{"id":1639,"date":"2016-05-16T17:37:57","date_gmt":"2016-05-16T14:37:57","guid":{"rendered":"https:\/\/www.protectimus.com\/blog\/?p=1639"},"modified":"2019-06-10T16:30:56","modified_gmt":"2019-06-10T13:30:56","slug":"sms-verification-is-vulnerable","status":"publish","type":"post","link":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/","title":{"rendered":"Dutch Scientists: SMS Verification Is Vulnerable"},"content":{"rendered":"<p>Computer security experts in their confrontation with the hackers are always trying to work ahead of the curve: to model and foresee probable &#8220;loopholes&#8221; in the data protection systems of different services and operating systems. In recent years, special attention has been paid to the mobile operating systems as more and more people use smartphones to enter their accounts or use them as 2-step verification means. Most often, users get 2-step verification codes (one-time passwords) via SMS. Sometimes, OTP passwords are also delivered via voice messages or generated with the help of a special application &#8211; mobile one-time password generator. But in this article, we will discuss the most popular OTP delivery method &#8211; SMS verification.<\/p>\n<p>Unfortunately, SMS verification cannot provide a proper level of reliability. First of all, mobile networks use open, unencrypted communication channels where any data protection is almost impossible. It is not difficult for a person who has the necessary technical skills and equipment to get connected to such a network. But, according to the <a href=\"http:\/\/fc16.ifca.ai\/preproceedings\/24_Konoth.pdf\">researchers<\/a> of <em>the Free University of Amsterdam<\/em>, even this is not so important: they have found another critical vulnerability of the SMS-based authentication.<\/p>\n<h2>What is the problem with SMS verification<\/h2>\n<p>Usually, a hacker needs\u00a0two\u00a0conditions for carrying out two-factor verification on behalf of his victim: a victim&#8217;s computer must be infected with the Trojan virus and the hacker should know the static password, which is the first factor of 2-step verification. But the Dutch researchers have found how to intercept the SMS tokens on the mobile devices with <em>Android<\/em> and <em>iOS<\/em> operating systems without having a permanent account password.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4713 size-full\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability-2.jpg\" alt=\"SMS verification on Android is vulnerable to attacks\" width=\"1442\" height=\"610\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability-2.jpg 1442w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability-2-300x127.jpg 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability-2-768x325.jpg 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability-2-1024x433.jpg 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability-2-610x258.jpg 610w\" sizes=\"auto, (max-width: 1442px) 100vw, 1442px\" \/><\/p>\n<p>The source of trouble lies in the possibility to synchronize your smartphone and computer. Once invented for convenience, this <em>Apple<\/em> and <em>Google<\/em> provided function now can endanger the user&#8217;s data protection. Moreover, although earlier the <em>Android<\/em> operating system was considered the most vulnerable, the present study showed that the vaunted <em>iOS<\/em> is even easier to hack.<\/p>\n<p>In both cases, the only thing the hacker needs to bypass the SMS-based authentication is to have a victim\u2019s computer infected with the Trojan virus. Usually, it is not difficult to install it: there have already been precedents when the spyware in the guise of the useful programs penetrated to the official app stores. And yes, we shouldn\u2019t forget about <a href=\"https:\/\/www.protectimus.com\/blog\/what-is-phishing-and-how-not-to-fall-into-its-nets\/\">phishing<\/a>, which, despite many warnings, keeps working.<\/p>\n<p>Further events are developing in different ways depending on the operating system &#8211; <em>Android<\/em> or <em>iOS<\/em>.<\/p>\n<p>In the <em>Android<\/em> case, the Trojan virus, disguised as the account holder, asks to download a spyware application on your smartphone, connected to the account. Once the malware is installed, it does not manifest itself and waits for an SMS with the OTP password. Then the one-time password is sent to the fraudsters\u2019 server even before the real account holder enters the OTP.<\/p>\n<p>&#8220;Working&#8221; with <em>OS X<\/em> and <em>iOS<\/em> is even easier for the Trojan virus. The latest versions of these operating systems have a feature allowing to read iMessages right from the computer. All incoming messages are placed in a separate file on the computer&#8217;s hard drive. The virus only needs to monitor the content in anticipation of the &#8220;H-hour.&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4714 size-full\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS_1-2.jpg\" alt=\"SMS verification on iOS is vulnerable to attacks\" width=\"1444\" height=\"498\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS_1-2.jpg 1444w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS_1-2-300x103.jpg 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS_1-2-768x265.jpg 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS_1-2-1024x353.jpg 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS_1-2-610x210.jpg 610w\" sizes=\"auto, (max-width: 1444px) 100vw, 1444px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4715 size-full\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS-2.jpg\" alt=\"SMS verification on iOS is vulnerable to attacks\" width=\"1443\" height=\"514\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS-2.jpg 1443w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS-2-300x107.jpg 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS-2-768x274.jpg 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS-2-1024x365.jpg 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/SMS_authentication_vulnarability_iOS-2-610x217.jpg 610w\" sizes=\"auto, (max-width: 1443px) 100vw, 1443px\" \/><\/p>\n<h2>Possible Solution<\/h2>\n<p>If the SMS verification can be compromised, what can help you to avoid this threat? Currently, the most obvious solution is hardware OTP token as it can provide the proper security level of the two-factor authentication.<\/p>\n<p>Hardware tokens are the most secure OTP tokens of <a href=\"https:\/\/www.protectimus.com\/blog\/otp-generation-algorithms-and-token-types\/\">all the types<\/a>. This one-time password generator works free of the Internet or GSM network. Moreover, modern hardware tokens can be further protected with the PIN-codes.<\/p>\n<p>When it comes to the usability of tokens, two-factor authentication providers &#8211; such as Protectimus &#8211; do everything to ensure it to the maximum. Generally, OTP tokens are small and their batteries last for 5 years. Hardware tokens can be made in the form of the key fobs (e.g., <strong>Protectimus Ultra<\/strong> and <strong>One<\/strong>) or credit cards (<strong>Protectimus Slim<\/strong> and <strong>Protectimus Slim Mini<\/strong>).<\/p>\n<p>By the way, our new hardware token smart card <a href=\"https:\/\/www.protectimus.com\/blog\/protectimus-new-otp-tokens\/\">Protectimus Slim Mini<\/a> is not only twice smaller than a standard credit card, but it also reprogrammable, supports NFC technology, and allows you to change the lifetime of the OTP password that also increases security.<\/p>\n<p>There are a lot of different authentication methods. But practice shows that one-time password generation with the help of the hardware tokens is the best means to compensate for existing vulnerabilities in 2-step verification.<\/p>\n<span class=\"et_bloom_bottom_trigger\"><\/span>","protected":false},"excerpt":{"rendered":"<p>Computer security experts in their confrontation with the hackers are always trying to work ahead of the curve: to model and foresee probable &#8220;loopholes&#8221; in the data protection systems of different services and operating systems. In recent years, special attention has been paid to the mobile operating systems as more and more people use smartphones [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":4376,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[7],"tags":[16,120,10,130,99],"class_list":["post-1639","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-2fa","tag-multifactor-authentication","tag-otp","tag-sms-authentication","tag-two-factor-authentication"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Anna\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Protectimus ltd\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus\" \/>\n\t\t<meta property=\"og:description\" content=\"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1900\" \/>\n\t\t<meta property=\"og:image:height\" content=\"689\" \/>\n\t\t<meta property=\"article:section\" content=\"Industry News\" \/>\n\t\t<meta property=\"article:tag\" content=\"2fa\" \/>\n\t\t<meta property=\"article:tag\" content=\"multifactor authentication\" \/>\n\t\t<meta property=\"article:tag\" content=\"otp\" \/>\n\t\t<meta property=\"article:tag\" content=\"sms authentication\" \/>\n\t\t<meta property=\"article:tag\" content=\"two-factor authentication\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2016-05-16T14:37:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-06-10T13:30:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/protectimus\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@protectimus\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@protectimus\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"Anna\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#article\",\"name\":\"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus\",\"headline\":\"Dutch Scientists: SMS Verification Is Vulnerable\",\"author\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/author\\\/ann\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/wp-content\\\/uploads\\\/2016\\\/05\\\/sms-authentication-2.jpg\",\"width\":1900,\"height\":689,\"caption\":\"SMS authentication vulnarability\"},\"datePublished\":\"2016-05-16T17:37:57+03:00\",\"dateModified\":\"2019-06-10T16:30:56+03:00\",\"inLanguage\":\"en-GB\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#webpage\"},\"articleSection\":\"Industry News, 2FA, multifactor authentication, OTP, SMS authentication, two-factor authentication, English, pll_5739d94d01c6b\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.protectimus.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/category\\\/industry-news\\\/#listItem\",\"name\":\"Industry News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/category\\\/industry-news\\\/#listItem\",\"position\":2,\"name\":\"Industry News\",\"item\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/category\\\/industry-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#listItem\",\"name\":\"Dutch Scientists: SMS Verification Is Vulnerable\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#listItem\",\"position\":3,\"name\":\"Dutch Scientists: SMS Verification Is Vulnerable\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/category\\\/industry-news\\\/#listItem\",\"name\":\"Industry News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/#organization\",\"name\":\"Protectimus\",\"description\":\"Blog Company\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/\",\"telephone\":\"+35319014565\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/protectimus\",\"https:\\\/\\\/twitter.com\\\/protectimus\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCwhXKBLAQfXca6bBWKjj27g\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/protectimus-solution-ltd\\\/mycompany\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/author\\\/ann\\\/#author\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/author\\\/ann\\\/\",\"name\":\"Anna\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d39b4328d187c831d5ebe5986dd92c9abc337b45adca23fcab04e0a0d0e0adc?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Anna\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#webpage\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/\",\"name\":\"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus\",\"description\":\"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\\u2019s computer with the Trojan virus.\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/author\\\/ann\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/author\\\/ann\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/wp-content\\\/uploads\\\/2016\\\/05\\\/sms-authentication-2.jpg\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#mainImage\",\"width\":1900,\"height\":689,\"caption\":\"SMS authentication vulnarability\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/sms-verification-is-vulnerable\\\/#mainImage\"},\"datePublished\":\"2016-05-16T17:37:57+03:00\",\"dateModified\":\"2019-06-10T16:30:56+03:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/\",\"name\":\"Protectimus Limited\",\"description\":\"Blog Company\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Dutch Scientists: SMS Verification Is Vulnerable - Protectimus<\/title>\n\n","aioseo_head_json":{"title":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","description":"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.","canonical_url":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#article","name":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","headline":"Dutch Scientists: SMS Verification Is Vulnerable","author":{"@id":"https:\/\/www.protectimus.com\/blog\/author\/ann\/#author"},"publisher":{"@id":"https:\/\/www.protectimus.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg","width":1900,"height":689,"caption":"SMS authentication vulnarability"},"datePublished":"2016-05-16T17:37:57+03:00","dateModified":"2019-06-10T16:30:56+03:00","inLanguage":"en-GB","mainEntityOfPage":{"@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#webpage"},"isPartOf":{"@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#webpage"},"articleSection":"Industry News, 2FA, multifactor authentication, OTP, SMS authentication, two-factor authentication, English, pll_5739d94d01c6b"},{"@type":"BreadcrumbList","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.protectimus.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog\/category\/industry-news\/#listItem","name":"Industry News"}},{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog\/category\/industry-news\/#listItem","position":2,"name":"Industry News","item":"https:\/\/www.protectimus.com\/blog\/category\/industry-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#listItem","name":"Dutch Scientists: SMS Verification Is Vulnerable"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#listItem","position":3,"name":"Dutch Scientists: SMS Verification Is Vulnerable","previousItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/blog\/category\/industry-news\/#listItem","name":"Industry News"}}]},{"@type":"Organization","@id":"https:\/\/www.protectimus.com\/blog\/#organization","name":"Protectimus","description":"Blog Company","url":"https:\/\/www.protectimus.com\/blog\/","telephone":"+35319014565","sameAs":["https:\/\/www.facebook.com\/protectimus","https:\/\/twitter.com\/protectimus","https:\/\/www.youtube.com\/channel\/UCwhXKBLAQfXca6bBWKjj27g","https:\/\/www.linkedin.com\/company\/protectimus-solution-ltd\/mycompany\/"]},{"@type":"Person","@id":"https:\/\/www.protectimus.com\/blog\/author\/ann\/#author","url":"https:\/\/www.protectimus.com\/blog\/author\/ann\/","name":"Anna","image":{"@type":"ImageObject","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/9d39b4328d187c831d5ebe5986dd92c9abc337b45adca23fcab04e0a0d0e0adc?s=96&d=mm&r=g","width":96,"height":96,"caption":"Anna"}},{"@type":"WebPage","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#webpage","url":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/","name":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","description":"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.","inLanguage":"en-GB","isPartOf":{"@id":"https:\/\/www.protectimus.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#breadcrumblist"},"author":{"@id":"https:\/\/www.protectimus.com\/blog\/author\/ann\/#author"},"creator":{"@id":"https:\/\/www.protectimus.com\/blog\/author\/ann\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg","@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#mainImage","width":1900,"height":689,"caption":"SMS authentication vulnarability"},"primaryImageOfPage":{"@id":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/#mainImage"},"datePublished":"2016-05-16T17:37:57+03:00","dateModified":"2019-06-10T16:30:56+03:00"},{"@type":"WebSite","@id":"https:\/\/www.protectimus.com\/blog\/#website","url":"https:\/\/www.protectimus.com\/blog\/","name":"Protectimus Limited","description":"Blog Company","inLanguage":"en-GB","publisher":{"@id":"https:\/\/www.protectimus.com\/blog\/#organization"}}]},"og:locale":"en_GB","og:site_name":"Protectimus ltd","og:type":"article","og:title":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","og:description":"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.","og:url":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/","og:image":"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg","og:image:secure_url":"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg","og:image:width":1900,"og:image:height":689,"article:section":"Industry News","article:tag":["2fa","multifactor authentication","otp","sms authentication","two-factor authentication"],"article:published_time":"2016-05-16T14:37:57+00:00","article:modified_time":"2019-06-10T13:30:56+00:00","article:publisher":"https:\/\/www.facebook.com\/protectimus","twitter:card":"summary","twitter:site":"@protectimus","twitter:title":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","twitter:description":"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.","twitter:creator":"@protectimus","twitter:image":"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2016\/05\/sms-authentication-2.jpg","twitter:label1":"Written by","twitter:data1":"Anna","twitter:label2":"Est. reading time","twitter:data2":"4 minutes"},"aioseo_meta_data":{"post_id":"1639","title":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","description":"The Dutch researchers found a vulnerability in SMS verification. To bypass 2FA the hacker needs only to infect the victim\u2019s computer with the Trojan virus.","keywords":null,"keyphrases":{"focus":{"keyphrase":"SMS verification"}},"primary_term":{"category":7},"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":"Industry News","og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":"Dutch Scientists: SMS Verification Is Vulnerable - Protectimus","twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-06-23 23:40:12","breadcrumb_settings":null,"limit_modified_date":false,"open_ai":null,"ai":null,"created":"2022-09-01 13:52:40","updated":"2026-06-23 23:40:12"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.protectimus.com\/blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.protectimus.com\/blog\/category\/industry-news\/\" title=\"Industry News\">Industry News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tDutch Scientists: SMS Verification Is Vulnerable\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.protectimus.com\/blog"},{"label":"Industry News","link":"https:\/\/www.protectimus.com\/blog\/category\/industry-news\/"},{"label":"Dutch Scientists: SMS Verification Is Vulnerable","link":"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/"}],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/1639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/comments?post=1639"}],"version-history":[{"count":10,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/1639\/revisions"}],"predecessor-version":[{"id":4716,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/1639\/revisions\/4716"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/media\/4376"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/media?parent=1639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/categories?post=1639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/tags?post=1639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}