• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Incognia Finds Crypto Exchanges Rely Too Heavily on Passwords and SMS Security

March 29, 2022

Incognia is turning its attention from Onboarding to Authentication with the release of the second part of its Crypto Mobile App Friction Report. Part one arrived in February, and found that the majority of cryptocurrency platforms were not taking adequate steps to verify someone’s identity during the onboarding process.

Incognia Finds Crypto Exchanges Rely Too Heavily on Passwords and SMS Security

With part two, Incognia is suggesting that the industry’s standards are just as lax when authenticating users after an account has been created. In that regard, the Authentication report looked at 21 leading cryptocurrency apps (15 exchanges and six wallets), and discovered that every single one still relies on either a password or a PIN as its primary authentication method. The majority (13 out of 15) of the exchanges do support some form of optional multi-factor authentication, though in most cases (nine out of 13) that second factor is a one-time password sent through an SMS message.

That raises serious concerns about crypto security, since SMS OTPs can be intercepted, and are vulnerable to social engineering. The NIST has designated SMS passcodes as a restricted authentication factor as a result of those shortcomings, and the continued reliance on SMS in cryptocurrency increases the risk of theft and fraud for individual end users.

Having said that, the report does offer some cause for optimism. Most (85 percent) of the exchanges allow users to replace their passwords with some kind of biometric authentication factor to increase their level of security.

The Incognia report also looked at password resets and new device logins, noting that there is a higher risk of account takeovers if those processes are not secure. Unfortunately, many of the exchanges are once again relying on SMS OTPs to protect people’s accounts. Some exchanges have opted for email Magic Links as an alternative, while crypto wallets prefer to use a 12-word seed phrase for device transfers. Seed phrases are effective, but they can be hard to remember and there is a risk that people could lose access to their wallets and their crypto reserves.

As it stands, cybercriminals stole $14 billion worth of cryptocurrency in 2021, while the amount held in illicit accounts jumped 360 percent to $11 billion. That poses a major problem as crypto usage increases, to the tune of 100 million app downloads in the fourth quarter of last year. Coinbase, FTX, Cash App, and Crypto.com were some of the apps looked at in Incognia’s report.

Filed Under: Industry News Tagged With: Biometric, biometric authentication, biometrics, crypto, Crypto Mobile App Friction Report, crypto theft, cryptocurrency, cryptocurrency exchanges, cybersecurity, Incognia, One Time Passcodes, passwords, SMS OTPs

Related News & Articles

The End of Catfishing – The Meet Group Integrates FaceTec’s Biometrics for Safer Online Dating

Samsung Oddly Silent on Security in S10 Lite, Note10 Lite Announcement

Yubico’s Latest Security Key Line is FIDO2-Ready

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • TSA to Expand MDL Pilot to Puerto Rico, Tennessee Airports
  • OECD Issues Draft Recommendation for Digital ID, Invites Comment
  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld