Two-factor authentication is a mess, as companies offer various implementations, with SMS and email account recovery methods vulnerable to determined hackers
Russell Brandom / The Verge :
Context & Ripple Effects
This Verge explainer lands in the middle of a slow-motion reckoning over SMS-based login: Snapchat had already added two-factor authentication back in 2015, but the method most services adopted — codes sent by text or email — is exactly what Brandom flags as the weak link. Within months of publication, AT&T, Sprint, T-Mobile, and Verizon responded by forming a Mobile Authentication Taskforce to build an open standard replacing flawed SMS 2FA.
The years after proved the critique prescient rather than alarmist: Instagram committed to a non-SMS two-factor system built on apps like Google Authenticator and Duo specifically to thwart SIM hijackers, while reporting showed the attack side industrializing — a hacker paid Sakari just $16 to reroute a reporter's texts (the Sakari text-rerouting incident) and a market of bots that steal 2FA codes via SMS services like Twilio emerged targeting Coinbase, Amazon, PayPal, and banks.
First-order effects
- Users whose accounts depend on SMS or email recovery — the default at most major services named in the coverage, from Snapchat-era adopters to Coinbase and PayPal customers — are exposed right now to attackers who can intercept texts or reset email.
- Carriers face immediate pressure: the taskforce formed by AT&T, Sprint, T-Mobile, and Verizon exists because their own SMS infrastructure is the vulnerability being exploited.
Second-order effects
- Consumer platforms are forced to rebuild authentication around authenticator apps — Instagram's Google Authenticator/Duo integration is the template other social networks must match or explain why they haven't.
- A criminal supply chain forms around the weakness: resellers like Sakari and Twilio-adjacent tooling let low-budget attackers buy text interception, turning SIM hijacking from a bespoke skill into a commodity service.
Third-order effects
- If the pattern holds, SMS 2FA gets deprecated as a security control and demoted to a fallback, with app-based tokens becoming the baseline expectation for consumer accounts — and pressure builds for regulation of bulk SMS rerouting tools, as the Sakari case showed.
- Authentication consolidates around whoever controls the second factor — phone carriers via their standard-setting taskforce versus platform-owned authenticator apps — making identity infrastructure a competitive layer rather than a solved checkbox.
The trend: Two-factor authentication is migrating off SMS toward app-based verification as text-message interception becomes cheap enough to industrialize.