
WASHINGTON — The Pentagon announced Friday that it has completed the most significant modernization of America’s nuclear command-and-control system in decades, replacing what officials described as “outdated military authentication technology” with the same security system currently protecting millions of Gmail accounts, online banking portals, and fantasy football leagues.
Under the new protocol, any order to launch a nuclear weapon will require two-factor authentication using a six-digit one-time password sent by SMS, followed by Apple Face ID and a CAPTCHA requiring the authorized officer to identify all squares containing either a car or a staircase.
“This brings nuclear deterrence firmly into the 21st century,” said Secretary of War Pete Hegseth. “For decades, we relied on expensive purpose-built communications networks, specialized cryptographic equipment, highly trained personnel, and elaborate command procedures. Then President Trump, who frankly has more strategic vision than every general in this building combined, asked a very simple question: Why are we reinventing something that Verizon already does for free?”
Officials said the modernization effort will save taxpayers hundreds of millions of dollars by eliminating specialized authentication equipment in favor of commercially available iPhones running the new Nuclear Authentication App, available through the App Store.
The Pentagon has reportedly selected the “Family Plan” tier, which allows up to six authorized users and includes free photo storage.
“We were spending $400 million a year on custom cryptographic devices,” said one senior defense official. “Now we spend $14.99 a month, and we get spam call filtering for free. That’s what I call strategic superiority.”
President Trump celebrated the upgrade on Truth Social at 1:30 a.m.
The system is protected by Face ID, a six-digit device passcode, and a requirement that users change their password every 90 days to something they have not used within the previous 24 months.
Passwords must contain at least one uppercase letter, one lowercase letter, one number, one special character, and may not contain the words “nuclear,” “launch,” “missile,” or “password.”
Military officials described the system as virtually impenetrable.
Pentagon officials emphasized that the SMS verification system incorporates multiple layers of commercial-grade security and therefore represents a substantial improvement over legacy systems developed specifically to survive nuclear war.
Cybersecurity experts praised the move as “bold,” “unorthodox,” and “possibly a war crime.”
“SMS-based 2FA is widely considered the least secure form of multi-factor authentication, vulnerable to SIM-swapping, SS7 attacks, and the fact that your carrier sells your data to literally anyone,” said Dr. Helena Voss of the Center for Applied Paranoia. “But sure, let’s put it in charge of the apocalypse. What could go wrong?”
Questions about cellular availability during a nuclear attack were dismissed as largely theoretical.
Under the new protocol, the President’s verification code will be delivered by text message even if he has been evacuated to a hardened command bunker 200 feet underground, beneath several layers of reinforced concrete and steel designed specifically to keep outside signals from getting in.
“That’s really more of an edge case,” Hegseth said. “If the President isn’t getting a signal, he can simply move closer to a window.”
Asked whether the bunker has any windows, Hegseth said the Pentagon was “exploring options” and noted that the facility does have guest Wi-Fi.
“We have excellent coverage with most major carriers,” said Hegseth. “Obviously there are some dead zones around missile silos in Montana, but we’re working with the carriers on that.”
In areas with weak reception, launch crews will be instructed to toggle airplane mode on and off, restart the device, or hold the phone above their heads.
If those steps fail, personnel can select Resend Code.
The Pentagon confirmed that standard carrier messaging rates may apply.
The new system also includes safeguards against unauthorized launches. After five unsuccessful authentication attempts, the account will automatically be locked for 30 minutes and an email will be sent to the registered address containing a link labeled Wasn’t You? Secure Your Account.
Officials said the link will remain valid for 24 hours.
In the event the President loses the authentication phone, the launch authorization system can be restored by contacting the Nuclear Command Account Recovery Center and answering several identity-verification questions.
For additional security, users may be asked to provide the name of the President’s first pet, the street he grew up on, and the last four digits of his Social Security number.
“We take account recovery extremely seriously,” said Hegseth.
The modernization project was reportedly inspired by a Pentagon cybersecurity task force that discovered that decades of specialized nuclear command infrastructure could be replaced by what one consultant described as “a pretty standard enterprise login flow.”
The contractor responsible for the system received a $742 million modernization contract and subsequently signed the Pentagon up for the $14.99-a-month Family Plan.
Defense officials nevertheless estimate the project will save taxpayers $38 million over 20 years.
“This is what innovation looks like. This is what leadership looks like,” Hegseth said. “We stopped asking how the military authenticated nuclear launch orders in the past and started asking how a mid-sized regional insurance company would solve the problem today.”
“We’ve also enabled Remember This Device for 30 Days,” Hegseth added. “So once you authenticate, you’re pretty much good to launch for a month. Convenience was a top priority.”
Future updates are already planned. The Pentagon is evaluating passkeys and a “Sign in with Google” option.
Officials stressed, however, that convenience would never come at the expense of national security.
“At the end of the day, nuclear command and control depends on one fundamental principle,” Hegseth said. “Something you know, something you have, and something you can correctly identify as a bicycle.”