Alternatives to SMS-Based OTPs for Authentication | India Business News - Times of India (2024)

MUMBAI: RBI has asked regulated entities like banks to look at alternatives to SMS-based one-time passwords for second-factor

authentication

. While there are alternatives, a mobile

phone

is central to all of them.
Bankers say that OTPs are susceptible to 'social engineering'

frauds

where one manages to get the customer to divulge the password or obtains the same through a SIM swap.

The most common

alternative

to

OTP

is an authenticator app that requires the user to obtain a password from another application on the phone. Service providers have developed other options as well like tokens within the mobile app. While this establishes the provenance of the message, it still needs a phone.
Route Mobile, which provides a communication platform as a service, sends nearly four billion OTPs every month on behalf of various service providers. "The increase in digital adoption also increases the potential for digital frauds. We are seeing a gap between the emerging markets, which are seeing high growth without any discussion on the rising frauds," Rajdipkumar Gupta, MD & CEO of Route Mobile. He said the rising frauds have prompted the company to launch TruSense division under Route Mobile UK to thwart identity theft.

TruSense has introduced OTP-less authentication, where the service provider will have a direct data connection with the user's device, identify the number, and exchange a token with the device without the user having to enter an OTP. According to David Vigar, executive VP in charge of digital identity, biometrics are not a good standalone authentication option as developments in AI have brought in a new risk of deepfakes bypassing facial recognition.
"For the Indian market, the mobile phone is the best identifier as the customer must verify their identity before obtaining a connection. Emails are not as good as it is easy to generate fake email identity. Also, anyone can generate an email without KYC," said Vigar.

Alternatives to SMS-Based OTPs for Authentication | India Business News - Times of India (2024)

FAQs

What are the alternatives to SMS OTP? ›

The most common alternative to OTP is an authenticator app that requires the user to obtain a password from another application on the phone. Service providers have developed other options as well like tokens within the mobile app. While this establishes the provenance of the message, it still needs a phone.

Which is the best OTP SMS service in India? ›

Fast2SMS is the best OTP SMS provider in India. It is one of the leading and fastest OTP bulk SMS provider in India. Fast2SMS provides bulk SMS OTP through a secured gateway and we ensure 100% safety of your transactions. We have build our reputation as a pioneer in the field of bulk SMS marketing.

What is the RBI OTP replacement? ›

Reserve Bank of India (RBI) is reportedly aiming to enhance digital payment security by replacing SMS-based OTPs with more secure authentication methods, such as authentication apps or biometric sensors on smartphones.

Is OTP mandatory in India? ›

Yes. The OTP has been introduced as additional safety feature for domestic transactions using credit or debit cards in India because of RBI. International transactions don't attract RBI diktats and thus there is no need for OTP.

What is replacing SMS? ›

Rich Communication Services (RCS) is a protocol aimed at replacing SMS messages with a richer text-message system that can transmit in-call multimedia, provide phonebook polling, and transmit other types of content.

What is the difference between mobile based OTP and SMS OTP? ›

TOTP-based 2FA is considered to be more secure than SMS-based 2FA because it is less susceptible to intercepts and spoofing. Additionally, TOTP-based 2FA does not rely on a phone number, so it can be used with any device that has the app installed.

Can I get OTP outside India? ›

Yes. You'll need to activate international roaming on your mobile phone before you travel overseas in order to receive the One-Time Pin (OTP). Contact your network provider as SMSs may incur an additional cost.

What is the difference between transactional SMS and OTP SMS? ›

Voice Backup – While OTP SMS service comes with a voice backup, Transactional SMS does not. For instance, SendOTP - MSG91 OTP platform - comes with an extra set of guaranteed delivery in form of a voice call backup; so if ever (99.99% it doesn't) an OTP fails the message is delivered via a voice call at no extra cost.

Can I receive OTP in USA? ›

Yes, as long as u have validity on ur sim! Yes u will receive otp s in usa without any pack...... but u need to activate international roaming for free by calling customer care.....

What is the new name for OTP? ›

A one-time password (OTP), also known as a one-time PIN, one-time passcode, one-time authorization code (OTAC) or dynamic password, is a password that is valid for only one login session or transaction, on a computer system or other digital device.

What is the new authentication of RBI? ›

“The Reserve Bank of India has prioritised security of digital payments, in particular the requirement of Additional Factor of Authentication (AFA) for making payments. No specific factor was mandated for authentication, but the digital payments ecosystem has primarily adopted SMS-based OTP as AFA.

What is a principle-based framework for authentication? ›

Definition: Principle-based authentication focuses on principles rather than rigid rules. Flexibility: It allows for various approaches based on context and risk. Context-Driven: Authentication adapts to the specific context of the transaction. Risk-Adaptive: The level of authentication adjusts based on risk factors.

Can international transaction happen without OTP? ›

International credit card transactions without OTP can be possible when the payment gateway you're using has permitted the same. Your credit or debit card can be used to make international purchases without an OTP authentication. This is because only domestic transactions are subject to the RBI's OTP authentication.

Does OTP work without internet? ›

The inputs to the TOTP algorithm are device time and a stored secret key. Neither the inputs nor the calculation require internet connectivity to generate or verify a token. Therefore a user can access TOTP via an app like Authy while offline.

Why is OTP not used? ›

In most cases, email accounts are protected solely by a username and password. This means that attackers can hijack the account with MITM or social engineering attacks that would drive users to give up their OTP to bad actors and lose access to their accounts.

How can I get OTP without messages? ›

In this case, you tie your mobile number to your account and click on the “Get a code” button. But many services, as an alternative, can also send a one-time password by email or use a 6-digit code generated in special authenticator applications, for example, Google OTP Authenticator.

Is SMS OTP better than authenticator? ›

You should use an authenticator app over SMS authentication because it is more secure and less likely to be intercepted by cybercriminals. Authenticator apps generate 2FA codes locally on a device, rather than sending them unencrypted over text message.

What are the two types of OTP? ›

There are two types of OTP: HOTP and TOTP.

Is email OTP the same as SMS OTP? ›

Email OTP authentication works the same way as SMS OTP which enables users to receive OTP codes through email. It also has the same primary function and can be used as an alternative channel for receiving OTP. For businesses, email authentication offers something that SMS OTP cannot.

Top Articles
How To Get Old Bank Statements From A Closed Account - DocuClipper
Declined business bank account alternatives | Merchant Advice Service
Palm Coast Permits Online
Housing near Juneau, WI - craigslist
Couchtuner The Office
Voordelige mode in topkwaliteit shoppen
Okatee River Farms
Buckaroo Blog
Seth Juszkiewicz Obituary
Garrick Joker'' Hastings Sentenced
Craigslist Greenville Craigslist
Syracuse Jr High Home Page
Ella Eats
Driving Directions To Atlanta
5808 W 110Th St Overland Park Ks 66211 Directions
Cooking Fever Wiki
Void Touched Curio
Nebraska Furniture Tables
Used Drum Kits Ebay
D10 Wrestling Facebook
Vanessa West Tripod Jeffrey Dahmer
Nail Salon Goodman Plaza
1-833-955-4522
Craigslistjaxfl
Officialmilarosee
Webcentral Cuny
Qhc Learning
Why do rebates take so long to process?
Elbert County Swap Shop
Prep Spotlight Tv Mn
Local Collector Buying Old Motorcycles Z1 KZ900 KZ 900 KZ1000 Kawasaki - wanted - by dealer - sale - craigslist
Sony Wf-1000Xm4 Controls
Planned re-opening of Interchange welcomed - but questions still remain
WOODSTOCK CELEBRATES 50 YEARS WITH COMPREHENSIVE 38-CD DELUXE BOXED SET | Rhino
Ridge Culver Wegmans Pharmacy
Kristen Hanby Sister Name
The Boogeyman Showtimes Near Surf Cinemas
AI-Powered Free Online Flashcards for Studying | Kahoot!
3400 Grams In Pounds
Dee Dee Blanchard Crime Scene Photos
Doordash Promo Code Generator
Mbfs Com Login
Anthem Bcbs Otc Catalog 2022
Celsius Claims Agent
Online-Reservierungen - Booqable Vermietungssoftware
Bmp 202 Blue Round Pill
Dyi Urban Dictionary
Minute Clinic Mooresville Nc
Wvu Workday
Suzanne Olsen Swift River
Bumgarner Funeral Home Troy Nc Obituaries
Haunted Mansion Showtimes Near The Grand 14 - Ambassador
Latest Posts
Article information

Author: Patricia Veum II

Last Updated:

Views: 5849

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Patricia Veum II

Birthday: 1994-12-16

Address: 2064 Little Summit, Goldieton, MS 97651-0862

Phone: +6873952696715

Job: Principal Officer

Hobby: Rafting, Cabaret, Candle making, Jigsaw puzzles, Inline skating, Magic, Graffiti

Introduction: My name is Patricia Veum II, I am a vast, combative, smiling, famous, inexpensive, zealous, sparkling person who loves writing and wants to share my knowledge and understanding with you.