Leaving SMS removes the telephony channel, but phishing resistance depends on origin binding and on every recovery path that can create a session.
SMS OTP is now a restricted authenticator. The hard part is what replaces it.
read more...
nLabs is the research practice at Neodata, in Montevideo, Uruguay. Corrections and questions: nlabs@neodata.com.uy
Leaving SMS removes the telephony channel, but phishing resistance depends on origin binding and on every recovery path that can create a session.
An OTP output is short and temporary. Its real security depends on seed custody, moving-factor state, verification policy, session binding and recovery.
Signature verification fails as a security boundary when the verifier and the application resolve different meanings from the same document.