Four major US carriers detail “Project Verify” for letting web sites authenticate users via data unique to a customer's phone and mobile subscriber account
The four major U.S. wireless carriers today detailed a new initiative that may soon let Web sites eschew passwords …
Context & Ripple Effects
Project Verify is the first concrete output of the Mobile Authentication Taskforce that AT&T, Sprint, T-Mobile, and Verizon formed in 2017 explicitly to replace SMS-based two-factor authentication with an open standard built on data unique to a customer's phone and subscriber account. If it works, the carriers stop being pipes and start being identity providers for the web.
The catch is that the same subscriber-account plumbing is the attack surface researchers keep flagging: US carriers were still dragging their feet on sharing real-time SIM swap data with banks in 2019, and a 2020 audit found vulnerable customer-support procedures at several of these same carriers that enable SIM swapping.
First-order effects
- Web sites gain a passwordless login option anchored in carrier-held subscriber data, and the four carriers acquire a new revenue-relevant role as gatekeepers of web identity.
Second-order effects
- Platform vendors pushing their own credentials — Google's passkey rollout on Android and Chrome being the visible example — now compete head-to-head with carrier-anchored authentication for the same login moment.
- Every SIM swap fraud incident at these carriers becomes a direct strike against Project Verify's credibility, since the scheme authenticates against exactly the accounts attackers hijack; carriers face pressure to ship protections like the Account Lock features AT&T, T-Mobile, Verizon, and Google Fi eventually rolled out.
Third-order effects
- If the pattern holds, web authentication consolidates around two rival trust anchors — the carrier's subscriber record versus the device vendor's cryptographic key — and whichever proves harder to socially engineer wins the passwordless era; the carriers' documented SIM-swap weaknesses are the open question deciding that contest.
The trend: Authentication is migrating from passwords and SMS codes toward stronger proofs of identity, with carriers and platform vendors racing to own the trust layer underneath.