Android has it, iOS needs it: Copy two-factor codes from text message

Jacob Kastrenakes, The Verge:

If you use two-factor authentication to secure your accounts, you’re probably used to this process: type in your password, wait for a text messaged code to arrive, memorize the code, and then type it back into the login prompt. It’s a bit of a pain.

Absolutely. Happens a lot. And this describes the process pretty well. Android has a fix:

In the new update, Messages will detect if you’re receiving a two-factor authentication code. When it does, it’ll add an option to the notification to copy the code, saving a step.

This is a step in the right direction. When a two-factor text is received, a copy button appears at the same time. Tap it, then paste it into the prompt.

It’d be nice to see this in iOS. But even better, it’d be nice to avoid the codes in the first place. The purpose of the codes is to prove that you have access to a verifying device. The codes themselves exist purely to give you a way to “move” the verification from the second device back to the original.

But iOS already does such an excellent job communicating between devices. I can copy on my iPhone, paste on my Mac, for example. And if the code is coming in on the same device that made the request, well that’s even easier.

What I’m suggesting is that Apple/Google work to create a verification service that eliminates all the friction. If I request a code on my Mac, popup a verification text message on my iPhone and, worst case, just make me tap “Yep” on an alert to verify the code, or “Nope” to let them know I didn’t make the request.

No reason for me to copy/paste or type in a number. Tap “Yep” and I’m in. Let the verification handshake happen in the background. Any reason this can’t be done?



10 thoughts on “Android has it, iOS needs it: Copy two-factor codes from text message”

  1. This is an incredibly bad idea. People get so many notifications, pop ups, and so on, that we all just mindlessly tap through to get rid of the notice. A bad actor could count on my not really looking at what I was tapping “yes” to and get into my account thanks to notification fatigue.

    Forcing you to do the tedious “read the code, type in the code” (or, if it’s all on the same device, “copy the code, paste the code”) ensures that you spend some brain cycles thinking about what you are doing, and helps protect you from saying “yes, this is me” to someone who is not you trying to get into your account.

  2. two factor authentication with sms is insecure, so automating it sounds like asking for trouble. Apple has its own 2fa implemented that does not need sms… maybe open that up as a sdk for ios apps ?

  3. At work, we use a system call Okta for single-sign on. Okta has an iPhone app for 2FA, and it can automatically push authentication requests from the service/web site requesting it to your phone. Then, you launch the app (or even better, force touch the notification) and hit “Accept”, and it logs you in without ever having to enter a code.

    I’d like to see Apple open like that up to developers, both as an iOS SDK and a back-end API for web sites to us.

  4. We use Okta Verify at work as well. It’s fantastic. Log into the portal, I get a push notification from Okta. I can hit “Accept” from the notification, and even from the Apple Watch. I don’t even have to get my phone out.

    Another thing that helps in this – if you can set up your service to use a non-SMS version of 2-factor, 1Password (and others, maybe) do this. Use the 1Password extenstion to input the username and password, and the 2-factor code is automatically placed on your clipboard.

    SMS 2-factor is easily spoofed, so if you have the option to use an app (Okta, Authy, 1Pass, etc.) to generate the code, you’re better off.

  5. How do you make an API that “automatically gets the code from some other device” and is not itself an attack vector?

    Tricky if not impossible, unless you can know both devices are correctly authenticated already (Apple probably can between Apple devices).

    (And Apple’s already reasonably clever about it between Apple devices, for Apple’s stuff.

    Almost all my SMS auth cases are for web logins for Important Services that aren’t in an app, and I really have no confidence in opening that up to auto-auth APIs.)

    Friction and security are arguably inseparable.

  6. Two Factor codes via text is a weak link for 2 factor authentication. As has happened before, someone can try and gain control of your phone account, issue a new SIM and get your authentications. Better is authentication with an authenticator app like google authenticator, etc. I personally use 1 password and the built in authenticator (one time passcode) when avail over text authentication. I wish more places offered using authenticator vs texting.

  7. This seems like a bad idea to me. If I had an android I would want to shut that shit off. Companies using SMS texts as 2FA need to fix their 2FA systems not have Google or Apple make it easier to copy the code.

  8. Umm … isn’t that what the Google Prompt second-factor option is for? (Not to mention that SMS isn’t a very secure channel in the first place.)

  9. We use Duo auth at work for this; heck, the Duo app runs on my watch…I enter my password on the Mac, wait for the prompt to pop up on the watch . tap ‘Accept’ and I’m in.

Leave a Reply

Your email address will not be published. Required fields are marked *