Mumbai: Starting July 1, users of Gmail gets QR code based 2FA. Google has officially phased out SMS-based two-factor authentication (2FA) for Gmail, introducing a more secure QR code-based 2FA method. Users logging into their Gmail accounts are now prompted to scan a QR code with their smartphone camera and follow on-screen instructions to authenticate.
Gmail gets QR code
The change is part of Google’s broader efforts to strengthen account security amid growing concerns over vulnerabilities in SMS-based systems. Unlike SMS codes, which can be intercepted through techniques like SIM swapping, phishing, or SMS pumping, QR codes offer a more secure alternative by eliminating the reliance on mobile networks.
The transition was first hinted at in February when media reports revealed Google’s intention to replace the traditional six-digit SMS code with QR code authentication. At the time, Gmail spokesperson Ross Richendrfer noted the shift aimed to reduce the abuse of SMS verification and enhance user protection.
“Over the next few months, we will be reimagining how we verify phone numbers. Specifically, instead of entering your number and receiving a 6-digit code, you’ll see a QR code being displayed, which you need to scan with the camera app on your phone,” media report had quoted Richendrfer as saying.
In general, QR codes are considered more secure than SMS codes for two-factor authentication. SMS codes are vulnerable to attacks like SIM swapping and phishing, while QR codes offer a more direct and secure method of authentication by eliminating the need for an intermediary (the mobile network) and reducing the risk of interception
While QR codes provide a safer and more direct verification process, the SMS-based one-time password (OTP) system remains widely used in sectors such as banking, financial services, and insurance (BFSI). This reliance continues to expose users to risks, contributing to financial losses, reputational harm, and declining public trust.
With the growing sophistication of cyber threats, Google’s move signals a broader shift in the tech industry toward stronger, more resilient authentication methods.
