Why sign in to the Community?

  • Submit a question
  • Check your notifications
Sign in to the Community or Sign in to TurboTax and start working on your taxes
Level 1
posted Feb 24, 2023 4:08:49 PM

How do I disable SMS authentication completely, but leave two-factor authentication enabled?

SMS is not a secure protocol. As long as a text message can be used to authenticate, my account cannot be secure. I use two-factor authentication, and I have already set it up. Sadly, the site still wants to use texting as a fallback option and I do not want that.

0 3 697
3 Replies
Intuit Alumni
Feb 25, 2023 10:57:30 AM

Often a verification code is provided to the user via text message or automated phone call. Please see this Help Article for more details.

Level 1
Feb 25, 2023 1:08:44 PM

Thank you for the response. This is the exact behavior I wish to remove. Signing in with a text message might be okay for a casual games website or social platform, but is grossly inappropriate for websites that collect, store, process, and display extremely sensitive and valuable financial data.

 

Did you know that SMS Authentication is illegal for banking websites in some countries?

 

This website does have actual 2FA (code generator app) capability. I had to use it to sign in to write this reply. There is no good reason for me to fall back to text messages. SMS is the weak link in a strong chain; being able to bypass my code generator with a text message is not acceptable security and makes everyone more vulnerable.

Level 1
Dec 5, 2024 9:53:54 PM

Does Intuit care about cybersecurity?  No legitimate financial website still forces their users to use SMS text message as an option for 2FA/MFA.  This should make the Inuit Chief Information Security Officer (CISO) very queasy.