• About Us
  • Disclaimer
  • Contact Us
  • Privacy Policy
Sunday, June 14, 2026
mGrowTech
No Result
View All Result
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions
No Result
View All Result
mGrowTech
No Result
View All Result
Home Marketing Automation

We Replaced SMS Authentication With Email and Authenticator Apps — Here’s Why

Josh by Josh
October 3, 2025
in Marketing Automation
0
We Replaced SMS Authentication With Email and Authenticator Apps — Here’s Why


At Buffer, security has always been a balance: keeping our customers’ accounts safe while making login as seamless as possible for our global user base.

A few months ago, we made a decision that might sound surprising — we removed SMS-based two-factor authentication (2FA) and moved fully to email-based verification.

READ ALSO

Why LinkedIn Is the Most-Cited Source in AI Search (and What Your Business Should Do Next)

Which Social Media APIs Support Multi-Platform Posting? 6 Free + Paid Options

It wasn’t a change we took lightly. SMS has long been seen as the standard for 2FA. But over time, the drawbacks began to outweigh the benefits.

Here’s the story of how we got there, what the transition looked like, and what we’ve seen since.

Why we moved away from SMS

SMS-based 2FA has long been considered a security standard, but our team discovered several critical issues that made us reconsider:

Security vulnerabilities were more common than expected

SIM swapping attacks have become increasingly sophisticated, allowing attackers to hijack phone numbers and bypass SMS-based security.

Additionally, SMS messages travel unencrypted through multiple carriers, creating potential interception points.

Costs were scaling unsustainably

Every authentication SMS costs money, and with our growing user base, these seemingly small fees were adding up to hundreds of dollars monthly. International SMS rates made this even more challenging because our global user base.

International regulations and Sender ID requirements

SMS regulations vary dramatically by country, making compliance a constant challenge. Each country has different requirements for Sender IDs (the name that appears as the sender of an SMS), with some requiring pre-registration that can take weeks or months to complete.

For example, Singapore requires business verification documents, India demands a template pre-approval process, and the UAE has strict content restrictions.

Managing these requirements across 100+ countries created an enormous administrative burden that grew with each new regulation.

Additionally, failing to comply with any local regulation could result in messages being blocked, and ultimately customers being unable to log into Buffer.

Third-party dependencies created failure points

We relied on SMS gateway providers that occasionally experienced outages, delivery delays, or rate-limiting issues.

When these services go down, our users can not access their accounts—a critical problem for a tool that powers social media strategies worldwide.

Why email made more sense

When we looked for alternatives, we realized we already had a stronger option: email.

So instead of just removing SMS and calling it a day, we reimagined our authentication flow by incorporating email as another venue.

We implemented time-limited, single-use verification codes sent via email with enhanced security headers and encryption. Our email infrastructure, which we already maintained for notifications and updates, proved more reliable than third-party SMS gateways.

We also added rate limiting and anomaly detection to prevent abuse.

The unexpected benefits of switching to email

The transition delivered improvements beyond our initial expectations:

  • Security actually improved. Email accounts typically have more robust security options than phone numbers, including their own 2FA, recovery options, and activity monitoring. Users maintain better control over their email accounts than their phone numbers, which can be transferred without their knowledge.
  • Support tickets decreased. We saw a drop in authentication-related support requests. Users no longer struggled with international SMS delivery issues, changed phone numbers, or carrier-specific problems.
  • Development velocity increased. Our engineering team no longer needs to maintain integrations with the SMS provider, debug delivery issues across different carriers, or handle country-specific SMS regulations.

How we rolled out the switch

Making this transition required careful planning.

We communicated the change to users well in advance, explaining the security benefits and addressing concerns. We provided detailed migration guides and temporarily supported both methods during the transition period.

For users who strongly preferred SMS, we helped them understand that modern email security, especially with providers like Gmail or Outlook that offer robust protection, provides equal or better security than SMS.

We also enhanced our email delivery infrastructure to ensure reliability, implementing redundant email service providers and monitoring delivery rates closely.

The right choice for Buffer

This decision won’t be right for every company. Services that don’t have users’ email addresses or that serve demographics with limited email access might need different solutions. However, for Buffer — where every user already has an email account associated with their profile — this change aligned perfectly with our needs.

Three months after the transition, the results speak for themselves: a reduction in authentication-related support tickets, and significant monthly savings that we’ve reinvested in product improvements.

Looking ahead

Removing SMS authentication initially felt like swimming against the current, but it forced us to think critically about security theater versus actual security. Sometimes the “standard” solution isn’t the best solution for your specific context.

We’re continuing to explore additional authentication options, including support for hardware security keys. But our email-first approach has proven that simpler can indeed be more secure.


We share these kinds of stories because we know other teams face similar tradeoffs. Have you reconsidered a “standard” security practice recently? We’d love to hear from you on our social media! Find us @buffer everywhere and follow Carlos on LinkedIn here.



Source_link

Related Posts

Why LinkedIn Is the Most-Cited Source in AI Search (and What Your Business Should Do Next)
Marketing Automation

Why LinkedIn Is the Most-Cited Source in AI Search (and What Your Business Should Do Next)

June 12, 2026
Which Social Media APIs Support Multi-Platform Posting? 6 Free + Paid Options
Marketing Automation

Which Social Media APIs Support Multi-Platform Posting? 6 Free + Paid Options

June 11, 2026
How to Leverage Loyalty Programs for Brand Advocacy
Marketing Automation

How to Leverage Loyalty Programs for Brand Advocacy

June 11, 2026
How the Engineer Behind Coding Kitty Built a Full Video Publishing Engine on Buffer’s API
Marketing Automation

How the Engineer Behind Coding Kitty Built a Full Video Publishing Engine on Buffer’s API

June 11, 2026
Email marketing : pourquoi il reste le canal le plus puissant des CMO
Marketing Automation

Email marketing : pourquoi il reste le canal le plus puissant des CMO

June 9, 2026
We Built a Custom Workflow with the Buffer API — and Tripled Our X Impressions
Marketing Automation

We Built a Custom Workflow with the Buffer API — and Tripled Our X Impressions

June 8, 2026
Next Post
Google removes ICE-spotting app following Apple’s ICEBlock crackdown

Google removes ICE-spotting app following Apple’s ICEBlock crackdown

POPULAR NEWS

Trump ends trade talks with Canada over a digital services tax

Trump ends trade talks with Canada over a digital services tax

June 28, 2025
15 Trending Songs on TikTok in 2025 (+ How to Use Them)

15 Trending Songs on TikTok in 2025 (+ How to Use Them)

June 18, 2025
Communication Effectiveness Skills For Business Leaders

Communication Effectiveness Skills For Business Leaders

June 10, 2025
App Development Cost in Singapore: Pricing Breakdown & Insights

App Development Cost in Singapore: Pricing Breakdown & Insights

June 22, 2025
Comparing the Top 7 Large Language Models LLMs/Systems for Coding in 2025

Comparing the Top 7 Large Language Models LLMs/Systems for Coding in 2025

November 4, 2025

EDITOR'S PICK

Black Friday shopping makes Klarna and Affirm extra dangerous

Black Friday shopping makes Klarna and Affirm extra dangerous

November 21, 2025
Hire vs Outsource Development After Funding: What Scales

Hire vs Outsource Development After Funding: What Scales

March 20, 2026
Findings from Our AI Visibility Study

Findings from Our AI Visibility Study

September 4, 2025
Meet oLLM: A Lightweight Python Library that brings 100K-Context LLM Inference to 8 GB Consumer GPUs via SSD Offload—No Quantization Required

Meet oLLM: A Lightweight Python Library that brings 100K-Context LLM Inference to 8 GB Consumer GPUs via SSD Offload—No Quantization Required

September 29, 2025

About

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Follow us

Categories

  • Account Based Marketing
  • Ad Management
  • Al, Analytics and Automation
  • Brand Management
  • Channel Marketing
  • Digital Marketing
  • Direct Marketing
  • Event Management
  • Google Marketing
  • Marketing Attribution and Consulting
  • Marketing Automation
  • Mobile Marketing
  • PR Solutions
  • Social Media Management
  • Technology And Software
  • Uncategorized

Recent Posts

  • How to Choose a Crisis Management PR Agency
  • Why communicators are trading employee engagement for employee experience
  • Age, Gender, and Placement Restrictions
  • As AI companies race to go public, who else is along for the ride?
  • About Us
  • Disclaimer
  • Contact Us
  • Privacy Policy
No Result
View All Result
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions