Alternatives to SMS-Based OTPs for Authentication | India Business News - Times of India (2024)

MUMBAI: RBI has asked regulated entities like banks to look at alternatives to SMS-based one-time passwords for second-factor

authentication

. While there are alternatives, a mobile

phone

is central to all of them.
Bankers say that OTPs are susceptible to 'social engineering'

frauds

where one manages to get the customer to divulge the password or obtains the same through a SIM swap.

The most common

alternative

to

OTP

is an authenticator app that requires the user to obtain a password from another application on the phone. Service providers have developed other options as well like tokens within the mobile app. While this establishes the provenance of the message, it still needs a phone.
Route Mobile, which provides a communication platform as a service, sends nearly four billion OTPs every month on behalf of various service providers. "The increase in digital adoption also increases the potential for digital frauds. We are seeing a gap between the emerging markets, which are seeing high growth without any discussion on the rising frauds," Rajdipkumar Gupta, MD & CEO of Route Mobile. He said the rising frauds have prompted the company to launch TruSense division under Route Mobile UK to thwart identity theft.

TruSense has introduced OTP-less authentication, where the service provider will have a direct data connection with the user's device, identify the number, and exchange a token with the device without the user having to enter an OTP. According to David Vigar, executive VP in charge of digital identity, biometrics are not a good standalone authentication option as developments in AI have brought in a new risk of deepfakes bypassing facial recognition.
"For the Indian market, the mobile phone is the best identifier as the customer must verify their identity before obtaining a connection. Emails are not as good as it is easy to generate fake email identity. Also, anyone can generate an email without KYC," said Vigar.

Alternatives to SMS-Based OTPs for Authentication | India Business News - Times of India (2024)

FAQs

What are the alternatives to SMS OTP? ›

The most common alternative to OTP is an authenticator app that requires the user to obtain a password from another application on the phone. Service providers have developed other options as well like tokens within the mobile app. While this establishes the provenance of the message, it still needs a phone.

Which is the best OTP SMS service in India? ›

Fast2SMS is the best OTP SMS provider in India. It is one of the leading and fastest OTP bulk SMS provider in India. Fast2SMS provides bulk SMS OTP through a secured gateway and we ensure 100% safety of your transactions. We have build our reputation as a pioneer in the field of bulk SMS marketing.

What is the RBI OTP replacement? ›

Reserve Bank of India (RBI) is reportedly aiming to enhance digital payment security by replacing SMS-based OTPs with more secure authentication methods, such as authentication apps or biometric sensors on smartphones.

Is OTP mandatory in India? ›

Yes. The OTP has been introduced as additional safety feature for domestic transactions using credit or debit cards in India because of RBI. International transactions don't attract RBI diktats and thus there is no need for OTP.

What is replacing SMS? ›

Rich Communication Services (RCS) is a protocol aimed at replacing SMS messages with a richer text-message system that can transmit in-call multimedia, provide phonebook polling, and transmit other types of content.

What is the difference between mobile based OTP and SMS OTP? ›

TOTP-based 2FA is considered to be more secure than SMS-based 2FA because it is less susceptible to intercepts and spoofing. Additionally, TOTP-based 2FA does not rely on a phone number, so it can be used with any device that has the app installed.

Can I get OTP outside India? ›

Yes. You'll need to activate international roaming on your mobile phone before you travel overseas in order to receive the One-Time Pin (OTP). Contact your network provider as SMSs may incur an additional cost.

What is the difference between transactional SMS and OTP SMS? ›

Voice Backup – While OTP SMS service comes with a voice backup, Transactional SMS does not. For instance, SendOTP - MSG91 OTP platform - comes with an extra set of guaranteed delivery in form of a voice call backup; so if ever (99.99% it doesn't) an OTP fails the message is delivered via a voice call at no extra cost.

Can I receive OTP in USA? ›

Yes, as long as u have validity on ur sim! Yes u will receive otp s in usa without any pack...... but u need to activate international roaming for free by calling customer care.....

What is the new name for OTP? ›

A one-time password (OTP), also known as a one-time PIN, one-time passcode, one-time authorization code (OTAC) or dynamic password, is a password that is valid for only one login session or transaction, on a computer system or other digital device.

What is the new authentication of RBI? ›

“The Reserve Bank of India has prioritised security of digital payments, in particular the requirement of Additional Factor of Authentication (AFA) for making payments. No specific factor was mandated for authentication, but the digital payments ecosystem has primarily adopted SMS-based OTP as AFA.

What is a principle-based framework for authentication? ›

Definition: Principle-based authentication focuses on principles rather than rigid rules. Flexibility: It allows for various approaches based on context and risk. Context-Driven: Authentication adapts to the specific context of the transaction. Risk-Adaptive: The level of authentication adjusts based on risk factors.

Can international transaction happen without OTP? ›

International credit card transactions without OTP can be possible when the payment gateway you're using has permitted the same. Your credit or debit card can be used to make international purchases without an OTP authentication. This is because only domestic transactions are subject to the RBI's OTP authentication.

Does OTP work without internet? ›

The inputs to the TOTP algorithm are device time and a stored secret key. Neither the inputs nor the calculation require internet connectivity to generate or verify a token. Therefore a user can access TOTP via an app like Authy while offline.

Why is OTP not used? ›

In most cases, email accounts are protected solely by a username and password. This means that attackers can hijack the account with MITM or social engineering attacks that would drive users to give up their OTP to bad actors and lose access to their accounts.

How can I get OTP without messages? ›

In this case, you tie your mobile number to your account and click on the “Get a code” button. But many services, as an alternative, can also send a one-time password by email or use a 6-digit code generated in special authenticator applications, for example, Google OTP Authenticator.

Is SMS OTP better than authenticator? ›

You should use an authenticator app over SMS authentication because it is more secure and less likely to be intercepted by cybercriminals. Authenticator apps generate 2FA codes locally on a device, rather than sending them unencrypted over text message.

What are the two types of OTP? ›

There are two types of OTP: HOTP and TOTP.

Is email OTP the same as SMS OTP? ›

Email OTP authentication works the same way as SMS OTP which enables users to receive OTP codes through email. It also has the same primary function and can be used as an alternative channel for receiving OTP. For businesses, email authentication offers something that SMS OTP cannot.

Top Articles
How To Fill Out A Deposit Slip
Money Basics: Managing a Savings Account
Craigslist Myrtle Beach Motorcycles For Sale By Owner
How To Fix Epson Printer Error Code 0x9e
#ridwork guides | fountainpenguin
Davita Internet
Thor Majestic 23A Floor Plan
Metallica - Blackened Lyrics Meaning
Farepay Login
Mate Me If You May Sapir Englard Pdf
Shorthand: The Write Way to Speed Up Communication
The Potter Enterprise from Coudersport, Pennsylvania
What is the surrender charge on life insurance?
Immediate Action Pathfinder
2024 U-Haul ® Truck Rental Review
Kris Carolla Obituary
Quest Beyondtrustcloud.com
Illinois Gun Shows 2022
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
Aberration Surface Entrances
DBZ Dokkan Battle Full-Power Tier List [All Cards Ranked]
iZurvive DayZ & ARMA Map
E22 Ultipro Desktop Version
Army Oubs
Lehmann's Power Equipment
SF bay area cars & trucks "chevrolet 50" - craigslist
Sussur Bloom locations and uses in Baldur's Gate 3
Garnish For Shrimp Taco Nyt
THE FINALS Best Settings and Options Guide
Craiglist.nj
This Is How We Roll (Remix) - Florida Georgia Line, Jason Derulo, Luke Bryan - NhacCuaTui
Where to eat: the 50 best restaurants in Freiburg im Breisgau
Nikki Catsouras: The Tragic Story Behind The Face And Body Images
Halsted Bus Tracker
Craigslist Ludington Michigan
Clark County Ky Busted Newspaper
Wattengel Funeral Home Meadow Drive
Academy Sports New Bern Nc Coupons
The Angel Next Door Spoils Me Rotten Gogoanime
Ucsc Sip 2023 College Confidential
'Guys, you're just gonna have to deal with it': Ja Rule on women dominating modern rap, the lyrics he's 'ashamed' of, Ashanti, and his long-awaited comeback
814-747-6702
Willkommen an der Uni Würzburg | WueStart
A rough Sunday for some of the NFL's best teams in 2023 led to the three biggest upsets: Analysis
Accident On 40 East Today
Mail2World Sign Up
North Park Produce Poway Weekly Ad
Lsreg Att
Inside the Bestselling Medical Mystery 'Hidden Valley Road'
Philasd Zimbra
Koniec veľkorysých plánov. Prestížna LEAF Academy mení adresu, masívny kampus nepostaví
Latest Posts
Article information

Author: Patricia Veum II

Last Updated:

Views: 5849

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Patricia Veum II

Birthday: 1994-12-16

Address: 2064 Little Summit, Goldieton, MS 97651-0862

Phone: +6873952696715

Job: Principal Officer

Hobby: Rafting, Cabaret, Candle making, Jigsaw puzzles, Inline skating, Magic, Graffiti

Introduction: My name is Patricia Veum II, I am a vast, combative, smiling, famous, inexpensive, zealous, sparkling person who loves writing and wants to share my knowledge and understanding with you.