{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T19:29:48Z","timestamp":1775244588410,"version":"3.50.1"},"reference-count":30,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2020,8,31]],"date-time":"2020-08-31T00:00:00Z","timestamp":1598832000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2020,8,31]]},"abstract":"<jats:p>Despite their popularity and ease of use, SMS-based authentication tokens are arguably one of the least secure forms of two-factor authentication. This does not imply, however, that it is an invalid method for securing an online account. The current security landscape is very different from that of two decades ago. Regardless of the critical nature of an online account or the individual who owns it, using a second form of authentication should always be the default option, regardless of the method chosen. In the wake of a large number of leaks and other intrusions, there are many username and password combinations out there in the wrong hands that make password spraying attacks cheap and easy to accomplish.<\/jats:p>","DOI":"10.1145\/3424302.3425909","type":"journal-article","created":{"date-parts":[[2020,9,23]],"date-time":"2020-09-23T01:27:47Z","timestamp":1600824467000},"page":"37-60","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Security Analysis of SMS as a Second Factor of Authentication"],"prefix":"10.1145","volume":"18","author":[{"given":"Roger Piqueras","family":"Jover","sequence":"first","affiliation":[{"name":"Bloomberg"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,9,22]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Alfonsi S. 2016. Hacking your phone. CBS News; https:\/\/www.cbsnews.com\/video\/hacking-your-phone\/."},{"key":"e_1_2_1_2_1","unstructured":"Cimpanu C. 2018. Newer Diameter telephony protocol just as vulnerable as SS7. Bleeping Computer; https:\/\/www.bleepingcomputer.com\/news\/security\/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7\/."},{"key":"e_1_2_1_3_1","unstructured":"Coonce S. 2019. The most expensive lesson of my life: details of SIM port hack. Medium; https:\/\/medium.com\/coinmonks\/the-most-expensive-lesson-of-my-life-details-of-sim-port-hack-35de11517124."},{"key":"e_1_2_1_4_1","unstructured":"Cox J. 2020. Hackers are breaking directly into telecom companies to take over customer phone numbers. Motherboard Tech by Vice; https:\/\/www.vice.com\/en_us\/article\/5dmbjx\/how-hackers-are-breaking-into-att-tmobile-sprint-to-sim-swap-yeh."},{"key":"e_1_2_1_5_1","volume-title":"31st Chaos Communication Congress.","author":"Engel T.","year":"2014","unstructured":"Engel, T. 2014. SS7: Locate. track. manipulate. 31st Chaos Communication Congress."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the 22nd Usenix Security Symposium, 33?48; https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity13\/sec13-paper_golde.pdf.","author":"Golde N.","year":"2013","unstructured":"Golde, N., Redon, K., Seifert, J.-P. 2013. Let me answer that for you: exploiting broadcast information in cellular networks. In Proceedings of the 22nd Usenix Security Symposium, 33?48; https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity13\/sec13-paper_golde.pdf."},{"key":"e_1_2_1_7_1","unstructured":"Greenberg A. 2019. The SIM swap fix that the U.S. isn't using. Wired; https:\/\/www.wired.com\/story\/sim-swap-fix-carriers-banks\/."},{"key":"e_1_2_1_8_1","volume-title":"How Apple and Amazon security flaws led to my epic hacking. Wired","author":"Honan M.","year":"2012","unstructured":"Honan, M. 2012. How Apple and Amazon security flaws led to my epic hacking. Wired; https:\/\/www.wired.com\/2012\/08\/apple-amazon-mat-honan-hacking\/."},{"key":"e_1_2_1_9_1","unstructured":"Hunt T. 2018. Beyond passwords: 2FA U2F and Google Advanced Protection; https:\/\/www.troyhunt.com\/beyond-passwords-2fa-u2f-and-google-advanced-protection\/."},{"key":"e_1_2_1_10_1","unstructured":"Hunt T. 2020. Have i been pwned; https:\/\/haveibeenpwned.com\/."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354263"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753384"},{"key":"e_1_2_1_13_1","volume-title":"ShmooCon 2016 Proceedings; https:\/\/shmoo.gitbook.io\/2016-shmoocon-proceedings\/bring_it_on\/05_lte_security_and_protocol_exploits.","author":"Jover R. P.","year":"2016","unstructured":"Jover, R. P. 2016. LTE security and protocol exploits. ShmooCon 2016 Proceedings; https:\/\/shmoo.gitbook.io\/2016-shmoocon-proceedings\/bring_it_on\/05_lte_security_and_protocol_exploits."},{"key":"e_1_2_1_14_1","unstructured":"Jover R. P. 2016. LTE security protocol exploits and location tracking experimentation with low-cost software radio. CoRR (Computing Research Repository) abs\/1607.05171; https:\/\/arxiv.org\/abs\/1607.05171."},{"key":"e_1_2_1_15_1","unstructured":"Jover R. P. 2020. 5G protocol vulnerabilities and exploits. ShmooCon 2020; http:\/\/rogerpiquerasjover.net\/5G_ShmooCon_FINAL.pdf."},{"key":"e_1_2_1_16_1","volume-title":"Security and protocol exploit analysis of the 5G specifications","author":"Jover R. P.","unstructured":"Jover, R. P., Marojevic, V. 2019. Security and protocol exploit analysis of the 5G specifications. IEEE Access; https:\/\/ieeexplore.ieee.org\/stamp\/stamp.jsp?arnumber=8641117."},{"key":"e_1_2_1_17_1","volume-title":"Location leaks on the GSM air interface. 19th annual Network and Distributed System Security Symposium","author":"Kune D. F.","unstructured":"Kune, D. F., Koelndorfer, J., Hopper, N., Kim, Y. 2012. Location leaks on the GSM air interface. 19th annual Network and Distributed System Security Symposium; https:\/\/www-users.cs.umn.edu\/~hoppernj\/celluloc.pdf."},{"key":"e_1_2_1_18_1","volume-title":"16th Symposium on Usable Privacy and Security; https:\/\/www.ieee-security.org\/TC\/SPW2020\/ConPro\/papers\/lee-conpro20","author":"Lee K.","year":"2020","unstructured":"Lee, K., Kaiser, B., Mayer, J., Narayanan, A. 2020. An empirical study of wireless carrier authentication for SIM swaps. 16th Symposium on Usable Privacy and Security; https:\/\/www.ieee-security.org\/TC\/SPW2020\/ConPro\/papers\/lee-conpro20.pdf."},{"key":"e_1_2_1_19_1","volume-title":"IEEE Intelligent Network 2001 Workshop, 9?13","author":"Liu C.-H.","year":"2001","unstructured":"Liu, C.-H., Chang, Y.-C., Huang, N.-F., Ling, Y.-L., Jan, H.-J. 2001. CAMEL evolution and PPS evaluation. In IEEE Intelligent Network 2001 Workshop, 9?13. IEEE; https:\/\/ieeexplore.ieee.org\/document\/915288."},{"key":"e_1_2_1_20_1","unstructured":"Mitre Corporation. Exploit SS7 to redirect phone calls\/SMS. MITRE ATT&CK Framework; https:\/\/attack.mitre.org\/techniques\/T1449\/."},{"key":"e_1_2_1_21_1","unstructured":"New York State Department of Consumer Protection. ATT SIM-card switch scam; https:\/\/www.dos.ny.gov\/consumerprotection\/scams\/att-sim.html."},{"key":"e_1_2_1_22_1","volume-title":"Breaking GSM phone privacy. Black Hat USA","author":"Nohl K.","year":"2010","unstructured":"Nohl, K. 2010. Breaking GSM phone privacy. Black Hat USA; https:\/\/srlabs.de\/wp-content\/uploads\/2010\/07\/100729.Breaking.GSM_.Privacy.BlackHat1-1.pdf."},{"key":"e_1_2_1_23_1","volume-title":"27th Chaos Communication Congress; https:\/\/fahrplan.events.ccc.de\/congress\/2010\/Fahrplan\/events\/4208","author":"Nohl K.","year":"2010","unstructured":"Nohl, K., Munaut, S. 2010. Wideband GSM sniffing. In 27th Chaos Communication Congress; https:\/\/fahrplan.events.ccc.de\/congress\/2010\/Fahrplan\/events\/4208.en.html."},{"key":"e_1_2_1_24_1","volume-title":"Black Hat DC","author":"Perez D.","year":"2011","unstructured":"Perez, D., Pico, J. 2011. A practical attack against GPRS\/EDGE\/UMTS\/HSPA mobile data communications. In Black Hat DC; https:\/\/media.blackhat.com\/bh-dc-11\/Perez-Pico\/BlackHat_DC_2011_Perez-Pico_Mobile_Attacks-wp.pdf."},{"key":"e_1_2_1_25_1","volume-title":"Signaling System #7","author":"Russell T.","unstructured":"Russell, T. 2002. Signaling System #7, volume 2. New York, NY: McGraw-Hill."},{"key":"e_1_2_1_26_1","unstructured":"Shaik A. Borgaonkar R. 2019. New vulnerabilities in 5G networks. Black Hat 2019; https:\/\/i.blackhat.com\/USA-19\/Wednesday\/us-19-Shaik-New-Vulnerabilities-In-5G-Networks-wp.pdf."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23236"},{"key":"e_1_2_1_28_1","unstructured":"Third Generation Partnership Project (3GPP) Technical Specification Group Services and System Aspects. 2018. Security architecture and procedures for 5G system. 3GPP TS 33.501 V1.0.0; https:\/\/portal.3gpp.org\/desktopmodules\/Specifications\/SpecificationDetails.aspx?specificationId=3169."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1080\/10658980701824432"},{"key":"e_1_2_1_30_1","unstructured":"XKCD. Password strength; https:\/\/xkcd.com\/936\/."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3424302.3425909","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3424302.3425909","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:25Z","timestamp":1750197745000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3424302.3425909"}},"subtitle":["The challenges of multifactor authentication based on SMS, including cellular security deficiencies, SS7 exploits, and SIM swapping"],"short-title":[],"issued":{"date-parts":[[2020,8,31]]},"references-count":30,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,8,31]]}},"alternative-id":["10.1145\/3424302.3425909"],"URL":"https:\/\/doi.org\/10.1145\/3424302.3425909","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,31]]},"assertion":[{"value":"2020-09-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}