use app-based authentication, according to Weinert. In Microsoft’s case, the tool of choice is  Microsoft Authenticator. The app uses encrypted communication and allows bidirectional communication on authentication status, Weinert noted. Over the past year, Microsoft has added app lock, the ability to hide notifications from the lock screen, and sign-in history.

The problem with SMS and voice protocols sent over PSTNs is they weren’t designed to support encryption, according to Weinert.

“Signals can be intercepted by anyone who can get access to the switching network or within the radio range of a device,” he noted.

Weiner raised that point last year, when he noted that “an attacker can deploy a software-defined-radio to intercept messages, or a nearby FEMTO, or use an SS7 intercept service to eavesdrop on the phone traffic.”

NIST Warnings

Microsoft isn’t the first company that has campaigned against using SMS or voice for MFA. Security experts have warned of the risks for several years. In 2016, the National Institute of Standards (NIST) initially proposed restricting the use of the networks for OTPs. While the agency softened its language, it still is not a recommended practice.

“We recommend our clients use app-based MFA whenever possible,” Valeo Networks’ Sherman said. “Under some specific scenarios we recommend physical keys; for example, if employees are not allowed to carry cellphones.”

In July, Google announced it was shifting from SMS and voice-based codes to phone prompts as its primary form of MFA. According to research conducted by Google last year, on-device prompts were a more secure than SMS. Cybercrooks were only successful with 1% of bulk phishing attempts with the phone prompts, which compares to 4% with SMS. Targeted attacks with phone prompts had a 10% success rate, compared with 26% with SMS. When used with security keys, no one successfully implemented a targeted or phishing attack.

For its part, 99% of Valeo Networks’ clients use MFA in some capacity, according to Sherman.

“I don’t think there are any that use strictly SMS,” he said. “It’s more of a mixed bag among the user base. I would say it’s roughly an even split between app based and SMS.”

Tags: MSPs Technologies Mobility & Wireless Security

Most Recent


  • Trend Micro Partner Program Gets Big Redesign
    The program is built around the Trend Micro One platform.
  • CEO Steve Brazier at Canalys Channels Forum EMEA 2023
    Canalys Channels Forum EMEA 2023: Vendors Ask Channel for Help During Economic Slowdown
    Channel partners are thriving as IT vendors continue to move to "partner-first" to navigate a tough economy, says Canalys.
  • No Competition?
    In Major CCaaS Play, NICE to Acquire LiveVox for $350 Million
    The move is part of a greater trend of CCaaS consolidation, which experts expect to continue.
  • Avaya CEO: Post-Bankruptcy, Channel Partners Enabling Collective Growth
    We picked the brain of Avaya's CEO’s regarding the channel's role in the company's emergence from chapter 11.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • edge computing
    'Challenging Results' for MSPs in Channel Futures' Exclusive Quarterly Survey
  • White House
    White House Urges Companies to Take Ransomware Attacks More Seriously
  • Security shield on digital background
    VMware Security Connect Focused on Redefining Security, Increasing Threats
  • Fortune 500 2021 logo
    AT&T, Microsoft, Verizon, More Tech, Telco Companies Make Latest Fortune 500

Upcoming Events

View all

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Channel Partners Conference & Expo

March 11, 2024 - March 14, 2024

Channel Futures Leadership Summit 2024

September 17, 2024 - September 19, 2024

Galleries

View all

Channel People on the Move: HP, 8×8, Five9, Nitel, RapidScale, More

October 3, 2023

7 Trends Impacting Ingram Micro Partners: Marriage of AI, Data Looms Large

October 2, 2023

Nutanix Partner Program Sees More Changes, Vendor Touts ‘Channel-Led’

October 2, 2023

Industry Perspectives

View all

Partners Balance Multicloud Opportunity, Complexity

September 25, 2023

Why Conversational AI Matters for Your Customers and How It Can Boost Your Revenue

September 15, 2023

The 5 Ds that Lead to Unplanned Business Sales

September 13, 2023

Webinars

View all

MSP 501: Leadership in Cybersecurity

October 19, 2023

DE&I: Find the Balance that Works for You

September 7, 2023

Above and Beyond with the NextGen 101ers

August 30, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 129: ZLH Enterprises

Coffee with Craig and James Episode 128: Channel Partner Strategies Intelligence Service

August 25, 2023

Coffee with Craig and James Episode 127: Expereo, Movie Night Returns

August 18, 2023

Coffee with Craig and James Episode 126: ARG

July 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X