AT&T, Sprint, T-Mobile, and Verizon form Mobile Authentication Taskforce to create new open standard and fix security flaws present in current SMS-based 2FA
Two-factor authentication (2FA) via SMS and a smartphone provides a heavy dose of additional security for your data …
Context & Ripple Effects
Two months after The Verge documented how fragmented and attack-prone two-factor implementations had become — with SMS and email recovery both exploitable by determined hackers (two-factor authentication is a mess) — the four major US carriers responded collectively rather than individually. The Mobile Authentication Taskforce puts AT&T, Sprint, T-Mobile, and Verizon behind one open standard, an unusual act of cooperation among rivals who otherwise compete for the same subscribers.
The move matters because the carriers sit on data no app developer has: the phone number, SIM, and subscriber account itself. A carrier-built standard would let services verify users against that substrate instead of shipping one-time codes over SMS, the channel whose flaws prompted the taskforce in the first place.
First-order effects
- SMS-based 2FA — the default second factor for most consumer accounts — now has a coordinated replacement effort backed by all four national carriers, shifting the fix from individual sites' workarounds to a shared standard.
- The four carriers commit engineering resources to a joint body, meaning their subscriber-identity infrastructure becomes a product surface rather than back-office plumbing.
Second-order effects
- The taskforce's work surfaces as Project Verify, where web sites authenticate users directly against phone and mobile-subscriber data — turning carrier identity into a credential that competes with SMS codes and third-party authenticator apps.
- Sites currently paying for or operating their own 2FA delivery gain a carrier-side alternative, pressuring SMS-gateway vendors and pushing authentication toward whoever controls the SIM.
Third-order effects
- The pattern points to carriers consolidating identity verification as a line of business layered on subscriber data — but the 2020 finding that these same carriers' customer-support procedures remained exposed to SIM swapping attacks shows a network-layer standard does not close the human-process gap attackers actually exploit.
- If the open-standard model holds, authentication authority migrates from individual websites and app makers toward the carriers collectively, raising the usual questions about a handful of companies controlling a universal login layer.
The trend: US carriers are converting their control of subscriber identity into an authentication business, moving from patching SMS-based 2FA to offering phone-verified login as a platform.