Google is ditching SMS - and will now use QR codes for Gmail account authentication

Isometric demonstrating multi-factor authentication using a mobile device.
(Image credit: Shutterstock)

  • Google is removing SMS messages as an authentication option
  • It will be replaced with on-screen QR codes
  • Removing SMS authentication reduces the risk of phishing and fraud

Google is officially moving away from using SMS messages in its Gmail account two-factor authenticator.

Gmail spokesperson Ross Richendrfer told Forbes, “we want to move away from sending SMS messages for authentication” to “reduce the impact of rampant, global SMS abuse.”

SMS authentication codes can be easily intercepted by hackers simply by porting your phone number to a new device - just one of the many security issues plaguing SMS messages for authentication.

QR codes to replace Gmail SMS authentication

Google will instead introduce on-screen QR codes that will have to be scanned with your chosen authentication device in order to verify that it is actually you trying to log in. This potentially adds an extra layer of biometric security for those who use a facial recognition or fingerprint scan to access their device or applications.

QR codes will also solve two other concerns related to SMS authentication methods. The first being that QR codes are more phishing resistant, as there will no longer be a security code to share with an attacker. The second being the authentication will no longer be reliant on the phone service provider’s abuse and fraud protections.

Authentication will still be reliant on the user having access to their mobile device, but removes a significant amount of the risk of abuse. For Google, it is also a win, as it cuts down on threat actors being able to run ‘traffic pumping’ campaigns.

In these campaigns, criminals will abuse online service providers to generate a huge amount of SMS messages to phone numbers they control, allowing them to generate revenue through access charges and intercarrier compensation.

In the future, Google hopes to move to a fully passkey supported authenticator system, but the move from passwords to passkeys hasn’t been as fast as Google had hoped, despite their best efforts to convince users to make the switch.

You might also like

TOPICS
Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Google Pixel 9 Pro
Google Password Manager may be set to introduce a nuclear option for its Android app
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
Person using finger print authentication
Passwords out, passkeys in: The future of secure authentication
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring