Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys

If an attacker has one of your devices, bypassing SMS is even easier. Nor does passwordless login have to rely on biometrics. If you consider it insecure, use a pin or a rolling authenticator code.

Honestly, some people are so anxious to knock Microsoft, you deny basica reality. These schemes are more secure than sending a password over the open Internet, then responding to a plaintext SMS message.


We're speaking of FIDO2 passkeys here, which are not passwords. You may be thinking of a pin, which one could indeed call a password, but is a little harder to spoof, since it never leaves your device.


But they can't. Whether you're speaking of a FIDO passkey or a pin, they are tied to a specific device. I could tell you my pin now is "1234", and that does you absolutely no good without access to the device that pin is associated with.


I think you've misread my statement. I was responding to the claim that any two factors are inherently better than any (different) single factor. Mathematically, this is false. If you use 2FA with each factor being 90% secure, that's more vulnerable than a single factor 99.9% secure.
Now, Now, Now, don't mix up logic and then confuse them with statistics (which the average person never learned). Well Said!
 
Back