Passwords and one time passcodes often fail because they add steps that legitimate users struggle to complete, while fraudsters adapt quickly to bypass them. That creates abandonment without reliably stopping account takeover or application fraud. When a control lowers completion rates more than it lowers attack success, it is no longer a good fit for high volume digital onboarding.
Why legacy passwords and one time passcodes feel costly in customer journeys
Passwords and one time passcodes often add friction at exactly the points where customers are trying to complete a task quickly, such as sign-up, login, password reset, or step-up verification. The user has to remember something, receive something, switch context, and sometimes retry. In high-volume journeys, that extra effort shows up as drop-off, support load, and lost conversion before it shows up as stronger security.
The deeper issue is that these controls are often measured by whether they exist, not by whether they improve the overall outcome. A control can still be “working” in a narrow sense while creating avoidable abandonment, device-switch failures, delivery delays, and false negatives that legitimate users cannot resolve without help. MFA Guide is useful here because it distinguishes legacy factors from phishing-resistant options and shows why the user experience and attacker resilience need to be evaluated together.
For customer journeys, the practical question is not whether a password or code can authenticate someone in theory. It is whether the control is proportionate to the risk, the volume, and the user population. In low-risk, low-volume contexts, those steps may be acceptable. In onboarding and repeated authentication flows, the same steps often create more operational drag than security value, especially when the business already has stronger signals available.
Why these controls often fail to stop modern account abuse
Passwords remain vulnerable to reuse, guessing, phishing, and credential stuffing, while one time passcodes are often weak against relay, SIM-swap, inbox compromise, or social engineering. That means the control may still inconvenience the customer even when it does not meaningfully raise attacker cost. Twilio 0ktapus breach 2022 is a relevant example because it shows how SMS-based one time codes and phishing can be combined to capture access despite an extra verification step.
The friction problem gets worse when the control depends on a channel that is itself unreliable. SMS delivery delays, blocked messages, roaming issues, shared devices, and support-assisted resets all introduce failure points that users experience as friction, but fraudsters treat as just another obstacle to route around. When the attacker’s bypass path is cheaper than the customer’s completion path, the control has failed as a journey control even if it remains a valid authentication factor on paper.
That is why modern customer authentication design increasingly separates “proof of presence” from “proof of identity” and looks for methods that reduce repeated interruption. Stronger factors can still be badly implemented, but the direction of travel is clear: if the control depends on repeated human effort and low-assurance delivery channels, it is usually fragile under both user and attacker pressure.
When to replace friction-heavy factors with better fit controls
Legacy passwords and one time passcodes become especially problematic when the journey is high-value, high-frequency, or high-abandonment sensitive. A bank account opening flow, checkout flow, claims portal, or support recovery flow should not force users through repeated hurdles unless those hurdles materially improve fraud resistance. NIST SP 800-63 Digital Identity Guidelines supports this kind of decision-making because it ties authenticator choice to assurance, phishing resistance, and the strength of the overall identity proofing and authentication process.
Better fit controls are usually the ones that reduce repeated interruption while preserving or improving assurance, such as phishing-resistant authentication, device-bound factors, passkeys, or risk-based step-up only when conditions change. The key is to align the control with the actual threat model. If the main problem is account takeover, a factor that can be intercepted or relayed may add little practical protection. If the main problem is completion loss, a factor that creates repeated prompts can damage the journey even when it is technically sound.
Teams should also distinguish between recovery and everyday login. Many customer complaints come from recovery flows that use the same weak mechanisms as initial sign-in, which turns account restoration into a second abandonment point. That is where the business impact compounds: legitimate users lose access, support volume rises, and attackers keep the same shortcut paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Auth assurance and phishing-resistant factor selection directly shape customer journey friction. |
| Recommendation — Choose authenticators that raise assurance without adding avoidable user steps. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Weak or interceptable login and one-time-code flows create authentication failure modes attackers exploit. |
| Recommendation — Harden authentication flows against interception, reuse, and credential stuffing. | ||
| CIS Controls v8 | CIS-5 — Account Management | Customer login and recovery friction is driven by account and credential lifecycle controls. |
| Recommendation — Review account access and recovery steps to remove unnecessary friction. | ||
Practitioner Guidance
What to prioritise: Measure the control as part of the full journey, not as an isolated security step. Track completion rate, recovery rate, support contact rate, and takeover rate together so you can see when a factor is reducing conversion more than it is reducing abuse.
Decision rule: If the control is customer-facing and the attacker can reuse, relay, or socially engineer around it, treat it as a temporary risk reduction measure rather than a durable authentication strategy.
What good looks like: The customer completes the task with fewer interruptions, while the business still has a stronger signal than a reusable password or interceptable code. The best outcome is not “more prompts”, it is lower friction with higher assurance.
Practitioner takeaway: In customer journeys, authentication should earn its place by improving both trust and completion. If it mainly increases effort while leaving common attack paths intact, it is a control smell, not a control win.
Related resources from NHI Mgmt Group
- Why do SMS one-time passwords create both fraud risk and customer friction in digital banking?
- Why do passwords and one-time passcodes fail as primary authentication methods in high-risk digital journeys?
- Why do passwords and SMS one-time passcodes create risk in remote authentication flows?
- How should organisations reduce reliance on passwords and one-time passcodes without creating more login friction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org