All articlesSecurity

SMS is not a second factor

A phone number can be hijacked at the carrier, and that hijack leaves no trace on the victim's side.

1 min read

One-time codes over SMS remain the most widely deployed second factor. They are also among the weakest, for a reason that has nothing to do with cryptography: the channel does not belong to the user.

A number can be ported at the carrier, on the strength of information a motivated attacker can assemble. From the network’s point of view the operation is legitimate, and the victim sees nothing until their phone loses signal.

What holds

A passkey or hardware key is bound to the domain that created it. A phishing site cannot use it, even with the user’s consent: the key refuses to sign for an origin that is not its own. That is not a matter of vigilance, it is a property of the protocol.

Where it comes back

Account recovery. That is where most rollouts quietly reintroduce SMS through a back door, undoing what they had just gained.

Talk to the Discovery AgentOpen in full
Command

Agent

Talk to the Discovery AgentFrame your project in eight questions.

Act

Dark themePin the site's appearance
Light themePin the site's appearance
System themeFollow the system preference again
Switch the site to FrenchFrançais
Labs — ProductFilter Labs by type
Labs — PrototypeFilter Labs by type
Labs — ResearchFilter Labs by type
Labs — Reset filtersClear every Labs filter
Journal — EngineeringFilter the Journal by category
Journal — SecurityFilter the Journal by category
Journal — Agent-NativeFilter the Journal by category
Journal — StudioFilter the Journal by category
Journal — Reset filtersClear every Journal filter
Tutorials — BeginnerFilter tutorials by level
Tutorials — IntermediateFilter tutorials by level
Tutorials — AdvancedFilter tutorials by level
Tutorials — Reset filtersClear every tutorials filter

Services

DiscoveryFrame the product before the first line of code, so the budget builds instead of correcting.
Product designAn interface that holds together, carried by a design system your developers can keep alive without us.
Web developmentA fast web application that holds up over time, with the tests and delivery chain to match.
Mobile developmentAn iOS and Android app from a single codebase, published on both stores.
Infrastructure & securityInfrastructure described as code, and Zero Trust access that does not rest on a text message.
Maintenance & evolutionA product kept current, watched and fixed, with someone who answers when it breaks.
Agent-Native Architecture AdvisoryMake an existing product agent-operable without rewriting it — and without opening more than it should.

Go to

YorroProduct engineering studio in Abidjan and Paris. We design, we build, we ship.
ServicesBuild a product end to end, or advise a team on its agent-native architecture.
LabsWhat the studio has built: products, prototypes and research, with where each one actually stands.
TutorialsStep-by-step guides drawn from real projects, grouped into tracks by topic.
JournalThe studio's notes and positions.
ContactDescribe your project; you get a framing back, not a boilerplate quote.
AboutWho runs the studio, how it works, and what it turns down.
Discovery AgentDescribe your project in conversation; the agent ticks the modules and produces an indicative estimate.

↑↓move↵runescclose