Microsoft is killing off SMS login codes, citing AI-powered hacking

Daniel Sims

Posts: 2,521   +76
Staff
In brief: Sending codes to users via SMS has long been discredited as the least secure multi-factor authentication method, and Microsoft will soon discontinue support for this practice altogether. Citing the rising danger of hackers armed with AI tools, the company has now provided a timeline for phasing out SMS codes.

IT admins will no longer be able to log into Microsoft Entra ID accounts using SMS-based 2FA codes starting February 1. The deadline is part of Microsoft's broader shift toward passkeys, widely considered one of the most secure login methods.

Admins recently began receiving an email from the company, obtained by Windows Latest, which outlines the SMS phaseout. Earlier this year, a support document also warned that Microsoft will eventually cease sending SMS codes to ordinary Windows Home and Professional users, but when that will happen remains unclear.

Security experts have advised against sending 2FA codes via text messages for years, primarily because they are easily intercepted. However, Microsoft's recent announcement also claims that AI has made phishing and other hacking methods more effective.

Traditional phishing strategies are more likely to trick users into handing over passwords and other sensitive data when used in tandem with AI. The technology also makes it easier for attackers to carry out SIM-swapping attacks.

A recent Windows 11 update also retired picture passwords. Initially introduced to promote Windows 8's touch capabilities, tracing gestures over pictures to log into Windows has not been considered truly secure for some time.

Microsoft has instead promoted PINs, biometrics, and passkeys over other methods, especially passwords. The company already encourages users to delete their passwords and use passkeys as their first login method. Starting September 1, Entra will prompt users to establish a passkey.

Easier to set up and use, passkeys lock authentication to specific devices without storing critical data on servers, leaving nothing for attackers to steal. However, researchers recently demonstrated that systems compromised with malware can leak passkey data stored in Google Chrome's memory.

Meanwhile, Google recently began testing another sign-in method for users who forget their passwords and do not have access to passkeys. After providing the company with a selfie video, users can log in from any other device by uploading another one, which is compared to the original. It remains to be seen whether the method is more or less secure than other biometric options.

Permalink to story:

 
The problem with this is that if you make your 2FA strong enough then your 2FA needs 2FA to use it and we're going down this chain of 3FA, but 4FA. I seriously have two phones because so many apps need ridiculous levels of 2FA that I have an extra phone setup as a 2FA device just in case I lose my main phone which is already a 2FA device.

2FA has gotten to such ridiculous levels I can get locked out of almost all of my accounts if I lose my phone. Even my recovery emails now require recovery emails

And there are also authenticator apps that won't run on alternative android OSs. I'm not a graphine OS guy, but I want more control than stock android gives me. Stock android USED to be great, but it's quickly spiralling into a locked down ecosystem filled with spyware. And my passwords end up getting leaked in data breaches by these massive companies collecting my data ANYWAY. I have never been hacked or attacked through any fault of my own. Any security vulnerabilities I've experienced over the years have been the result of these companies mishandling my data.

SMS is fine. If you're dumb enough to have your password leaked AND have malware or spyware on your phone that hackers can use concurrently, you probably can't be helped. Although M$ has done a wonderful job of encouraging updates with Windows 11, I'm sure that has nothing to do with it >.>
 
Last edited:
No thanks. I don't want to link anything to my phone.

There are days I don't even take my phone with me when I leave the house. I'm not linking banking info to it, no digital wallets, I know the handful of phone numbers I may need to call by memory should I need to call them, I know the random passwords I've created for logging into things sites/email that I need. I don't like the idea of being forced to use a single device for logging into things.

I may be a bit of a freak about all of this, but I'm not relying on my phone to be my sole source for logging into things.
 
The problem with this is that if you make your 2FA strong enough then your 2FA needs 2FA to use it and we're going down this chain of 3FA, but 4FA. I seriously have two phones because so many apps need ridiculous levels of 2FA that I have an extra phone setup as a 2FA device just in case I lose my main phone which is already a 2FA device.

2FA has gotten to such ridiculous levels I can get locked out of almost all of my accounts if I lose my phone. Even my recovery emails now require recovery emails

And there are also authenticator apps that won't run on alternative android OSs. I'm not a graphine OS guy, but I want more control than stock android gives me. Stock android USED to be great, but it's quickly spiralling into a locked down ecosystem filled with spyware. And my passwords end up getting leaked in data breaches by these massive companies collecting my data ANYWAY. I have never been hacked or attacked through any fault of my own. Any security vulnerabilities I've experienced over the years have been the result of these companies mishandling my data.

SMS is fine. If you're dumb enough to have your password leaked AND have malware or spyware on your phone that hackers can use concurrently, you probably can't be helped. Although M$ has done a wonderful job of encouraging updates with Windows 11, I'm sure that has nothing to do with it >.>

Passkeys can be saved in Bitwarden so it is device agnostic
 
Back