Sunday, February 23, 2025

Exclusive: Google Confirms Gmail To Ditch SMS Code Authentication

Must read

It is certainly no secret that using SMS text messages for security codes used to authenticate your identity is far from ideal. Just as the tech industry is slowly moving away from passwords to passkeys that take a more secure biometric approach to logins, the use of code-generating apps and even app-less approaches to two-factor authentication have increasingly become the norm in recent years. But SMS has always been said to be better than no authentication at all, which is hard to argue with. Now, following a privileged conversation with Google insiders, I can exclusively reveal that Gmail is finally looking to ditch SMS codes for authentication. Here’s everything you need to know.

Forbes3.9 Billion Passwords Stolen—What You Need To Know

Gmail Spokesperson: “We Want To Move Away From Sending SMS Messages For Authentication”

“Just like we want to move past passwords with the use of things like passkeys,” Gmail spokesperson Ross Richendrfer told me, “we want to move away from sending SMS messages for authentication.” So began an email conversation with Google that revealed, for the first time, SMS codes are to be ditched when it comes to authentication and replaced with QR codes to “reduce the impact of rampant, global SMS abuse.”

Google currently uses SMS verification primarily for two distinct purposes: security and abuse control. The former, Richendrfer explained, is to verify “that we’re dealing with the same user as before,” while the latter ensures fraudsters don’t abuse Google’s services. An example of this, as provided by Google, was when criminals create thousands of Gmail accounts in order to distribute spam and malware.

ForbesCritical New PayPal Warning: Genuine Emails Used In Ongoing Attack

Why Gmail Is Getting Rid Of SMS Codes

SMS codes present numerous security challenges, according to Richendrfer and his colleague at Google, Kimberly Samra. They can be phished, people don’t always have access to the device the codes are sent to, and they are reliant on the security practices of the user’s carrier. “If a fraudster can easily trick a carrier into getting hold of someone’s phone number,” Richendrfer said, any “security value of SMS goes away.”

Then there’s the fact that SMS verification codes are also often at the very heart of many criminal operations. One relatively new scam that Google has observed across the last couple of years is what it refers to as traffic pumping. I’ve also heard this called artificial traffic inflation and toll fraud, but the methodology is always the same. Over to Richendrfer and Samra to explain: “It’s where fraudsters try to get online service providers to originate large numbers of SMS messages to numbers they control, thereby getting paid every time one of these messages is delivered.”

ForbesAmazon Prime Security Warning: Beware This 4-Step Hack Attack

From SMS To QR Codes For Gmail Authentication

“Over the next few months, we will be reimagining how we verify phone numbers,” Richendrfer told me; “Specifically, instead of entering your number and receiving a 6-digit code, you’ll see a QR code being displayed, which you need to scan with the camera app on your phone.”

I’m not the world’s greatest fan of QR codes as many of my articles can attest to, but this remains a momentous security moment for Google and Gmail users.

The benefits that QR codes for authentication can offer are twofold, according to Google:

  1. Reducing the phishing risk of Gmail users being tricked into sharing their security codes with a threat actor. Primarily, and rather obviously, since there’s no such code to share in the first place.
  2. Removing reliance, in most cases at least, of Google users on their phone carrier for anti-abuse protections.

“SMS codes are a source of heightened risk for users,” Richendrfer concluded, “we’re pleased to introduce an innovative new approach to shrink the surface area for attackers and keep users safer from malicious activity.” Signing off with an intriguing “look for more from us on this in the near future,” but without an actual date for implementing the changes for Google account holders and Gmail users, it’s something I’m sure we can all agree cannot come soon enough.

ForbesGoogle Confirms Enhanced Attack Protection For 1 Billion Chrome Users

Latest article