Ever Wonder Why Banks Are Slowly Getting Rid of OTPs?

A different kind of security is taking shape as banks look for better ways to verify customers.

All over the world, banks are changing how they protect online transactions. For years, one-time passwords, or OTPs, have been a common way to confirm a transaction. Usually, a six-digit code is sent by SMS. Some banks now send the code by email.

But OTPs have weaknesses.

β€’ SMS can be stolen. If a scammer takes control of your mobile number through a SIM swap, they can receive your OTP.

β€’ Email can also be hacked. If someone gets into your email account, they may see your OTP too.

β€’ Scammers can trick you into giving away the code. They may send a fake banking link and ask you to enter the OTP there.

Banks are using other ways to confirm transactions, including:

β€’ Fingerprint or Face ID

β€’ Approving a transaction in the banking app

β€’ Checking if the device is trusted

β€’ Passkeys, which can replace passwords and OTPs

What about the Philippines?

The change is already happening here.

Under a BSP rule, covered financial institutions are required to limit the use of SMS and email OTPs. Institutions handling complex electronic financial services and high-value online transactions must use stronger authentication methods for customer-initiated transactions. These can include biometric, behavioral, and passwordless authentication.

OTPs can still be used in some situations and for transactions that do not require the stronger authentication measures.

The OTP may slowly become a thing of the past.

⌨ ᴛʸᡖⁱⁿᡍ α΄α΅˜α΅— α΅’αΆ  ᡗʰᡉ Κ™Λ‘α΅˜α΅‰ α΅ˆα΅ƒΚ³α΅‰α΅ ᡐᡘ˒ⁱᢜ ᡇˑᡒᡍ

A Peace of War β€’ Darem Placer