Google Is Finally Upgrading SMS Logins for Gmail Users – Here’s Why
Google is revolutionizing the way users log in to their accounts, introducing a safer and more secure authentication method. For years, SMS text messages have been the go-to method for delivering security codes to verify identities. However, this approach is far from foolproof. Google is now set to phase out SMS-based two-factor authentication (2FA) for Gmail users, replacing it with a more secure QR code verification system . This move aims to eliminate risks associated with intercepted or stolen codes, offering users a more robust way to protect their accounts.
In recent years, the tech industry has been gradually shifting away from traditional passwords and SMS-based 2FA, embracing code-generating apps and app-less authentication methods like passkeys. According to a report by Forbes, Google’s new QR code verification system is expected to roll out over the coming months, marking a significant step forward in enhancing account security and reducing vulnerabilities tied to SMS-based systems, such as phishing attacks and SIM-swapping fraud.
In an interview with Forbes, Gmail spokesperson Ross Richendrfer explained the rationale behind this change: “Just like we want to move past passwords with the use of things like passkeys, we want to move away from sending SMS messages for authentication.”
Currently, Google uses a six-digit code sent via SMS for verification. With the new update, Gmail users will instead scan a QR code displayed on their screen using their smartphone cameras to verify their identity. Richendrfer elaborated, “Over the next few months, we'll be reimagining how we verify phone numbers. Specifically, instead of entering your number and receiving a 6-digit code, you will see a QR code being displayed, which you need to scan with the camera app on your phone.”
SMS-based authentication has long been criticized for its security flaws. Richendrfer highlighted several challenges, including the susceptibility of SMS codes to phishing, the reliance on users having access to their devices, and the security practices of mobile carriers. “If a fraudster can easily trick a carrier into getting hold of a user's phone number, any security value of SMS goes away,” he said.
Google has also observed newer scams, such as “traffic pumping,” where fraudsters exploit SMS systems to generate revenue. Richendrfer explained, “It’s where fraudsters try to get online service providers to originate large numbers of SMS to numbers they control, thereby getting paid every time one of these messages is delivered.”
By transitioning to QR code verification, Google aims to address these vulnerabilities and provide users with a more secure authentication method. “SMS codes are a source of heightened risk for users. We are pleased to introduce an innovative new approach to shrink the surface area for attackers and keep users safer from malicious activity,” Richendrfer concluded.
This shift underscores Google’s commitment to staying ahead of cyber threats and ensuring user accounts remain secure in an increasingly digital world. As the tech giant continues to innovate, the move away from SMS-based authentication marks a significant milestone in the evolution of online security.
In recent years, the tech industry has been gradually shifting away from traditional passwords and SMS-based 2FA, embracing code-generating apps and app-less authentication methods like passkeys. According to a report by Forbes, Google’s new QR code verification system is expected to roll out over the coming months, marking a significant step forward in enhancing account security and reducing vulnerabilities tied to SMS-based systems, such as phishing attacks and SIM-swapping fraud.
In an interview with Forbes, Gmail spokesperson Ross Richendrfer explained the rationale behind this change: “Just like we want to move past passwords with the use of things like passkeys, we want to move away from sending SMS messages for authentication.”
You may also like
- Elon Musk teases Grok 4.6 and 4.7 as AI race heats up
- Will continue to invest in India: Unilever CEO Fernando Fernandez
- What made California's largest AI datacenter that had promised not to use Colorado River water to file lawsuit to access 280 million gallons of river water meant for farming
- Europe's most valuable company loses millions after what some analysts say 'nightmare scenario' for ASML due to China's ...
- WhatsApp rolls out web calling and new call features across devices
Currently, Google uses a six-digit code sent via SMS for verification. With the new update, Gmail users will instead scan a QR code displayed on their screen using their smartphone cameras to verify their identity. Richendrfer elaborated, “Over the next few months, we'll be reimagining how we verify phone numbers. Specifically, instead of entering your number and receiving a 6-digit code, you will see a QR code being displayed, which you need to scan with the camera app on your phone.”
SMS-based authentication has long been criticized for its security flaws. Richendrfer highlighted several challenges, including the susceptibility of SMS codes to phishing, the reliance on users having access to their devices, and the security practices of mobile carriers. “If a fraudster can easily trick a carrier into getting hold of a user's phone number, any security value of SMS goes away,” he said.
Google has also observed newer scams, such as “traffic pumping,” where fraudsters exploit SMS systems to generate revenue. Richendrfer explained, “It’s where fraudsters try to get online service providers to originate large numbers of SMS to numbers they control, thereby getting paid every time one of these messages is delivered.”
By transitioning to QR code verification, Google aims to address these vulnerabilities and provide users with a more secure authentication method. “SMS codes are a source of heightened risk for users. We are pleased to introduce an innovative new approach to shrink the surface area for attackers and keep users safer from malicious activity,” Richendrfer concluded.
This shift underscores Google’s commitment to staying ahead of cyber threats and ensuring user accounts remain secure in an increasingly digital world. As the tech giant continues to innovate, the move away from SMS-based authentication marks a significant milestone in the evolution of online security.





