Skip to content
  • Products & Services
  • Security Operations
  • Threat Research
  • AI Research
  • Sophos Life
  • Products & Services
  • Security Operations
  • Threat Research
  • AI Research
  • Sophos Life
Naked Security Naked Security

Snapchat steps up its security with login verification

Snapchat has an optional new security feature in version 9.9, called Login Verification. Here's why you should definitely update your app and turn it on.
Written by John Zorabedian
June 11, 2015
Naked Security 2FA login verification SnapChat two-factor authentication

snapchat-login-verification-550Snapchat is hugely popular with teens and young adults as a way to send short-lived photo and video messages, but it hasn’t won many fans in the security business.

In the past couple of years, Snapchat has run into trouble with the US Federal Trade Commission for its deceptive marketing practices, and was blasted by security researchers for really poor security of users’ account information.

More recently, however, Snapchat has picked up its security game in a big way – notably, since April 2014 when it hired a new director of information security, ex-Googler Jad Boutros, who says he is building a “culture of security” at the company.

On Monday, Snapchat released version 9.9.0 of the app for Android and iOS, with an optional new security feature called Login Verification that helps prevent unauthorized account access.

This kind of extra protection is especially relevant now that Snapchat is offering additional services such as Snapcash, to help prevent a thief from logging in as you and sending money from your account to another Snapchat account.

Once enabled, Login Verification requires users to enter a one-time code when logging in from a new device (in addition to their password).

This type of verification, also known as two-factor authentication (or for Apple accounts, two-step verification) makes it doubly hard for an imposter to access your account.

snapchat-login-verificationBecause the verification code is sent via SMS text message to the phone number linked to the account, a snoop would need to have access to your phone as well as knowing your username and password combination to log in as you.

You can also use the Login Verification setting to verify additional devices, or to request a Recovery Code you can enter for logging in from an unverified device in case of a lost or stolen phone.

If you want to use Snapchat on, for example, your iPhone and your iPad, or manage your account online from your Mac, you can verify all of those devices – but a thief with your username and password signing in from another device wouldn’t be able to log in without a verification code.

And if you’re worried about someone else getting access from one of your verified devices, you can also “forget” previously verified devices from the Login Verification setting.

Here at Naked Security, we haven’t found many occasions to give Snapchat a pat on the back, but we’re happy with these additions for better security.

Snapchat should do everything it can to encourage people to use them.

Learn more about two-factor authentication

Two-factor authentication (or “2FA”) is not a foolproof defense against unauthorized account access – but we highly recommend turning it on wherever possible.

Sophos experts and Naked Security writers Paul Ducklin and Chester Wisniewski investigate 2FA in an episode of their popular (and award-winning) weekly podcast.

Chet and Duck explain the different types of 2FA, and they also look candidly at the downsides.

Have a listen using the audio player below.


(Audio player not working? Download to listen offline, or listen on Soundcloud.)


Image of Snapchat on mobile device courtesy of focal point / Shutterstock.com.

Share this:

  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • More
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to print (Opens in new window) Print
  • Click to email a link to a friend (Opens in new window) Email
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • 9
About the Author

John Zorabedian

John Zorabedian is a blogger, copywriter and editor. He has a background in journalism, writing about technology, business, politics and culture. He lives and works in the Boston area.

Read Similar Articles

May 24, 2021

What to expect when you’ve been hit with Avaddon ransomware

May 19, 2021

What’s New in Sophos EDR 4.0

May 19, 2021

Sophos XDR: Driven by data

Subscribe to get the latest updates in your inbox.
Which categories are you interested in?
Change Region
  • América Latina
  • Brasil
  • Deutschland
  • English
  • France
  • Iberia
  • Italia
  • Japan
Terms Privacy
  • Privacy Notice
  • Cookies
Legal
  • General
  • Modern Slavery Statement
  • Speak Out
© 1997 - 2025 Sophos Ltd. All rights reserved