Facebook's instant verification still relies on insecure SMS authentication
Full article507 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Facebook's instant verification is potentially a significant user experience step forward. But it still falls back on SMS verification, which is widely seen as insecure and worth leaving behind.
Facebook is attempting to reduce reliance its on SMS authentication for Account Kit, the ubiquitous account creation tool that lets you log into different apps using your account with the social media giant.
Instead of automatically sending a one-time password to verify a user, Facebook checks via instant verification if the user has the main Facebook app installed on that same device. If the phone numbers match, the sign in with the new app progresses. If not, the process reverts to SMS.
The stated goal is to make the entire sign-in process smoother. Mission accomplished on that front; no one wants to have to copy SMS codes, especially if phone service is spotty. Non-Facebook apps like Familonet, which shares physical locations between family members, reported an increased conversion rate after turning to Account Kit.
https://www.youtube.com/watch?v=b1nuhRfAFjw
SMS authentication, however, is relatively insecure. It can be spoofed, phished and surveilled. The National Institute of Standards and Technology warned public and private sector techies against using SMS authentication, but it remains in heavy use. Alternatives like Google’s Authenticator app are rising in popularity and authentication hardware like YubiKey saw increased sales in 2016. Twitter, the other social media behemoth, tried last week to enable more secure app authentication but made it impossible to disable password reset via SMS.
Instant verification is not being marketed by Facebook as a security boon but, somehow, it is being lauded on social media that way. In fact, it’s probably a neat little user experience boost. But SMS is still inextricably involved in Facebook’s instant verification, leaving a notable hole for anyone with a mind toward cybersecurity.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/facebook-instant-verification-sms-authentication/