AT&T, Sprint, T-Mobile, and Verizon form Mobile Authentication Taskforce to create new open standard and fix security flaws present in current SMS-based 2FA
Context & Ripple Effects
The taskforce lands two months after The Verge documented how fragmented and attack-prone two-factor authentication had become, with SMS and email recovery methods left open to determined hackers. All four national carriers — AT&T, Sprint, T-Mobile, and Verizon — now commit jointly to an open standard, which matters because SMS codes ride on their networks and they are the only players positioned to replace them at the source.
First-order effects
- The four carriers take direct ownership of a flaw in their own product: SMS-based 2FA, which they deliver and profit from, is officially deemed insecure enough to require a joint replacement standard.
- Web services and banks relying on SMS codes gain a roadmap for migrating to carrier-backed authentication instead of building their own fixes.
Second-order effects
- The joint structure becomes a template for cross-carrier security work — by 2018 the same four carriers detail Project Verify, authenticating users to websites via data unique to their phone and subscriber account, and by 2019 AT&T and T-Mobile extend the model to cross-network call authentication against spoofed robocalls.
- An open standard pressures any carrier or messaging platform still treating SMS delivery as a neutral pipe, since the networks themselves are now asserting a security role over traffic they carry.
Third-order effects
- If the pattern holds, US carriers evolve from bit pipes into de facto identity providers, with phone-subscriber data as the credential layer for web login — a structural shift in who vouches for who you are online.
- That shift only holds if the carriers close their own gaps: researchers later found AT&T, T-Mobile, and Verizon support procedures exposed customers to SIM swapping attacks, meaning the network-level identity layer inherits whatever weaknesses remain in account-recovery processes.
The trend: US carriers are consolidating authentication into a shared network-layer standard, moving identity verification away from SMS codes and toward phone-subscriber credentials.