Ik heb bunq support gevraagd (en het expliciet gevraagd naar een medewerker te laten gaan) en kreeg het volgende antwoord:
Is gewoon SMS dusunderstand you want to know what the differences are between regular SMS and the SMS you receive for authorising Click to Pay. I am here to clarify this for you.
In Click to Pay, SMS authentication is part of a multi-layered security model. The SMS itself is not encrypted beyond standard carrier-level protection, but the authentication data — such as the one-time verification code — is generated and validated over an encrypted channel (TLS) between the issuer, the payment network, and the Click to Pay service.
This means that even if an SMS were intercepted, it couldn’t be reused or linked to any sensitive information. The verification codes are randomized, time-bound, and bound to a single transaction session.
In short, the ‘secure’ aspect doesn’t come from the SMS transport layer itself, but from the encryption, tokenization, and one-time validation protocols that surround the Click to Pay authentication process.