By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Marketing In Asia
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
    Marketing
    This category deals with best news and updates on marketing and branding news and events.
    Show More
    Top News
    Jonathan_Reeve_Headshot
    Eagle Eye Reveals Impact of Loyalty Programs on APAC Retailers
    2 months ago
    moha Launches the Brand New Kesar Chandan Soap, a Masterpiece Crafted with the Finest Natural Ingredients
    moha Launches Kesar Chandan Soap: A Luxurious Blend of Saffron and Sandalwood
    4 months ago
    Ultifresh Setting the Gold Standard in Sustainable Fashion and Corporate Responsibility
    Ultifresh: Setting the Gold Standard in Sustainable Fashion and Corporate Responsibility
    4 months ago
    Latest News
    Are coworking spaces the best way to keep up the next generation of Malaysian workers engaged?
    6 days ago
    Marketing in Asia Presents an Exclusive Interview with Ng Chew Wee, Head of Business Marketing, APAC at TikTok
    3 weeks ago
    How AI is Disrupting Advertising Production and Creatives
    4 weeks ago
    Maximising Loyalty ROI: A Guide for Retail Marketers
    1 month ago
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
    Startup
    News and articles from startup and venture investment world
    Show More
    Top News
    Japan’s Evolving Booze Culture: A Market in Transformation
    Japan’s Evolving Booze Culture: A Market in Transformation
    7 months ago
    text
    Safe Space™ announces partnership with National Healthcare Group as it continues to boost employee support and wellbeing
    8 months ago
    Sakshi Kalani Founder & CEO of Savy Click and Jaipur Unfolded
    AI-Powered Analytics: Sakshi Kalani on Influencer Marketing in 2025
    8 months ago
    Latest News
    Byron J. Fernandez: Minimize the stress of business crises with strong CX
    5 months ago
    Vedant Mahajan Acquires Stake in Flite: Transforming Event Technology with Innovation
    5 months ago
    Navigating the Digital Economy and Tax Challenges for SMEs
    5 months ago
    sehatUP Launches India’s First Integrated Digital Health Clinic, Pioneering Holistic Healthcare
    7 months ago
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
    Business
    News and press releases from business world of Asia
    Show More
    Top News
    Gabie Boko_CMO_NetApp
    Marketing in Asia Presents an Exclusive Interview with Gabie Boko, Chief Marketing Officer, NetApp
    4 weeks ago
    Stella Zhu
    How AI is Disrupting Advertising Production and Creatives
    4 weeks ago
    Mr. Preston Tan, Vice President of Toyota Motors Asia
    Toyota Motor Asia – Move Your World Launch at Bangkok International Motor Show
    1 month ago
    Latest News
    Modern retail marketing technology solution allows businesses to deliver mind-blowing numbers of offers in real time
    4 days ago
    Are coworking spaces the best way to keep up the next generation of Malaysian workers engaged?
    6 days ago
    Marketing in Asia Presents an Exclusive Interview with Andy See, Founder and Managing Director of Perspective Strategies
    6 days ago
    Marketing in Asia Presents an Exclusive Interview with Ng Chew Wee, Head of Business Marketing, APAC at TikTok
    3 weeks ago
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
    Society
    News and articles from and for societies around us
    Show More
    Top News
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    5 months ago
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    6 months ago
    Australia luxury property
    Australia’s Luxury Real Estate Market Soars as Affluent Buyers Seek Waterfront Dreams
    6 months ago
    Latest News
    From Taboo to Triumph: How Malaysians Are Transforming Their Intimate Health Journey
    2 months ago
    Top 5 Misconceptions About Antibiotics Malaysians Need to Stop Believing
    2 months ago
    Eagle Eye Reveals Impact of Loyalty Programs on APAC Retailers
    2 months ago
    Elevate Your Haircare in 2025 with Jung Beauty’s Luxurious Camellia Edition Treatment
    4 months ago
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Search
Technology
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
Other Pages
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Web Stories
  • Videos
  • Disclaimer
  • Terms of Service
  • Privacy Policy
© 2024 Marketing In Asia Sdn Bhd. All Rights Reserved.
Reading: Is SMS One Time Password (OTP) Secure?
Share
Sign In
Notification Show More
Latest News
avia
India: Revolutionizing Video And Content For The Global Media And Entertainment Industy
Press Release
UNESCO Global Forum
Thailand, Led by DPM Prasert, to Showcase Leadership in Hosting the 3rd UNESCO Global Forum on the Ethics of AI 2025
Press Release
Ensign Infosecurity
Ensign InfoSecurity Recognised in MITRE’s 2024 Impact Report for Contribution to Global Cyber Defence Research
Press Release
Fore Experience
Fore Coffee Opened “Fore Experience” an Extension Experience for Customers
Press Release
Medhavi Group and Patanjali Japan Foundation forge strategic partnership to unlock global employment opportunities
Medhavi Group and Patanjali Japan Foundation Sign MoU to Open Global Career Opportunities for Indian Youth in Japan
Press Release
Aa
Marketing In Asia
Aa
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Startup Register & Login
Search
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Have an existing account? Sign In
Follow US
© 2023 Marketing In Asia Sdn Bhd. All Rights Reserved.
Marketing In Asia > Blog > Society > Inspiration > Is SMS One Time Password (OTP) Secure?
Inspiration

Is SMS One Time Password (OTP) Secure?

profile
Last updated: 2022/07/29 at 4:44 PM
Iqbal Abdullah
Share
10 Min Read
is-sms-one-time-password-(otp)-secure?
SHARE

SMS OTP security and what to do to protect yourself

While explaining our GetOTP: Multi OTP API product to anyone who is willing to listen, this is a question that we have been asked time and time again.

“So, is it or is it not secure?” you ask.

Before we answer that…

Let us go through examples of how you can get hacked even though you’re using SMS OTPs.

1. Malware on your phone

This is the most common form of hacking with the highest rate of success. The attacker infects your smart device with a malicious app, which you downloaded from the internet. The malicious app has permission to access your SMS messages and to connect to the internet to send those messages to the attacker’s server.

This is the biggest reason why we’re seeing an explosion of scams and attacks in recent years, due to the obliquity of the smartphone in our lives.

How to protect yourself

On your part, you can prevent this by not downloading unknown apps from unknown places or companies. Also, apps with few reviews, or that ask for permissions that they shouldn’t have in the first place. For example, if a free gaming app says it wants to access your SMS messages, it’s a red flag.

2. SIM swap attacks

This is a more elaborate form of hacking through social engineering, which targets the human factor.

The attacker will call your mobile carrier, impersonate your identity and get your carrier to reissue another SIM under your name. Once they have the “new” SIM, they can use it on a different device and receive an SMS sent to your number. When this happens, you will lose connectivity on your own device. It’s a telltale sign that you’re being attacked if you were not expecting to lose connectivity.

In order for the attacker to be successful, she or he needs to know something about you, such as your address and your full name. This means that this will most likely be a targeted attack on yourself, and not a full-blown attack affecting many people.

How to protect yourself

Granted, this is not a problem with SMS OTP per se, but a weakness in the human processes within the carrier itself. Carriers can reduce the risk of these attacks by adding checks. A good example is making a call to the real subscriber to confirm through a secondary number or email. In general, by removing as many human elements within the process and automating as much as possible.

On your end, make sure to review how the carrier of your choice implements this process and try going for one that fits what we described above.

3. Compromised SMS Centers

If the SMS centres managed by our mobile carrier themselves that receives and routes SMS to mobile phones are compromised, then anything that you send and receive will be accessible to the attacker.

How can the SMS centres get compromised? Well, it is difficult, but not impossible. Malware attacks that trick the carrier’s employees, or outright illegal acts by rogue employees which break into the SMS centres and leak data come to mind.

Carriers in all legal jurisdictions operate through licenses given to them by the government. In exchange for these licenses, the carriers need to adhere to certain standards of operations, which include security standards. You should expect a higher security standard from your carriers than you would if you’re storing sensitive data in your own home.

How to protect yourself

Again, make sure you’re going with a reputable carrier and hope for the best.

4. Intercepting your mobile traffic

If you’re a particularly important or famous person, like the president of a country, or controversial politician, or even a successful drug lord, then congratulations: This particular attack is for you.

An attacker tries to intercept the traffic between your mobile and the carrier itself in the air, through tools such as an IMSI Catcher or an RTL-SDR radio scanner. These tools are easy to find and use and are common within law enforcement, but the attacker needs to be close to the target and listen to the correct traffic. Remember the stakeout scenes in unmarked vans parked at the side of the street that detectives usually do to catch a criminal? Yes, that is what is required if you’re trying to attack someone with this method.

How to protect yourself

If you’re not a president of a country, or controversial politician, or even a successful drug lord, no need to worry. You’ll probably never have this issue.

5. Fake redirects

Most of the time though, it’s not even the SMS itself.

Man-in-the-middle attacks target you by setting up a fake site or an internet access point. These types of attacks intercept your data and try to either redirect you to a fake site and get you to input a valid SMS OTP sent to your mobile, or try to replicate the verification data which you used to log in to an online service using a valid SMS OTP.

These types of attacks are easy to execute and will be the more common types of attacks.

How to protect yourself

You can avoid them by making sure that you’re accessing sites that are encrypted (they will have HTTPS in their URL) and also not to click on links from emails or SMS which you did not expect to receive or from unknown sources.

6. Brute force attacks

Finally, we have the classic brute force attacks. Attackers will do thousands of attempts with many different combinations of OTPs at the website they want to break, hoping that one of those will be a valid OTP.

How to protect yourself

This is beyond our control, but the website administrators can protect themselves better by rate-limiting: Controlling the number of attempts allowed in a period of time. We have this feature in GetOTP through the usage of Captcha, and if website administrators use our API, they can forget about the nitty-gritty details of trying to implement a secure OTP mechanism.

In conclusion

How secure an SMS OTP directly depends on how secure the receiving device is. Just like the device, the OTP is also vulnerable to physical attacks. If an attacker gains physical access to your device, then all bets are off.

Remember that SMS-based two-factor authentication (2FA) is still better than having your usual username/password combination. Billions of SMS messages are being sent and received every single day, and due to its ubiquity, SMS will not be going anywhere overnight.

Having said that, only having SMS OTP as your only authentication method is not good enough. It should be coupled with email, voice, or a strong login/password mechanism. The usual advice applies here: Set strong passwords with more than 8 random characters using alphabets, numbers, and signs, and never use the same password for different websites.

When we talk about security, it usually boils down to these two things: – There is no silver bullet to “security”. Have different ways to authenticate, like having more than one lock at your door. – It’s always a trade-off of convenience and security. For 99% of us, the usual precautions like not installing what we don’t know and not clicking on strange links, coupled with good passwords and SMS OTP will be enough. Of course, depending on who you are and what you’re going to protect, this will definitely change.

To conclude, SMS OTP is “secure enough” for most of us, but it comes with the condition that all the other parts that surround it, especially the device that receives the SMS OTP is also secure.

You Might Also Like

Anant Bhai Ambani’s Vantara Unveils Striking Wildlife Sculptures in Mumbai to Expose the Hidden Threat of Plastic Pollution

Hong Kong Palace Museum Unveils ‘The Origins of Chinese Civilisation’ Exhibition, Showcasing 5,000 Years of History

Superstars of Vantara: Celebrity Voices Champion Wildlife Conservation in Latest Edutainment Series Episode

Influencer Marketing in the F&B Sector: How to Choose the Right Partners

Vantara: Pioneering Global Wildlife Rescue and Rehabilitation, Led by Anant Bhai Ambani

MIA
Get Latest Job Updates on Whatsapp and Telegram
SCIKEY Logo
Whatsapp
Telegram
TAGGED: otp, security, sms

Sign Up For MIA Newsletter

Be keep up! Get the latest updates about the Marketing world delivered straight to your inbox.

    By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
    Iqbal Abdullah July 29, 2022 December 20, 2021
    Share This Article
    Facebook Twitter LinkedIn Email Copy Link Print
    Share
    What do you think?
    Love0
    Happy0
    Joy0
    Surprise0
    Sad0
    Angry0
    Cry0
    profile
    By Iqbal Abdullah
    Follow:
    I am an e-resident of Estonia and a resident of Tokyo, and also run the LaLoka Labs group. We create software for our clients to help them become more productive and happier human beings. I have been working remotely since 2007. My interests are travel, learning new languages and seeing technology work to improve our lives.
    Previous Article 10-social-media-trends-to-look-out-for-in-2022 10 Social Media Trends To Look Out For In 2022
    Next Article how-to-use-qr-codes-in-marketing How To Use QR Codes In Marketing
    Leave a comment Leave a comment

    Leave a Reply Cancel reply

    You must be logged in to post a comment.

    9.5k Followers Follow
    3.4k Followers Like
    1.1k Followers Follow
    214 Followers Follow
    208 Subscribers Subscribe

    Latest News

    avia
    India: Revolutionizing Video And Content For The Global Media And Entertainment Industy
    Press Release 3 days ago
    UNESCO Global Forum
    Thailand, Led by DPM Prasert, to Showcase Leadership in Hosting the 3rd UNESCO Global Forum on the Ethics of AI 2025
    Press Release 3 days ago
    Ensign Infosecurity
    Ensign InfoSecurity Recognised in MITRE’s 2024 Impact Report for Contribution to Global Cyber Defence Research
    Press Release 3 days ago
    Fore Experience
    Fore Coffee Opened “Fore Experience” an Extension Experience for Customers
    Press Release 3 days ago

    PropertyGuru

    property guru

    You Might also Like

    Anant Bhai Ambani’s Vantara Unveils Striking Wildlife Sculptures in Mumbai to Expose the Hidden Threat of Plastic Pollution (1)
    BuzzCampaignInspirationLifestyleOpen Category

    Anant Bhai Ambani’s Vantara Unveils Striking Wildlife Sculptures in Mumbai to Expose the Hidden Threat of Plastic Pollution

    7 months ago
    Hong Kong Palace Museum Unveils 'The Origins of Chinese Civilisation' Exhibition, Showcasing 5,000 Years of History
    EducationEntertainmentInspirationPress Release

    Hong Kong Palace Museum Unveils ‘The Origins of Chinese Civilisation’ Exhibition, Showcasing 5,000 Years of History

    8 months ago
    Superstars of Vantara Celebrity Voices Champion Wildlife Conservation in Latest Edutainment Series Episode
    CampaignEventInspirationLifestylePeople

    Superstars of Vantara: Celebrity Voices Champion Wildlife Conservation in Latest Edutainment Series Episode

    8 months ago
    Satish Bhatia, Co - Founder The Malabar Coast
    InspirationMarketingOpinionPeopleResearch

    Influencer Marketing in the F&B Sector: How to Choose the Right Partners

    8 months ago
    //

    Get Asia to Notice You

    Quick Link

    • Contact
    • RSS Terms of Service
    • Policies & Standards
    • About Us
    • FAQ
    • Disclaimer
    • Terms Of Service
    • Privacy Policy

    Top Categories

    • Marketing
    • Startup
    • Feature Stories
    • News
    • People
    • Inspiration

    Sign Up for Our Newsletter

    Subscribe to our newsletter to get our newest articles instantly!

      Marketing In AsiaMarketing In Asia
      Follow US
      © 2024 Marketing In Asia. All Rights Reserved.
      • Disclaimer
      • Terms of Service
      • Privacy Policy