Why we do not use SMS codes

Which second factor privymail.eu uses instead of SMS codes, why it works without a phone number and what it does not protect.

privymail.eu sends no codes by SMS, and a phone number is not mandatory. One-time codes from an app and passkeys serve as the second factor, that is, as a second proof alongside the password. For emergencies there are recovery codes.

A phone number is not a key

A code by SMS seems convenient: no app, no set-up, the phone is there anyway. As proof of identity it is worth little, for three reasons.

  • The number is not firmly yours. A mobile operator can transfer it to another SIM card. Whoever convincingly poses as you there gets your number and with it your codes.
  • The code travels through other hands. An SMS passes through the mobile network and usually through a delivery service. Both can read it, and both learn when a sign-in code went to which number.
  • The number is a personal identifier. It ties a mailbox to a mobile contract and so, in most cases, to a name.

For us there would be more: to send SMS, we would have to integrate a delivery service and store your number. Our principle is different: data we do not hold can be neither lost nor handed over by us.

Two factors without a phone number. Plus codes for emergencies.

SMS codeOne-time code from an appPasskey
Needs a phone numberyesnono
Is sent to youyesno, it is generated on your deviceno
Can be phished on a fake pageyesyesno
At privymail.eudoes not existsecond factorsecond factor
  • One-time codes from an app. The method is called TOTP and is specified in RFC 6238. During set-up, an app on your device receives a secret from the service. After that, both compute the same short code from this secret and the time of day, and the code is valid only briefly. Nothing is sent in the process. Each code is valid only once, and the secret is stored encrypted on our side, with a key outside the database.
  • Passkeys. A passkey is a key pair: the private part stays on your device or in your password manager, and the service stores only the public part. With us, passkeys are a second factor, not a replacement for the password: access to the key for your stored mail depends on the password, and a passkey cannot provide it.
  • Recovery codes. Once an account is fully set up, the service shows a set of recovery codes, and only at that one moment. Each code is valid once and replaces exactly one factor: the second factor at sign-in or the forgotten password. If an account has a second factor, resetting the password additionally requires that factor or a second code. A new set can be issued; the old codes then expire.

The second factor is voluntary. It can only be set up once you have confirmed that the recovery codes are saved.

What it costs

  • Set-up. Setting up an app or creating a passkey is more work than typing in a number.
  • No reset by SMS. We have no master key. Anyone who loses the password and all recovery codes loses access to the account; only a mail app that is already set up keeps reading with its app password. Anyone who loses the password and the second factor at the same time needs two codes.
  • Abuse is slowed in a different way. Without a phone number, a common hurdle against accounts created in bulk is missing. A computational puzzle takes its place, together with limits.

What it does not solve

  • Real-time phishing. A fake sign-in page can intercept a one-time code and pass it on at once, just like an SMS code. A passkey is bound to the genuine address of the website and cannot be phished that way.
  • The key to your mail. The second factor protects sign-in, changes to the password and the factors, and the creation of app passwords, not the key. Anyone who knows your password and also holds copies of our database and of the mail store needs no code.
  • Mail apps. An app password works without a second factor, because mail protocols have no second step.
  • Passkeys travel. A passkey contains your email address and an account identifier. Your device can store both and, depending on the provider, synchronise them to its cloud.

Further reading