• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

You’re Implementing This Basic Security Feature All Wrong

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
June 27, 2016, 7:27 PM ET
87th Annual Academy Awards - Arrivals
HOLLYWOOD, CA - FEBRUARY 22: Actress Reese Witherspoon attends the 87th Annual Academy Awards at Hollywood & Highland Center on February 22, 2015 in Hollywood, California. (Photo by Kevork Djansezian/Getty Images)Kevork Djansezian—Getty Images

You’ve created different passwords for all your online accounts and set up a password manager to remember them all. You’ve also changed your passwords after all the recent hackings and implemented two-factor authentication, a tool that provides extra protection against breaches by requiring a second login code that is sent to your smartphone, for example, each time you sign on.

Nice job! This is the closest thing to hacker-proof you’ve ever been, right?

Hold the phone—literally. Because that last measure—two factor authentication—may have several vulnerabilities. The flaws here have to do with the way many Internet companies send security codes to your phone as part of the two-factor authentication process, as Wired points out.

Texts, or SMS messages, are not the ideal way to convey such information. Attackers can compromise your text-based two-factor authentication in a few ways.

Get Data Sheet, Fortune’s technology newsletter.

First, they can do it through social engineering—in other words, by calling your mobile service provider and asking them to redirect messages normally delivered to your phone to one containing a different SIM card. You can help block this by calling your provider and asking to set up a PIN code on your account, where applicable.

Second, attackers can intercept messages using a device called an IMSI—or international mobile subscriber identity—catcher. The machines are not cheap, sure—but hey, maybe your enemies are well off?

And third, hackers can exploit weaknesses in the protocols that allow telecom carriers to exchange data between networks. That became clear earlier this year after 60 Minutes aired a segment on Signaling System 7, one such vulnerable protocol.

The good news: there are alternatives. Instead of using a two-factor process tied to your mobile device’s SMS, consider downloading and implementing a separate two-factor authentication app. These apps generate random numbers on your device—time-based one-time passwords—that are coupled with your online accounts. Examples include EMC-owned (EMC) RSA SecurID, or Google (GOOG) Authenticator.

For more security advice, watch:

Now I know what some of you are probably thinking: this level of security must just be for the paranoids. Well, maybe.

Security is a risk based decision. But if you would like to be proactive, go ahead and make the change where you’re able. In this humble reporter’s opinion, it’s worth staying ahead of the attack curve when possible. Because when the lions approach, you don’t want to be the straggler left sipping at the watering hole.

This isn’t just a theoretical weakness, after all. Black Lives Matter activist DeRay McKesson had his Twitter (TWTR) account taken over, apparently by a hacker who duped someone at Verizon (VZ) into authorizing a fraudulent SIM card. Political activists in Russia and Iran have had their Telegram accounts hijacked. Even Lorrie Cranor, chief technologist of the U.S. Federal Trade Commission, got scammed.

If you’re an online business, here’s the takeaway: offer your users a non-SMS two-step login method. Besides, you might be keeping privacy-conscious users—ones who don’t wish to part with their phone numbers—from protecting their accounts.

For the rest of the Internet’s denizens: if you haven’t set up two-factor authentication, do! Even in the absence of an app-based option, you still should. SMS-based two-factor authentication is better than nothing.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Graphic depicting a coin reads, Fortune Crypto: Facebook Crypto 2.0
CryptoCrypto Playbook
Facebook’s first crypto push set off a firestorm. This time around, its plans are met with a shrug
By Jeff John RobertsFebruary 27, 2026
48 minutes ago
jack dorsey
AILayoffs
Block CEO Jack Dorsey lays off nearly half of his staff because of AI and predicts most companies will make similar cuts in the next year
By Jake AngeloFebruary 27, 2026
2 hours ago
Anthropic CEO Dario Amodei.
AIAnthropic
The Pentagon brands Anthropic’s CEO a ‘liar’ with a ‘God-complex’ as deadline looms over AI use in weapons and surveillance
By Beatrice NolanFebruary 27, 2026
4 hours ago
lacks
LawLawsuit
The immortal life of Henrietta Lacks lawsuits gets a bit shorter with Novartis settlement
By Brian Witte and The Associated PressFebruary 27, 2026
4 hours ago
burger king
AIOpenAI
Burger King tests OpenAI-powered headsets that will track the friendliness of drive-through workers
By Dee-Ann Durbin and The Associated PressFebruary 27, 2026
6 hours ago
zuck
LawSocial Media
20-year-old claiming social media addiction in landmark trial says she was on it ‘all day long’ as a child. Meta brings up abusive environment
By Kaitlyn Huamani, Barbara Ortutay and The Associated PressFebruary 27, 2026
6 hours ago

Most Popular

placeholder alt text
Innovation
An MIT roboticist who cofounded bankrupt robot vacuum maker iRobot says Elon Musk’s vision of humanoid robot assistants is ‘pure fantasy thinking’
By Marco Quiroz-GutierrezFebruary 25, 2026
2 days ago
placeholder alt text
Success
Jeff Bezos says being lazy, not working hard, is the root of anxiety: ‘The stress goes away the second I take that first step’
By Sydney LakeFebruary 25, 2026
2 days ago
placeholder alt text
Economy
Trump claims America is ‘winning so much.’ The IMF agrees, adding that Trump’s trade policies are the only thing holding it back from even more
By Tristan BoveFebruary 26, 2026
1 day ago
placeholder alt text
Success
Gen Z Olympic champion Eileen Gu says she rewires her brain daily to be more successful—and multimillionaire founder Arianna Huffington says it really does work
By Orianna Rosa RoyleFebruary 25, 2026
2 days ago
placeholder alt text
Economy
It’s more than George Clooney moving to France: America is becoming the ‘uncool’ country that people want to move away from
By Nick LichtenbergFebruary 27, 2026
12 hours ago
placeholder alt text
AI
Jamie Dimon says society should start preparing for AI job displacement: ‘Now’s the time to start thinking about’ it
By Marco Quiroz-GutierrezFebruary 25, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.