Potential Pitfalls of Two Factor Authentication

  • Security.  Certain methods of 2FA can cause issues. For example, sending a one-time password or authentication code by SMS text message is not particularly secure. Mobile phones can be easily lost or stolen and as a result SMS messages can be intercepted or forwarded to another.
  • Support Issues.  It is unrealistic to expect helpdesk staff to be trained and have access to all mobile phones, so this approach only works if employees are limited to using just one or two types of phone.  Tokens can be expensive to purchase and can have costly administration overheads due to the resources required to manage and support them.
  • Tokens.  There can be an overhead in procuring the tokens, distributing them to customers, maintaining them and being able to replace them when lost or damaged
  • Cost.   Implications of costs of sending SMS messages.
  • Practicality.  Some methods for two-factor authentication remain impractical. Smartcards require smartcard-readers and tokens need software to be installed on any remote PC or laptop before they can be used.
  • Additional Hardware Requirement. Require users to carry additional equipment