FINDING · DETECTION
The Iranian government blocked international One-Time Passwords (OTPs) during the June 2025 shutdown, forcing citizens to abandon secure international platforms and migrate to government-approved domestic services with known security and privacy vulnerabilities — using authentication infrastructure as a deliberate chokepoint to coerce adoption of surveilled platforms at scale.
From 2025-miaan-stealth-blackout — Iran's Stealth Blackout: A Multi-stakeholder Analysis of the June 2025 Internet Shutdown · Executive Summary — Human Rights Implications · 2025 · Filterwatch / Miaan Group multi-stakeholder report
Implications
- Circumvention tools and secure-messaging apps must not depend on SMS OTPs delivered via international carriers for authentication; build offline onboarding or alternative second-factor flows that bypass international telephony infrastructure entirely.
- Treat forced migration to government-controlled platforms as a threat model distinct from simple blocking: design systems so that blocking the circumvention tool does not automatically degrade users' security posture by pushing them toward surveilled alternatives.
Tags
Extracted by claude-sonnet-4-6 — review before relying.