Tuesday, 16 Jul 2024

One-time passwords in messaging apps: a modern approach to 2FA

With the increasing need for secure authentication methods, messaging apps are emerging as a modern and convenient solution. Eireview introduces Protectimus Bot, a brand-new approach to two-factor authentication (2FA) that utilizes chatbots on popular messaging platforms. This innovative method offers a more secure alternative to traditional SMS authentication, all while being completely free and easy to use.

The Benefits of Messaging Apps for OTP Delivery

SMS authentication has long been the go-to method for 2FA due to its convenience. However, it comes with its downsides. SMS authentication is expensive, offers a low level of security, and requires users to be within range of a mobile phone network. Eireview’s solution addresses these limitations by leveraging messaging apps for OTP delivery.

Enhanced Security and Cost-effectiveness

OTP delivery through messaging apps provides a higher level of security compared to SMS authentication. Access to messaging apps is protected by passwords and often supported by multifactor authentication. Moreover, all messages sent through these apps are reliably encrypted. This ensures that sensitive information remains secure throughout the authentication process.

Apart from the security benefits, using messaging apps for 2FA is also cost-effective. Businesses no longer need to bear the expenses of sending expensive SMS messages. Instead, OTP passwords and other notifications can be sent for free using these messaging services.

User-Friendly and No Additional Installation Required

Implementing 2FA through messaging apps eliminates the need for distributing hardware tokens or requiring users to install authentication apps. Most users already have at least one messaging app installed on their smartphones, making it a seamless and familiar process. By simply utilizing a messaging app, businesses can offer their users a hassle-free and user-friendly authentication experience.

The Algorithms and Functionality Behind OTP Delivery

One-time passwords delivered through messaging apps can be generated using two main algorithms: HOTP (HMAC-based One-time Password Algorithm, RFC 4226) and TOTP (Time-based One-time Password Algorithm, RFC 6238). These algorithms ensure the generation of unique and time-bound passwords for each authentication attempt.

Additionally, Protectimus Bot supports CWYS (Confirm What You See) data-signing functionality, based on OCRA (OATH Challenge-Response Algorithm, RFC 6287). This functionality enables the generation of one-time passwords using transaction or session data, further enhancing the level of security.

How to Activate Two-Factor Authentication with Protectimus Bot

Activating 2FA with Protectimus Bot on popular messaging apps such as Telegram, Facebook Messenger, or Viber is a straightforward process. Users simply need to search for the @ProtectimusBot account in their preferred messaging app and start a chat with the bot using the /getid command.

Upon entering the /getid command, the user will receive a unique chat ID, which they must provide to their administrator. The administrator can then input the chat ID into the admin panel, making it effortless to issue a token to the user.

Frequently Asked Questions

Q: Is messaging app authentication more secure than SMS authentication?
A: Yes, messaging app authentication offers a higher level of security due to password protection, multifactor authentication, and encrypted messages.

Q: Does messaging app authentication require additional installations?
A: No, most users already have at least one messaging app installed on their smartphones, eliminating the need for additional installations.

Q: How much does it cost to send OTP passwords through messaging apps?
A: OTP passwords and other notifications can be sent for free using messaging apps, making it a cost-effective solution.

Q: Which algorithms are used for generating one-time passwords through messaging apps?
A: Protectimus Bot supports HOTP, TOTP, and CWYS algorithms to ensure secure and unique one-time passwords.


Eireview’s Protectimus Bot revolutionizes two-factor authentication by leveraging the convenience and security of messaging apps. By eliminating the need for traditional SMS authentication, businesses can provide their users with a more secure, cost-effective, and user-friendly authentication experience.

