Yahoo recently developed a new system for accessing its services without a password.
This new system uses the mobile phone to verify the user's identity. Instead of typing passwords, the user receives a verification code via SMS on their mobile phone (of course, the user is required to provide their mobile phone number when activating this option). Once the user receives the code, they log in and connect to their account!
Are you wondering what evil might lurk behind this wonderful advancement in the field of identity verification?
Well, the intentions are the best, it's encouraging that online services are putting effort and thought into making their users' lives easier and safer. However, analysis shows that this method is probably not the safest solution...
Essentially, it's another single-factor authentication method, meaning it doesn't offer any additional security. If the single factor is compromised, the user loses control of their account again, just like with password.
Whether you forget your password or lose your mobile phone, the result is the same.
However, the real question remains: Is this method more secure than traditional passwords?
We find that if an attacker gains access to a user's mobile phone, then they inevitably gain access to the account. So if you lose your mobile phone and it has an indication of your Yahoo username , then congratulations, you just clicked it!
At the same time, text messages themselves can become carriers of mobile malware. Usually for extortion and money extortion and other times for outright theft of bank accounts.
This authentication process can also be used (and abused) for various purposes, such as if you lose your phone and using the location setting and Yahoo to locate the device. Similarly, the process can be used to spam or harass someone who has their phone connected to Yahoo.
In conclusion, is it more convenient to use this method? Absolutely. But is it also more secure? The answer is: not at all. In case you have decided to use this procedure, make sure that you will not forget your mobile phone more often than you forget your passwords and of course, do not forget to strengthen the protection of your phone in any way provided to you (e.g. lock screen, password, etc.) so that it remains as safe as possible in case it is lost.

