FINDING · POLICY
During the June 2025 shutdown, Iranian authorities blocked international One-Time Password (OTP) SMS delivery, preventing new sign-ins to foreign secure-messaging platforms and VPN services. This forced users toward government-approved domestic platforms that lack security and privacy protections. The blockade of OTPs effectively weaponized account-recovery flows as a secondary shutdown layer, disproportionately affecting users who needed to activate new circumvention tools during the crisis.
From 2025-iran-shutdown-measurement — Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed Action · §Human Rights Implications · 2026 · WWW '26 (Proceedings of the ACM Web Conference 2026)
Implications
- Circumvention tools that require an OTP or email-based account setup will be unusable at the moment users need them most; design for pre-registration or credential-free activation (e.g. share-codes, invite tokens) that works without SMS reachability.
- Tools should detect OTP/account-setup failure and present offline-capable fallback instructions during a detected shutdown event.
Tags
Extracted by claude-sonnet-4-6 — review before relying.