{"id":4134,"date":"2016-07-28T15:23:08","date_gmt":"2016-07-28T09:53:08","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=4134"},"modified":"2016-07-28T15:23:08","modified_gmt":"2016-07-28T09:53:08","slug":"nist-recommends-sms-two-factor-authentication-deprecation","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/nist-recommends-sms-two-factor-authentication-deprecation\/","title":{"rendered":"NIST Recommends SMS Two-Factor Authentication Deprecation"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/ift.tt\/2abOYa5\" title=\"NIST Recommends SMS Two-Factor Authentication Deprecation | Threatpost | The first stop for security news\"><\/p>\n<div>\n<div class=\"entry-content\">\n<p>A U.S. government agency said\u00a0the end is nigh for SMS-based two-factor authentication, citing a\u00a0lack of security around the feature.<\/p>\n<p>The latest\u00a0draft version of the <a href=\"https:\/\/ift.tt\/28QyQsR\">Digital Authentication Guideline<\/a> issued this week by the U.S. National Institute for Standards and Technology (NIST) said the practice would soon be discouraged.<\/p>\n<div class=\"related-posts-inner\">\n<h3>Related Posts<\/h3>\n<article id=\"post-118814\" class=\"secondary-post  post-118814 post type-post status-publish format-standard has-post-thumbnail hentry category-mobile-security category-web-security tag-2-step-verification tag-authentication tag-credentials tag-google tag-google-security tag-password-dump tag-password-hacks tag-password-reuse tag-passwords tag-two-factor-authentication\">\n<p class=\"post-info\">\n\t\t\t\t\t\t\t<span class=\"date\">June 21, 2016 , 4:26 pm<\/span>\n\t\t\t\t\t\t<\/p>\n<\/article>\n<article id=\"post-118498\" class=\"secondary-post  post-118498 post type-post status-publish format-standard has-post-thumbnail hentry category-web-security tag-anish-athalye tag-ari-juels tag-authentication tag-autocorrect tag-common-password-errors tag-cornell-university tag-devdatta-akhawe tag-dropbox-1 tag-mit tag-passwords tag-rahul-chatterjee tag-relaxed-checker tag-thomas-ristenpart tag-typo-tolerant-password-checker tag-typos\">\n<p class=\"post-info\">\n\t\t\t\t\t\t\t<span class=\"date\">June 6, 2016 , 2:15 pm<\/span>\n\t\t\t\t\t\t<\/p>\n<\/article>\n<article id=\"post-117787\" class=\"secondary-post last post-117787 post type-post status-publish format-standard has-post-thumbnail hentry category-mobile-security category-vulnerabilities tag-account-hijacking tag-antifraud-system tag-authentication tag-call-hijacking tag-freedompop tag-halifax-uk-bank tag-mobile-security-2 tag-paul-moore tag-sms-hijacking\">\n<p class=\"post-info\">\n\t\t\t\t\t\t\t<span class=\"date\">May 3, 2016 , 11:36 am<\/span>\n\t\t\t\t\t\t<\/p>\n<\/article><\/div>\n<p>The Digital Authentication Guideline sets the rules that all authentication software eventually follows.<\/p>\n<p>Acknowledging there\u2019s a\u00a0risk that\u00a0SMS messages can be intercepted or redirected, NIST is encouraging any service considering adopting two-factor authentication in the future to\u00a0\u201cconsider alternative authenticators.\u201d<\/p>\n<p>In the document, NIST claims that services need to verify the phone number it sends codes to belongs to a legitimate network and not a VoIP service, before stating\u00a0the method may be discouraged in future releases.<\/p>\n<blockquote>\n<p>\u201cIf the out of band verification is to be made using a SMS message on a public mobile telephone network, the verifier SHALL verify that the pre-registered telephone number being used is actually associated with a mobile network and not with a VoIP (or other software-based) service.\u201d<\/p>\n<\/blockquote>\n<p>\u201cChanging the pre-registered telephone number SHALL NOT be possible without two-factor authentication at the time of the change. OOB using SMS is deprecated, and may no longer be allowed in future releases of this guidance,\u201d the document reads.<\/p>\n<p>The document does support biometrics, at least in limited use, for authentication. As long as biometrics is used alongside another authentication factor, it\u2019s permissible, NIST claims. Biometric authentication on its own can have false match rates, can be spoofed, and \u201cdo not provide confidence in the authentication of the subscriber by themselves.\u201d<\/p>\n<p>NIST has stressed the document is a public preview, meaning the processes aren\u2019t in play yet and are still subject to comment. NIST will seek comments for roughly two weeks and follow it up by a 2-3 week period for editors to review those comments.<\/p>\n<p>The agency is seeking comment on SP 800-63-3 via GitHub. While the platform may seem like an unorthodox choice, NIST said\u00a0it considers the site a robust forum for drafting the document and is encouraging substantive technical and procedural comments. NIST first called on the public to help the agency map out the guideline when it previewed it on GitHub initially,<a href=\"https:\/\/ift.tt\/2aqCnN9\">\u00a0in May<\/a>.<\/p>\n<p>Several services have already begun moving away from\u00a0two-factor authentication.\u00a0Facebook\u00a0uses something called Code Generator as part of its login approvals feature. When a user turns it on, they\u2019re asked for a special security code, which changes every thirty seconds, upon logging in.\u00a0Google has a similar function, Google Authenticator, that supplies users with\u00a0a six- to eight-digit one-time password. Companies such as\u00a0Authy and Duo specialize in solutions as well.<\/p>\n<p>Two-factor authentication has become almost ubiquitous over the last several years. The functionality, which allows services to send users a code to enter, along with a password, as an added layer of security has been adopted across multiple industries. Companies such as\u00a0<a href=\"https:\/\/ift.tt\/2abOy3E\">Apple<\/a>, <a href=\"https:\/\/ift.tt\/2aqCg4k\">Dropbox<\/a>, <a href=\"https:\/\/ift.tt\/2abOAbM\">Snapchat<\/a>, <a href=\"https:\/\/ift.tt\/2aqCisS\">Evernote<\/a>, and <a href=\"https:\/\/ift.tt\/2abOCA7\">Twitter<\/a> have adopted two-factor authentication to combat account takeovers and compromises.<\/p>\n<p>Still, 2FA is no silver bullet; attackers and researchers alike have poked\u00a0holes in the method, mainly via man in the middle attacks.\u00a0<a href=\"https:\/\/ift.tt\/2aqBVOL\">Two years<\/a> ago, researchers from Duo\u00a0found a way to bypass the mechanism used in\u00a0PayPal and transfer money from a victim\u2019s account to any recipient they chose. Vulnerabilities have also surfaced in plugins offered by <a href=\"https:\/\/ift.tt\/2abODEd\">WordPress<\/a>, <a href=\"https:\/\/ift.tt\/2aqCjNf\">Google<\/a>, and <a href=\"https:\/\/ift.tt\/1XFlOzn\">Instagram<\/a> that enabled hackers to bypass two-factor authentication.<\/p>\n<\/div><\/div>\n<p>via https:\/\/ift.tt\/29ZUTxz<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A U.S. government agency said\u00a0the end is nigh for SMS-based two-factor authentication, citing a\u00a0lack of security around the feature. The latest\u00a0draft version of the Digital Authentication Guideline issued this week by the U.S. National Institute for Standards and Technology (NIST) said the practice would soon be discouraged. Related Posts June 21, 2016 , 4:26 pm &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/nist-recommends-sms-two-factor-authentication-deprecation\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NIST Recommends SMS Two-Factor Authentication Deprecation&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12],"tags":[],"class_list":["post-4134","post","type-post","status-publish","format-standard","hentry","category-itsec"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-14G","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=4134"}],"version-history":[{"count":1,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4134\/revisions"}],"predecessor-version":[{"id":4135,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4134\/revisions\/4135"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=4134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=4134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=4134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}