This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Why not 2FA via SMS?

more options

Why can't 2-step authentication (for my Firefox Account) be done via SMS instead of requiring me to download another app? Isn't that how most other web apps handle it?

Why can't 2-step authentication (for my Firefox Account) be done via SMS instead of requiring me to download another app? Isn't that how most other web apps handle it?

Chosen solution

Originally two factor authentication was done via an SMS message with a code (not specifically by Mozilla, but in general). The reason that most companies are transitioning to using two factor authentication apps instead is for security.

As it turns out, it's fairly easy to hijack SMS text messages, which would make it easy for an attacker to gain access to your account, even though it's protected with two factor authentication.

Authentication apps don't suffer from this security flaw and since the majority of mobile devices are smart devices, it's usually not a big deal.

Another good thing about using an authentication app instead of SMS is that you can use a variety of devices, not just those that have a SIM card. It also allows you to use multiple different devices to authenticate your account. For example, if you don't have access to your smartphone, you can unlock your account with a computer if you have an authentication app setup on there.

Read this answer in context 👍 0

All Replies (1)

more options

Seçilmiş Həll

Originally two factor authentication was done via an SMS message with a code (not specifically by Mozilla, but in general). The reason that most companies are transitioning to using two factor authentication apps instead is for security.

As it turns out, it's fairly easy to hijack SMS text messages, which would make it easy for an attacker to gain access to your account, even though it's protected with two factor authentication.

Authentication apps don't suffer from this security flaw and since the majority of mobile devices are smart devices, it's usually not a big deal.

Another good thing about using an authentication app instead of SMS is that you can use a variety of devices, not just those that have a SIM card. It also allows you to use multiple different devices to authenticate your account. For example, if you don't have access to your smartphone, you can unlock your account with a computer if you have an authentication app setup on there.