Join the Mozilla’s Test Days event from 9–15 Jan to test the new Firefox address bar on Firefox Beta 135 and get a chance to win Mozilla swag vouchers! 🎁

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Hierdie gesprek is in die argief. Vra asseblief 'n nuwe vraag as jy hulp nodig het.

Why not 2FA via SMS?

  • 1 antwoord
  • 1 het hierdie probleem
  • 28 views
  • Laaste antwoord deur Wesley Branton

more options

Why can't 2-step authentication (for my Firefox Account) be done via SMS instead of requiring me to download another app? Isn't that how most other web apps handle it?

Why can't 2-step authentication (for my Firefox Account) be done via SMS instead of requiring me to download another app? Isn't that how most other web apps handle it?

Gekose oplossing

Originally two factor authentication was done via an SMS message with a code (not specifically by Mozilla, but in general). The reason that most companies are transitioning to using two factor authentication apps instead is for security.

As it turns out, it's fairly easy to hijack SMS text messages, which would make it easy for an attacker to gain access to your account, even though it's protected with two factor authentication.

Authentication apps don't suffer from this security flaw and since the majority of mobile devices are smart devices, it's usually not a big deal.

Another good thing about using an authentication app instead of SMS is that you can use a variety of devices, not just those that have a SIM card. It also allows you to use multiple different devices to authenticate your account. For example, if you don't have access to your smartphone, you can unlock your account with a computer if you have an authentication app setup on there.

Lees dié antwoord in konteks 👍 0

All Replies (1)

more options

Gekose oplossing

Originally two factor authentication was done via an SMS message with a code (not specifically by Mozilla, but in general). The reason that most companies are transitioning to using two factor authentication apps instead is for security.

As it turns out, it's fairly easy to hijack SMS text messages, which would make it easy for an attacker to gain access to your account, even though it's protected with two factor authentication.

Authentication apps don't suffer from this security flaw and since the majority of mobile devices are smart devices, it's usually not a big deal.

Another good thing about using an authentication app instead of SMS is that you can use a variety of devices, not just those that have a SIM card. It also allows you to use multiple different devices to authenticate your account. For example, if you don't have access to your smartphone, you can unlock your account with a computer if you have an authentication app setup on there.