They remain unsuitable because they are readable, relayable, and often socially engineered through SIM swap, carrier compromise, or adversary-in-the-middle phishing. For sensitive actions, the control must prove possession through non-reusable cryptographic evidence rather than a secret that a user can copy or recite.
Why OTP delivery channels fail high-risk policy tests
SMS and voice OTPs are still useful for lower-assurance recovery or step-up cases, but they do not meet the bar for high-risk identity policies because the code itself is a transferable secret. A policy that must withstand phishing, interception, or targeted takeover needs a factor that is cryptographically bound to the session or relying party, not something a person can read out loud or forward.
That distinction matters because the control objective is not simply “a second step”, it is resistant proof of possession. In high-risk workflows, the attack surface includes SIM swap, voicemail abuse, call forwarding, phone-number recycling, telecom account compromise, and adversary-in-the-middle relays that can capture and reuse the OTP before the user notices.
The practical consequence is that OTPs behave more like a shared secret with delivery risk than a strong authenticator. They can reduce opportunistic abuse, but they do not reliably stop an attacker who has already gained temporary control of the channel or has convinced the user to disclose the code.
Why readable, relayable codes are a poor trust primitive
OTP weakness is structural. The code is short-lived, but it is still human-readable and manually transferable, which means the value being checked by the verifier is not bound to the device, the browser, or the transaction. Once the code leaves the trusted path, the defender loses the property that should matter most in a high-risk policy: proof that the same claimant who started the session is finishing it.
That is why phishing-resistant methods such as passkeys or security keys are preferred for privileged access, payment approvals, and recovery actions. They create an origin- and session-aware assertion that an attacker cannot simply relay over SMS or a voice call. For a practical comparison of common MFA paths, see MFA Guide and the phishing-resistant guidance in NIST SP 800-63 Digital Identity Guidelines.
Voice OTP adds a further reliability problem because it often depends on call routing, voicemail access, and carrier-side controls that the relying party does not own. Even when the number is correct, the caller may not be the verified person, and the policy decision still rests on a channel that was never designed to prove cryptographic possession.
What high-risk identity policy should require instead
High-risk identity policy should ask whether the factor survives interception, relay, and social engineering. If it does not, it belongs in a lower-assurance tier. The stronger alternative is a phishing-resistant authenticator, especially when the action can create financial loss, administrative takeover, or irreversible account changes. Where organisations are standardising the control set, Identity Security Posture Management (ISPM) Guide helps frame the right findings to track, while Identity Security Programme Guide is useful when the decision has to be operationalised across policy, exceptions, and ownership.
For organisations with mixed populations and legacy coverage, the right design pattern is not “ban OTP everywhere”, but “treat OTP as insufficient where the blast radius is high”. That usually means reserving SMS or voice only for low-risk fallback, or tightly constrained recovery, while requiring stronger authenticators for admin changes, payout approvals, enrolment changes, and account recovery resets.
If the policy is intended to withstand targeted attack, it should also account for the human factor. Attackers often do not break the channel first, they persuade the user to hand over the code or to approve a malicious flow. OWASP Non-Human Identity Top 10 is relevant where automation and delegated access expand the same control problem into machine actors, and the general lesson remains the same: the authenticator must be hard to relay and easy to verify.
Risk and Threat Considerations
SMS and voice OTPs create a concentrated failure mode because one compromised number, forwarding rule, telecom account, or phishing page can defeat the factor across many services at once. The risk is not only interception, it is also takeover of the delivery path, which makes the control especially weak for privileged actions and account recovery.
Failure mechanism: An attacker swaps the SIM, hijacks the carrier account, diverts calls or texts, or relays the OTP through an adversary-in-the-middle flow, then uses the code before expiry to complete authentication or recovery.
Impact: The attacker can bypass step-up controls, reset credentials, take over high-value accounts, and chain that access into fraud, data exposure, or administrative compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant assurance levels directly address OTP weakness in high-risk identity decisions. |
| Recommendation — Require phishing-resistant authenticators for sensitive actions and recovery paths. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | OTP suitability turns on authenticator lifecycle and resistance to misuse or exposure. |
| Recommendation — Manage authenticators so high-risk access uses stronger, non-replayable factors. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Readable OTPs are vulnerable because they can be relayed or phished like weak authentication material. |
| NHI-07 — Long-Lived Secrets | OTP weaknesses echo the broader problem of secrets that remain usable when disclosed or forwarded. | |
| NHI-10 — Human Use of NHI | Human-readable codes are vulnerable because users can be induced to reveal them. | |
| Recommendation — Replace relayed OTP flows with phishing-resistant authentication for critical access. Limit reusable secret-based access on high-risk paths and prefer cryptographic proof. Avoid controls that depend on users verbally sharing authentication material. | ||
Practitioner Guidance
What to verify: If a policy still allows SMS or voice OTP, verify exactly which actions it protects and whether those actions can lead to irreversible account change, privilege gain, or financial loss. If yes, the factor is too weak for that workflow.
Decision rule: Use OTP only where the organisation can tolerate relay or interception risk; require phishing-resistant authentication for recovery, admin elevation, and any transaction where replay would be materially harmful.
Common mistake: Treating “we added MFA” as sufficient without checking whether the chosen factor can be copied, forwarded, or socially engineered. The right question is whether the factor is bound to the claimant and the session, not whether it is time-limited.
Practitioner takeaway: High-risk policy should prefer authenticators that are verifiably non-transferable, because the security goal is not to deliver a code to a person, it is to prove possession in a way an attacker cannot realistically relay.