The Los Angeles Post
U.S. World Business Lifestyle
Today: April 02, 2025
Today: April 02, 2025

Smartphone users advised to ditch popular safety feature

Smartphone users
Federal cybersecurity officials issued a warning for smartphone users against using text messages for two-factor authentication, citing vulnerabilities.
January 03, 2025
Rebekah Ludman - LA Post

Federal cybersecurity officials issued a stark warning for smartphone users against using text messages for two-factor authentication, citing vulnerabilities in telecommunications networks that could expose users to security breaches.

The Cybersecurity and Infrastructure Security Agency (CISA) released new guidance urging smartphone users to abandon SMS-based authentication codes following the discovery of widespread telecom network breaches. The agency emphasized that text messages lack encryption, making them susceptible to interception by malicious actors who gain access to telecommunications networks.

"SMS messages are not encrypted — a threat actor with access to a telecommunication provider's network who intercepts these messages can read them," CISA stated in its memo. The agency noted that text-based verification methods are not "phishing-resistant" and pose particular risks for high-profile targets.

The warning comes in the wake of major network intrusions affecting AT&T, Verizon, and other carriers, which officials believe were orchestrated by Chinese hackers. According to security experts, the breach campaign, known as Salt Typhoon, may be "ongoing and likely larger in scale than previously understood. "

Jeff Greene, executive assistant director for cybersecurity at CISA, acknowledged the persistent nature of the threat. "We cannot say with certainty that the adversary has been evicted," Greene told Politico. "We're on top of tracking them down ... but we cannot with confidence say that we know everything, nor would our partners."

CISA recommends users switch to more secure authentication methods, including dedicated authentication apps, FIDO authentication, or passkeys. While authentication apps remain vulnerable to certain breaches, they offer stronger protection than SMS-based verification. For services that only provide text-based two-factor authentication, the agency advises users to seek alternative platforms when possible.

Additional security measures recommended by CISA include implementing password managers, creating strong passwords, setting device PINs, and maintaining current software updates on personal devices. The FBI has also advised users to adopt encrypted messaging platforms like Signal or WhatsApp for general communication.

Share This

Popular

Business|Crime|Technology|US

Man faces charges after Teslas set on fire with Molotov cocktails

Man faces charges after Teslas set on fire with Molotov cocktails
Education|Technology|US

'It's complicated': students reflect on first year under a phone ban

'It's complicated': students reflect on first year under a phone ban
Business|Crime|Technology

‘He just wouldn’t stop staring at me’: Tesla drivers say they’re being harassed on road

‘He just wouldn’t stop staring at me’: Tesla drivers say they’re being harassed on road
Business|Crime|Technology|US

Oracle tells clients of second recent hack, log-in data stolen, Bloomberg News reports

Oracle tells clients of second recent hack, log-in data stolen, Bloomberg News reports

Technology

Business|Economy|Political|Technology|US

Trump's auto tariffs to cover $600 billion in imports, including laptop computers

Trump's auto tariffs to cover $600 billion in imports, including laptop computers
Crime|Political|Technology|US

APD's plate reader technology assists in shooting arrest, but spurs City Council debate

APD's plate reader technology assists in shooting arrest, but spurs City Council debate
Entertainment|Technology

Nintendo Switch 2 launches in June with new Mario Kart World game

Nintendo Switch 2 launches in June with new Mario Kart World game
Business|Crime|Political|Technology|US

Boeing working with DOJ on revised plea deal in 737 MAX fraud case, CEO says

Boeing working with DOJ on revised plea deal in 737 MAX fraud case, CEO says

Access this article for free.

Already have an account? Sign In