medium
Single Answer
0Mikaela's company has implemented multifactor authentication using SMS messages to provide a numeric code. What is the primary security concern that Mikaela may want to express about this design?
Answer Options
A
SMS messages are not encrypted.
B
SMS messages can be spoofed by senders.
C
SMS messages may be received by more than one phone.
D
SMS messages may be stored on the receiving phone.
Correct Answer: A
Explanation
SMS messages are not encrypted, meaning that they could be sniffed and captured. While using two factors is more secure than a single factor, SMS is one of the less secure ways to implement two-factor authentication because of this. SMS messages can be spoofed, can be received by more than one phone, and are typically stored on the recipient's phone. The primary threat here, however, is the unencrypted message itself.