COMMENTARY

One-time passwords marked ‘Likely-SCAM’ could breed complacency

Yong Jun Yuan

Yong Jun Yuan

Published Mon, Feb 6, 2023 · 08:58 PM
    • Using SMSes is weak as an authentication factor, and users should be prepared to accept some inconveniences in exchange for stronger protections for their online accounts.
    • Using SMSes is weak as an authentication factor, and users should be prepared to accept some inconveniences in exchange for stronger protections for their online accounts. PHOTO: BT FILE

    THE recent rollout of an SMS scam prevention initiative has hit some snags, with legitimate messages being marked as likely scams.

    At best, these temporary problems will be ironed out; and the public will enjoy several months of scam-free messages before new loopholes are found and exploited.

    At worst, the initiative could breed complacency. There is some urgency, therefore, to find better ways to communicate and to secure accounts against fraudulent use.

    Starting this month, all SMSes with alphanumeric sender names – meaning they have alphabets and not just numbers – will be labelled “Likely-SCAM” unless the sender has paid to be listed on the Singapore SMS Sender ID Registry.

    But verification issues have led to some SMSes – including legitimate one-time passwords (OTPs) sent using access management provider Okta – being marked as scams anyway.

    Okta and several other companies were forced last week to tell customers to ignore the scam categorisations for now.

    Yet, this is potentially confusing and dangerous.

    Payments provider EZ-Link, for instance, sent an email last Friday (Feb 3) informing customers that EZ-Link has registered and that customers should disregard any messages impersonating them with the “Likely-SCAM” tag.

    As users receive official-looking messages from companies, especially OTPs, they could eventually end up trusting “Likely-SCAM” messages instead.

    This issue may, of course, be temporary. The Infocomm Media Development Authority said some senders may have registered very close to or after Jan 31, and perhaps have not yet been verified. Once verification is complete, the number of messages tagged as likely scams should fall.

    From July, SMSes from unregistered entities using alphanumeric sender IDs will be blocked entirely. This means there should be no confusion among customers, and companies will be forced to register themselves.

    Yet, there is a chance that users will also turn complacent about SMSes they receive. It may not take long for scammers to figure out ways to get around the system.

    Security companies have advocated for the phasing out of SMS as a second factor for authentication instead.

    In a blog post published in May 2020, Okta senior product marketing manager Teju Shyamsundar recommended companies ditch SMS authentication. She noted the numerous ways SMS authentication can be compromised, some of them not particularly high-tech.

    Would-be thieves can impersonate anyone with enough information. A perpetrator can call your telco and request a new SIM card with your number. All your SMSes will then be sent to the perpetrator instead; and by the time you realise you have lost your network, the perpetrator could have wreaked havoc.

    In 2021, British police arrested eight perpetrators of these so-called “SIM swapping” attacks. The perpetrators had hijacked the social media profiles of US celebrities, and stole money and bitcoin.

    A better authentication practice is in-app prompts, which several banks and organisations already use.

    These in-app prompts are more secure because they are encrypted and sent through the company’s app. Unlike OTPs, they cannot be copied and given to others

    Users also need to unlock their phones before they can access these prompts, whereas SIM cards can be stolen and accessed much more easily.

    Still, even this method can be compromised.

    When users lose their devices and reset their accounts, companies may still fallback on SMS and emails to register a new device, rendering them vulnerable to similar attacks.

    One potential solution is for companies to require both SMS and email verification to reset passwords. Google’s solution has been to give users a list of “backup codes” to regain access. These can be printed and stored in a physical location, such as a safe.

    Companies should also give more thought to how they manage employee access. Employees could be disallowed from resetting their passwords without first meeting tech support, either in person or over a video call.

    Users should brace for some inconvenience. But they should bear in mind that if they have an easy time resetting their passwords and two-factor authentication, potential perpetrators would find it easy too.