Page 7 / 11
SIM cloning copies a card's secret keys; a SIM swap tricks your carrier into moving your number. Learn how they differ, which is the real threat today, and how to protect your codes.
A CAPTCHA is a challenge that tells humans from bots to block fake accounts and OTP bot abuse. Learn the main types, how it differs from a verification code, and why sites use both.
Passwordless authentication lets you log in without a password - using a passkey, biometric, security key, or one-time code. Learn how it works, its trade-offs, and how it compares to 2FA.
Vishing is voice phishing - a scam phone call that pressures you into revealing a password, verification code, or payment. Learn the scripts attackers use and how to stay safe.
SMS codes are usually delayed by the delivery path - carrier filtering, congestion, roaming, or grey routes - not your phone. Learn why codes lag and how to get them faster.
SMS is not end-to-end encrypted - texts travel as readable data through carrier networks and can be intercepted via SS7 or a SIM swap. Learn what that means for verification codes and when to upgrade.
A hardware security key proves your login with phishing-resistant cryptography; SMS 2FA sends a code that can be intercepted. Learn how they compare and when to use each.
Account takeover is when an attacker controls your account using a stolen password or a phished code, then locks you out. Learn the common attack paths and why a second factor stops most of them.
Spoofing fakes the caller ID or SMS sender so a call or text seems to come from a number that isn't the sender's - the trick behind many scams. Learn how it works and how it differs from number masking.
Step-up authentication asks for extra proof - like an SMS code - only when an action is risky, such as a large transfer or a new device. Learn how it balances security and friction.
Authentication proves who you are; authorization decides what you can do. Learn why identity comes first, where verification codes fit, and why the distinction matters for security.
When an authenticator app code keeps getting rejected, the cause is usually clock drift - your phone's time is out of sync. Learn the one-minute fix and why these codes aren't sent to you.
Number masking hides your real number behind a proxy so two people can talk without seeing each other's digits - like ride-share apps. Learn how it works and how it differs from a separate receiving number.
A text-enabled toll-free number sends SMS nationwide, and its carrier verification makes it reliable for high-volume codes. Learn how it compares to local and short codes, and what it means for receiving.
An unrequested code usually means someone is trying to access an account with your number - often because they have your password. Learn why the code is harmless until shared, and when to change your password now.
3D Secure is two-factor authentication for online card payments - the SMS code or app approval before a purchase completes. Learn how it works and why a stolen card number isn't enough.
CPaaS lets apps add SMS, voice, and verification via APIs instead of building telecom infrastructure. Learn what it is and why most codes you receive are sent through one.
Smishing is phishing by text - a scam SMS that tricks you into clicking a link or sharing a code. Learn the common lures and the simple rule that makes you immune.