Simple clear advice in plain English

Facebook and Dropbox in favour of SMS codes to stengthen security

Following a security breach in which passwords were stolen, Dropbox now sends a six-digit code via text message to a mobile phone

phone texts
Experts say SMS security codes are fine for some websites but not for online banking

More websites should ask customers to confirm their identification by using one-off security codes sent by text messages, rather than by only entering a username and password.

Andy Kemshall of security firm Securenvoy warned that a study of security professionals found 42 per cent believe "the average kid could crack most end user's passwords."

Read more: Security news | Security software reviews

He said the second-factor authenticaiton process of confirming a transaction or a person's identity using code sent via text messages is a simpler version of the system many online banks have tried, which uses a card reader.

"Even if a hacker has found out your password, they won't have your phone. If your phone is stolen, the criminal is unlikely to know your password."

Recently cloud storage service Dropbox has introduced a two-stage sign-in process for its online storage service,

Following a security breach in which passwords were stolen, Dropbox now sends a six-digit code via text message to a mobile phone, which is entered after the username and password.

The system will also work through apps for iPad and iPhone, Blackberry, Windows Phone 7 and Android devices.

However, Oren Kedem, at security firm Trusteer, disagrees that two-factor authentication using SMS is inherently safe.

"SMS authentication is insecure as there are multiple ways it could be compromised. Some malicious software can hide, read and generate texts on mobile devices," he warned.

Rik Ferguson of Trend Micro also agreed with two-factor authentication sent by text being used for online banking.

"The question is not only about verifying the person initially making the transaction but is the transaction itself valid?

"For example you could be sending £50 to your son's bank account online using the code, but if you had malware that allowed a man-in-the-middle attack, the hacker could change that from £50, to £500 and direct the money to a different account.It's ok for sites such as drop box but it's not fail safe.

"It should certainly never be used for online banking because we have seen so much mobile malware used to bypass this form of security," he said.

Reader Comments

Not everybody has mobile phones....

The problem is not everybody has mobile phones, so people without mobile phones will be locked out of using Dropbox etc.

Posted by Josh, 07 Sep 2012

Answer for Josh

Hi Josh I can put your mind at rest somewhat as you are not forced to use a mobile phone to access Dropbox; the new two step sign in process is not enabled by default, you have to turn it on. Speaking personally for a moment, you can pick up a pay as you go mobile for around £10 from Tesco. I'd consider that a reasonable cost for the increased security. Of course, that doesn't help if you're in an area with no mobile signal. The Dropbox website offers some mobile apps that don't require a signal to work https://www.dropbox.com/help/363/en#2fa-apps although you will need a smartphone or tablet with a camera I hope that's helpful. Kind regards Tim

Posted by Tim Smith, 07 Sep 2012

   

Add your comment

Please keep comments constructive and free from abuse of any kind and swearing. If you wish to link to a product or service online, please do so in such a way that makes it clear that it is not spam. If you are connected to any such product you should make that clear.

We may use your comments in the magazine. We may edit your comments for clarity or to remove unacceptable material. We will attribute your comments but not share your email address.

We request your email address and record your Internet Address (IP address) in order to block spam from our site. We will never share this information without your permission.

All comments are reviewed by the Computeractive Team before being published. Please bear with the slight delay this causes, you don't need to post more than once.

Click here to read our Privacy Policy

Click here to read our site Terms & Conditions

Related articles

w-381-securejava-1

How to disable Java on a PC, Mac and in a web browser

Get rid of the plug-in from Windows, OS X, Linux, Internet Explorer, Chrome, Firefox and Safari

Java logo

Java flaw poses security risk to Windows, Mac and Linux

Users urged to disable Java as criminals exploit flaws to spread malware

Dropbox beefs up security

Content Recommendation

Question & Answer

Q.Why is Windows Backup skipping files?

> Read the answer

Q.Why do my scanned documents display gibberish?

> Read the answer

Q.How can I convert MTS files to edit in Windows Movie...

> Read the answer

Best deals on the web

img

Samsung NP350E7C-A04UK

£349.99- Buy it now

img

Toshiba Satellite C850D-11Q (PSCC2E-00R00JEN)

£279.97- Buy it now

img

Lenovo G580 (MAANJUK)

£379.99- Buy it now

Updating your subscription status Loading

Most popular articles

No matching document

Poll

Do you have Windows 8?

Jargon Buster

Computing terms explained in plain English

CPU

Central Processing Unit. Another term for a computer processor.

Great shopping deals from Computeractive

Information currently unavailable