For a decade the standard defence for a Gmail account has been the six-digit code that arrives by text message after you type your password. Google now says that code is a liability. Over the next few months, its two-step verification will stop sending SMS codes and instead show a QR code on the sign-in screen, which you scan with your phone’s camera to prove it is you.
Why Google is doing it
“SMS codes now present a major security risk for users,” Google spokesperson Ross Richendrfer said, announcing the change. The company’s reasoning comes in three parts:
- The phone number is the weak point. A criminal who convinces a mobile operator to move your number to a new SIM — a “SIM swap” — receives your codes. Operators’ security standards vary widely from country to country, and Google cannot fix that.
- Phishing. A fake login page can ask for your password and then your SMS code, and relay both to the real Gmail within seconds. A QR code tied to the device that is signing in is much harder to relay.
- Traffic pumping. Fraudsters set up premium-rate numbers and trigger floods of verification texts to them, pocketing a share of the SMS charges. Google was paying for its own abuse.
What it means for Bangladesh
All three problems are familiar here. SIM registration is tied to NID, but SIM replacement at a customer-care point has repeatedly been exploited in mobile-banking fraud, and OTP-phishing calls (“I am from the bank, read me the code”) are the most common scam reported. Removing SMS from the Gmail chain cuts one link that attackers in Bangladesh use daily.
What to set up now
- Go to myaccount.google.com → Security → 2-Step Verification.
- Add a passkey (fingerprint or face on your phone) — Google treats this as the primary method and it is immune to phishing.
- Add the Google Authenticator app or another authenticator as a second method, so you can sign in without mobile signal.
- Download your backup codes and keep them somewhere that is not your phone.
- Only then remove the phone number as a sign-in method — keep it for account recovery if you wish, but not as the second factor.
Google has not given an exact date for the switch, and it will arrive gradually. The QR flow will be the default; users without a second device will still have options, but the era of the texted code is ending, and the banks and mobile-money operators that still rely on it should read the announcement as a warning about their own systems.
Source: India Today, via Prothom Alo.




