{"id":4409,"date":"2022-11-10T06:44:00","date_gmt":"2022-11-10T06:44:00","guid":{"rendered":"https:\/\/wibmo.com\/moving-beyond-sms-otp-authentication\/"},"modified":"2024-06-04T06:09:37","modified_gmt":"2024-06-04T06:09:37","slug":"moving-beyond-sms-otp-authentication","status":"publish","type":"post","link":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/","title":{"rendered":"Moving beyond SMS OTP Authentication"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4409\" class=\"elementor elementor-4409\">\n\t\t\t\t<div class=\"elementor-element elementor-element-28d8bab3 e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\" data-id=\"28d8bab3\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-407b2e4a elementor-widget elementor-widget-text-editor\" data-id=\"407b2e4a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If you have ever transacted or purchased online, you must have come across the OTP Authentication. The system-generated code delivered through SMS on your device serves as a verification of the claim that you are the actual owner of the device as well as the account\/card\/wallet through which the transaction is initiated.<\/p>\n<p>The authentication or verification of our identity as who we claim ourselves to be is a part of our day-to-day lives. Be it checking in at the airport or going past the security desk of an office, though we identify ourselves with our name, we authenticate ourselves with some other form of ID card. With growing security concerns, both in the physical and digital worlds, authentication methods have evolved not only to protect but also to provide a seamless experience to users.<\/p>\n<p>The ways in which one can be authenticated fall into three categories:<\/p>\n<p>\u00b7 Knowledge: Something the user knows (eg. Password)<\/p>\n<p>\u00b7 Ownership: Something the user has (eg. ID card)<\/p>\n<p>\u00b7 Inherence: Something the user is (eg. Fingerprint)<\/p>\n<p>The above categories are referred as the Authentication Factors and the use of the number of factors in an authentication process derives its name.<\/p>\n<p>\u00b7 Single-factor Authentication: Requires providing only one piece of verifiable information such as a password<\/p>\n<p>\u00b7 Two-factor Authentication(2FA): Requires providing two pieces of verifiable information such as a password and then proof of possession of their smartphone (through an SMS OTP delivered on that device)<\/p>\n<p>\u00b7 Multi-factor Authentication: Required to provide two or more pieces of verifiable information. As in the case of 2FA, where two categories (factors) of information are required, it is also considered an MFA.<\/p>\n<p>The idea of an OTP was first suggested in the 1980s by Leslie Lamport. With growing attacks and increasing authentication requirements, many patented OTP algorithms were developed. Today, OTPs are synonymous with two-factor authentication and are thought to augment existing passwords with an extra layer of security. Yet, fraudsters manage to circumvent it every day.<\/p>\n<p><strong class=\"na hj\">SIM SWAP<\/strong>: In this scenario, a fraudster uses the stolen identity (name, email, government ID, etc.) to trick a mobile service provider into issuing a new SIM card for an existing phone number.<\/p>\n<p>Once the new SIM card is active, the original SIM card will be shut down, and the fraudster will try to gain access to the user\u2019s financial application. Once the fraudster has gained access, the last line of defense\u20142FA or SMS OTP, is compromised.<\/p>\n<p><strong class=\"na hj\">JAILBREAK or ROOT<\/strong>: Removing software restrictions put in place by manufacturers, to gain full access to the device&#8217;s operating system is called &#8220;jailbreaking&#8221; for iOS and &#8220;rooting&#8221; for the Android operating system. Generally, it is aimed at customizing the user experience or gaining access to a greater variety of unofficial apps.<\/p>\n<p>Jailbroken and rooted devices are susceptible to malware and viruses due to the weakened built-in security features of the devices. This eliminates security controls made by the manufacturer, which enables hackers to steal personal information, attack the network, or introduce malware, spyware, or viruses to circumvent the authentication measures in place.<\/p>\n<p>Investigating the feasibility of implementing a code by financial institutions that checks if the device is rooted or jailbroken prior to the installation of the mobile application and disallows the mobile application to install or function if the phone is rooted or jailbroken, can save its customers from possible fraud.<\/p>\n<p>Increasing layers of security is not a feasible solution for financial institutions when consumers prefer speed and convenience, even when it comes to accessing financial services online. User experience has become one of the determining factors when it comes to user adoption in any industry globally. Not receiving an SMS OTP, is one of the most painful experiences one can have as a user. Latency, in addition to the SMS cost, is a challenge for financial institutions in the exponentially growing digital era.<\/p>\n<p>Maintaining a balance between fighting fraud and improving the consumer experience is a challenge. Leveraging inherence-based authentication, such as biometrics, or ownership-based authentication, such as push notifications on the registered device, are some of the authentication measures that cater to both security and the consumer experience. <a class=\"af nw\" href=\"https:\/\/www.wibmo.com\/tridentity\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Technological solutions<\/a> with multiple authentication measures other than SMS OTPs and device binding are the way forward for providing a delightful customer experience without compromising security.<\/p>\n<p><strong class=\"na hj\">Author:<\/strong><\/p>\n<p><a class=\"af nw\" href=\"https:\/\/www.linkedin.com\/in\/sujitmahato\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Sujit Kumar Mahato<\/a>, Product Manager<\/p>\n<p><a class=\"af nw\" href=\"https:\/\/www.wibmo.com\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Wibmo<\/a> A PayU\/Naspers FinTech Company<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2cf8b8c e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\" data-id=\"2cf8b8c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-54d8097 wpr-post-info-align-center elementor-widget elementor-widget-wpr-post-info\" data-id=\"54d8097\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wpr-post-info.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<ul class=\"wpr-post-info wpr-post-info-vertical\"><li class=\"wpr-post-info-taxonomy\"><a href=\"https:\/\/wibmo.com\/blogs\/tag\/authentication-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Authentication<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/fraud-prevention-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Fraud Prevention<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/global-digital-payments-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Global Digital Payments<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/payments-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Payments<\/a><\/li><\/ul>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>If you have ever transacted or purchased online, you must have come across the OTP Authentication. The system-generated code delivered through SMS on your device serves as a verification of the claim that you are the actual owner of the device as well as the account\/card\/wallet through which the transaction is initiated. The authentication or verification of our identity as who we claim ourselves to be is a part of our day-to-day lives. Be it checking in at the airport or going past the security desk of an office, though we identify ourselves with our name, we authenticate ourselves with some other form of ID card. With growing security concerns, both in the physical and digital worlds, authentication methods have evolved not only to protect but also to provide a seamless experience to users. The ways in which one can be authenticated fall into three categories: \u00b7 Knowledge: Something the user knows (eg. Password) \u00b7 Ownership: Something the user has (eg. ID card) \u00b7 Inherence: Something the user is (eg. Fingerprint) The above categories are referred as the Authentication Factors and the use of the number of factors in an authentication process derives its name. \u00b7 Single-factor Authentication: Requires providing only one piece of verifiable information such as a password \u00b7 Two-factor Authentication(2FA): Requires providing two pieces of verifiable information such as a password and then proof of possession of their smartphone (through an SMS OTP delivered on that device) \u00b7 Multi-factor Authentication: Required to provide two or more pieces of verifiable information. As in the case of 2FA, where two categories (factors) of information are required, it is also considered an MFA. The idea of an OTP was first suggested in the 1980s by Leslie Lamport. With growing attacks and increasing authentication requirements, many patented OTP algorithms were developed. Today, OTPs are synonymous with two-factor authentication and are thought to augment existing passwords with an extra layer of security. Yet, fraudsters manage to circumvent it every day. SIM SWAP: In this scenario, a fraudster uses the stolen identity (name, email, government ID, etc.) to trick a mobile service provider into issuing a new SIM card for an existing phone number. Once the new SIM card is active, the original SIM card will be shut down, and the fraudster will try to gain access to the user\u2019s financial application. Once the fraudster has gained access, the last line of defense\u20142FA or SMS OTP, is compromised. JAILBREAK or ROOT: Removing software restrictions put in place by manufacturers, to gain full access to the device&#8217;s operating system is called &#8220;jailbreaking&#8221; for iOS and &#8220;rooting&#8221; for the Android operating system. Generally, it is aimed at customizing the user experience or gaining access to a greater variety of unofficial apps. Jailbroken and rooted devices are susceptible to malware and viruses due to the weakened built-in security features of the devices. This eliminates security controls made by the manufacturer, which enables hackers to steal personal information, attack the network, or introduce malware, spyware, or viruses to circumvent the authentication measures in place. Investigating the feasibility of implementing a code by financial institutions that checks if the device is rooted or jailbroken prior to the installation of the mobile application and disallows the mobile application to install or function if the phone is rooted or jailbroken, can save its customers from possible fraud. Increasing layers of security is not a feasible solution for financial institutions when consumers prefer speed and convenience, even when it comes to accessing financial services online. User experience has become one of the determining factors when it comes to user adoption in any industry globally. Not receiving an SMS OTP, is one of the most painful experiences one can have as a user. Latency, in addition to the SMS cost, is a challenge for financial institutions in the exponentially growing digital era. Maintaining a balance between fighting fraud and improving the consumer experience is a challenge. Leveraging inherence-based authentication, such as biometrics, or ownership-based authentication, such as push notifications on the registered device, are some of the authentication measures that cater to both security and the consumer experience. Technological solutions with multiple authentication measures other than SMS OTPs and device binding are the way forward for providing a delightful customer experience without compromising security. Author: Sujit Kumar Mahato, Product Manager Wibmo A PayU\/Naspers FinTech Company Authentication, Fraud Prevention, Global Digital Payments, Payments<\/p>\n","protected":false},"author":7,"featured_media":4449,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[82,85],"tags":[137,90,140,127],"class_list":["post-4409","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-insights","category-reading-list","tag-authentication-2","tag-fraud-prevention-2","tag-global-digital-payments-2","tag-payments-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Moving beyond SMS OTP Authentication - Digital Payments, Payment Security and Lending - Wibmo<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Moving beyond SMS OTP Authentication - Digital Payments, Payment Security and Lending - Wibmo\" \/>\n<meta property=\"og:description\" content=\"If you have ever transacted or purchased online, you must have come across the OTP Authentication. The system-generated code delivered through SMS on your device serves as a verification of the claim that you are the actual owner of the device as well as the account\/card\/wallet through which the transaction is initiated. The authentication or verification of our identity as who we claim ourselves to be is a part of our day-to-day lives. Be it checking in at the airport or going past the security desk of an office, though we identify ourselves with our name, we authenticate ourselves with some other form of ID card. With growing security concerns, both in the physical and digital worlds, authentication methods have evolved not only to protect but also to provide a seamless experience to users. The ways in which one can be authenticated fall into three categories: \u00b7 Knowledge: Something the user knows (eg. Password) \u00b7 Ownership: Something the user has (eg. ID card) \u00b7 Inherence: Something the user is (eg. Fingerprint) The above categories are referred as the Authentication Factors and the use of the number of factors in an authentication process derives its name. \u00b7 Single-factor Authentication: Requires providing only one piece of verifiable information such as a password \u00b7 Two-factor Authentication(2FA): Requires providing two pieces of verifiable information such as a password and then proof of possession of their smartphone (through an SMS OTP delivered on that device) \u00b7 Multi-factor Authentication: Required to provide two or more pieces of verifiable information. As in the case of 2FA, where two categories (factors) of information are required, it is also considered an MFA. The idea of an OTP was first suggested in the 1980s by Leslie Lamport. With growing attacks and increasing authentication requirements, many patented OTP algorithms were developed. Today, OTPs are synonymous with two-factor authentication and are thought to augment existing passwords with an extra layer of security. Yet, fraudsters manage to circumvent it every day. SIM SWAP: In this scenario, a fraudster uses the stolen identity (name, email, government ID, etc.) to trick a mobile service provider into issuing a new SIM card for an existing phone number. Once the new SIM card is active, the original SIM card will be shut down, and the fraudster will try to gain access to the user\u2019s financial application. Once the fraudster has gained access, the last line of defense\u20142FA or SMS OTP, is compromised. JAILBREAK or ROOT: Removing software restrictions put in place by manufacturers, to gain full access to the device&#8217;s operating system is called &#8220;jailbreaking&#8221; for iOS and &#8220;rooting&#8221; for the Android operating system. Generally, it is aimed at customizing the user experience or gaining access to a greater variety of unofficial apps. Jailbroken and rooted devices are susceptible to malware and viruses due to the weakened built-in security features of the devices. This eliminates security controls made by the manufacturer, which enables hackers to steal personal information, attack the network, or introduce malware, spyware, or viruses to circumvent the authentication measures in place. Investigating the feasibility of implementing a code by financial institutions that checks if the device is rooted or jailbroken prior to the installation of the mobile application and disallows the mobile application to install or function if the phone is rooted or jailbroken, can save its customers from possible fraud. Increasing layers of security is not a feasible solution for financial institutions when consumers prefer speed and convenience, even when it comes to accessing financial services online. User experience has become one of the determining factors when it comes to user adoption in any industry globally. Not receiving an SMS OTP, is one of the most painful experiences one can have as a user. Latency, in addition to the SMS cost, is a challenge for financial institutions in the exponentially growing digital era. Maintaining a balance between fighting fraud and improving the consumer experience is a challenge. Leveraging inherence-based authentication, such as biometrics, or ownership-based authentication, such as push notifications on the registered device, are some of the authentication measures that cater to both security and the consumer experience. Technological solutions with multiple authentication measures other than SMS OTPs and device binding are the way forward for providing a delightful customer experience without compromising security. Author: Sujit Kumar Mahato, Product Manager Wibmo A PayU\/Naspers FinTech Company Authentication, Fraud Prevention, Global Digital Payments, Payments\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/\" \/>\n<meta property=\"og:site_name\" content=\"Digital Payments, Payment Security and Lending - Wibmo\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-10T06:44:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-04T06:09:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1400\" \/>\n\t<meta property=\"og:image:height\" content=\"695\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Sujit Kumar Mahato\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sujit Kumar Mahato\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/\"},\"author\":{\"name\":\"Sujit Kumar Mahato\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/person\\\/5d110c20c9f6bfe7da73fe6237be28fc\"},\"headline\":\"Moving beyond SMS OTP Authentication\",\"datePublished\":\"2022-11-10T06:44:00+00:00\",\"dateModified\":\"2024-06-04T06:09:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/\"},\"wordCount\":736,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Beyond-SMS-OTP-authentication.webp\",\"keywords\":[\"Authentication\",\"Fraud Prevention\",\"Global Digital Payments\",\"Payments\"],\"articleSection\":[\"Industry Insights\",\"Reading List\"],\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/\",\"name\":\"Moving beyond SMS OTP Authentication - Digital Payments, Payment Security and Lending - Wibmo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Beyond-SMS-OTP-authentication.webp\",\"datePublished\":\"2022-11-10T06:44:00+00:00\",\"dateModified\":\"2024-06-04T06:09:37+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#primaryimage\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Beyond-SMS-OTP-authentication.webp\",\"contentUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Beyond-SMS-OTP-authentication.webp\",\"width\":1400,\"height\":695},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/moving-beyond-sms-otp-authentication\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Moving beyond SMS OTP Authentication\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#website\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\",\"name\":\"Digital Payments, Payment Security and Lending - Wibmo\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\",\"name\":\"Digital Payments, Payment Security and Lending - Wibmo\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/cropped-New-Project.png\",\"contentUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/cropped-New-Project.png\",\"width\":220,\"height\":45,\"caption\":\"Digital Payments, Payment Security and Lending - Wibmo\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/person\\\/5d110c20c9f6bfe7da73fe6237be28fc\",\"name\":\"Sujit Kumar Mahato\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a995ef0db158ad77acd190325c2d7147552d4550d50c9ae6b7f77da5870c15a3?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a995ef0db158ad77acd190325c2d7147552d4550d50c9ae6b7f77da5870c15a3?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a995ef0db158ad77acd190325c2d7147552d4550d50c9ae6b7f77da5870c15a3?s=96&d=mm&r=g\",\"caption\":\"Sujit Kumar Mahato\"},\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/author\\\/sujit-kumar-mahato\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Moving beyond SMS OTP Authentication - Digital Payments, Payment Security and Lending - Wibmo","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/","og_locale":"en_US","og_type":"article","og_title":"Moving beyond SMS OTP Authentication - Digital Payments, Payment Security and Lending - Wibmo","og_description":"If you have ever transacted or purchased online, you must have come across the OTP Authentication. The system-generated code delivered through SMS on your device serves as a verification of the claim that you are the actual owner of the device as well as the account\/card\/wallet through which the transaction is initiated. The authentication or verification of our identity as who we claim ourselves to be is a part of our day-to-day lives. Be it checking in at the airport or going past the security desk of an office, though we identify ourselves with our name, we authenticate ourselves with some other form of ID card. With growing security concerns, both in the physical and digital worlds, authentication methods have evolved not only to protect but also to provide a seamless experience to users. The ways in which one can be authenticated fall into three categories: \u00b7 Knowledge: Something the user knows (eg. Password) \u00b7 Ownership: Something the user has (eg. ID card) \u00b7 Inherence: Something the user is (eg. Fingerprint) The above categories are referred as the Authentication Factors and the use of the number of factors in an authentication process derives its name. \u00b7 Single-factor Authentication: Requires providing only one piece of verifiable information such as a password \u00b7 Two-factor Authentication(2FA): Requires providing two pieces of verifiable information such as a password and then proof of possession of their smartphone (through an SMS OTP delivered on that device) \u00b7 Multi-factor Authentication: Required to provide two or more pieces of verifiable information. As in the case of 2FA, where two categories (factors) of information are required, it is also considered an MFA. The idea of an OTP was first suggested in the 1980s by Leslie Lamport. With growing attacks and increasing authentication requirements, many patented OTP algorithms were developed. Today, OTPs are synonymous with two-factor authentication and are thought to augment existing passwords with an extra layer of security. Yet, fraudsters manage to circumvent it every day. SIM SWAP: In this scenario, a fraudster uses the stolen identity (name, email, government ID, etc.) to trick a mobile service provider into issuing a new SIM card for an existing phone number. Once the new SIM card is active, the original SIM card will be shut down, and the fraudster will try to gain access to the user\u2019s financial application. Once the fraudster has gained access, the last line of defense\u20142FA or SMS OTP, is compromised. JAILBREAK or ROOT: Removing software restrictions put in place by manufacturers, to gain full access to the device&#8217;s operating system is called &#8220;jailbreaking&#8221; for iOS and &#8220;rooting&#8221; for the Android operating system. Generally, it is aimed at customizing the user experience or gaining access to a greater variety of unofficial apps. Jailbroken and rooted devices are susceptible to malware and viruses due to the weakened built-in security features of the devices. This eliminates security controls made by the manufacturer, which enables hackers to steal personal information, attack the network, or introduce malware, spyware, or viruses to circumvent the authentication measures in place. Investigating the feasibility of implementing a code by financial institutions that checks if the device is rooted or jailbroken prior to the installation of the mobile application and disallows the mobile application to install or function if the phone is rooted or jailbroken, can save its customers from possible fraud. Increasing layers of security is not a feasible solution for financial institutions when consumers prefer speed and convenience, even when it comes to accessing financial services online. User experience has become one of the determining factors when it comes to user adoption in any industry globally. Not receiving an SMS OTP, is one of the most painful experiences one can have as a user. Latency, in addition to the SMS cost, is a challenge for financial institutions in the exponentially growing digital era. Maintaining a balance between fighting fraud and improving the consumer experience is a challenge. Leveraging inherence-based authentication, such as biometrics, or ownership-based authentication, such as push notifications on the registered device, are some of the authentication measures that cater to both security and the consumer experience. Technological solutions with multiple authentication measures other than SMS OTPs and device binding are the way forward for providing a delightful customer experience without compromising security. Author: Sujit Kumar Mahato, Product Manager Wibmo A PayU\/Naspers FinTech Company Authentication, Fraud Prevention, Global Digital Payments, Payments","og_url":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/","og_site_name":"Digital Payments, Payment Security and Lending - Wibmo","article_published_time":"2022-11-10T06:44:00+00:00","article_modified_time":"2024-06-04T06:09:37+00:00","og_image":[{"width":1400,"height":695,"url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp","type":"image\/webp"}],"author":"Sujit Kumar Mahato","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sujit Kumar Mahato","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#article","isPartOf":{"@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/"},"author":{"name":"Sujit Kumar Mahato","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/person\/5d110c20c9f6bfe7da73fe6237be28fc"},"headline":"Moving beyond SMS OTP Authentication","datePublished":"2022-11-10T06:44:00+00:00","dateModified":"2024-06-04T06:09:37+00:00","mainEntityOfPage":{"@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/"},"wordCount":736,"commentCount":0,"publisher":{"@id":"https:\/\/wibmo.com\/blogs\/#organization"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#primaryimage"},"thumbnailUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp","keywords":["Authentication","Fraud Prevention","Global Digital Payments","Payments"],"articleSection":["Industry Insights","Reading List"],"inLanguage":"en","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/","url":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/","name":"Moving beyond SMS OTP Authentication - Digital Payments, Payment Security and Lending - Wibmo","isPartOf":{"@id":"https:\/\/wibmo.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#primaryimage"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#primaryimage"},"thumbnailUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp","datePublished":"2022-11-10T06:44:00+00:00","dateModified":"2024-06-04T06:09:37+00:00","breadcrumb":{"@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#primaryimage","url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp","contentUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp","width":1400,"height":695},{"@type":"BreadcrumbList","@id":"https:\/\/wibmo.com\/blogs\/moving-beyond-sms-otp-authentication\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wibmo.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Moving beyond SMS OTP Authentication"}]},{"@type":"WebSite","@id":"https:\/\/wibmo.com\/blogs\/#website","url":"https:\/\/wibmo.com\/blogs\/","name":"Digital Payments, Payment Security and Lending - Wibmo","description":"","publisher":{"@id":"https:\/\/wibmo.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wibmo.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":"Organization","@id":"https:\/\/wibmo.com\/blogs\/#organization","name":"Digital Payments, Payment Security and Lending - Wibmo","url":"https:\/\/wibmo.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/08\/cropped-New-Project.png","contentUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/08\/cropped-New-Project.png","width":220,"height":45,"caption":"Digital Payments, Payment Security and Lending - Wibmo"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/person\/5d110c20c9f6bfe7da73fe6237be28fc","name":"Sujit Kumar Mahato","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/a995ef0db158ad77acd190325c2d7147552d4550d50c9ae6b7f77da5870c15a3?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a995ef0db158ad77acd190325c2d7147552d4550d50c9ae6b7f77da5870c15a3?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a995ef0db158ad77acd190325c2d7147552d4550d50c9ae6b7f77da5870c15a3?s=96&d=mm&r=g","caption":"Sujit Kumar Mahato"},"url":"https:\/\/wibmo.com\/blogs\/author\/sujit-kumar-mahato\/"}]}},"jetpack_featured_media_url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/Beyond-SMS-OTP-authentication.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts\/4409","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/comments?post=4409"}],"version-history":[{"count":0,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts\/4409\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/media\/4449"}],"wp:attachment":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/media?parent=4409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/categories?post=4409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/tags?post=4409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}