<?xml version="1.0"?>
<oembed><version>1.0</version><provider_name>ValeurBit Infosec</provider_name><provider_url>https://valeurbit.com/blog</provider_url><author_name>ValeurBit</author_name><author_url>https://valeurbit.com/blog/author/valeurbit/</author_url><title>What Mistakes in implementing SMS authentication | ValeurBit Infosec</title><type>rich</type><width>600</width><height>338</height><html>&lt;blockquote class="wp-embedded-content" data-secret="smloYsxxu7"&gt;&lt;a href="https://valeurbit.com/blog/what-mistakes-in-implementing-sms-authentication/"&gt;What Mistakes in implementing SMS authentication&lt;/a&gt;&lt;/blockquote&gt;&lt;iframe sandbox="allow-scripts" security="restricted" src="https://valeurbit.com/blog/what-mistakes-in-implementing-sms-authentication/embed/#?secret=smloYsxxu7" width="600" height="338" title="&#x201C;What Mistakes in implementing SMS authentication&#x201D; &#x2014; ValeurBit Infosec" data-secret="smloYsxxu7" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" class="wp-embedded-content"&gt;&lt;/iframe&gt;&lt;script type="text/javascript"&gt;
/* &lt;![CDATA[ */
/*! This file is auto-generated */
!function(d,l){"use strict";l.querySelector&amp;&amp;d.addEventListener&amp;&amp;"undefined"!=typeof URL&amp;&amp;(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&amp;&amp;!/[^a-zA-Z0-9]/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret="'+t.secret+'"]'),o=l.querySelectorAll('blockquote[data-secret="'+t.secret+'"]'),c=new RegExp("^https?:$","i"),i=0;i&lt;o.length;i++)o[i].style.display="none";for(i=0;i&lt;a.length;i++)s=a[i],e.source===s.contentWindow&amp;&amp;(s.removeAttribute("style"),"height"===t.message?(1e3&lt;(r=parseInt(t.value,10))?r=1e3:~~r&lt;200&amp;&amp;(r=200),s.height=r):"link"===t.message&amp;&amp;(r=new URL(s.getAttribute("src")),n=new URL(t.value),c.test(n.protocol))&amp;&amp;n.host===r.host&amp;&amp;l.activeElement===s&amp;&amp;(d.top.location.href=t.value))}},d.addEventListener("message",d.wp.receiveEmbedMessage,!1),l.addEventListener("DOMContentLoaded",function(){for(var e,t,s=l.querySelectorAll("iframe.wp-embedded-content"),r=0;r&lt;s.length;r++)(t=(e=s[r]).getAttribute("data-secret"))||(t=Math.random().toString(36).substring(2,12),e.src+="#?secret="+t,e.setAttribute("data-secret",t)),e.contentWindow.postMessage({message:"ready",secret:t},"*")},!1)))}(window,document);
/* ]]&gt; */
&lt;/script&gt;
</html><description>Many online services use SMS as a user authentication mechanism.&#xA0;But small mistakes are made that will lead to big problems.&#xA0;This is what this article will be about. Introduction This authentication method is popular in b2c services, because it increases conversion, because the user does not need to remember passwords, come up with logins, but simply...</description></oembed>
