The National Institute of Standards and Technology (NIST) has released the latest version of its Digital Authentication blueprint, which includes guidelines for greater online security. The new version heralds the future ban on SMS Two Factor Authentication (2FA).
The new guidelines (Digital Authentication Guideline or DAG) are a set of rules used by software manufacturers to build secure services, as well as by government and private entities to assess the security of services and software.
NIST experts are constantly updating the guidelines in an effort to keep up with the changes taking place in the IT field.
According to the latest version of the Digital Authentication Guideline (DAG), NIST officials appear to be discouraging companies from using two-factor authentication via SMS, stating that SMS 2FA could be considered insecure in future versions of the DAG.
The NIST DAG argues that two-factor authentication using SMS is a vulnerable process because the phone may not always be in the possession of its owner.
Also, because some VoIP services allow SMS message spoofing, NIST officials encourage software vendors that use SMS-based 2FA systems to check VoIP connections before sending a 2FA code.
SMS as a protocol is widely considered insecure. We have read of many weaknesses in the SMS protocol from time to time that allow data interception.
