Why SMS Two-Factor Authentication Is Better Than Nothing (But Not By Much)

Turning on text-message codes was a real improvement over a password alone, and you should not turn them off. You should also understand that of the four common ways to do two-factor, this is the worst one, and the gap is wider than most people assume.

CISA sorts these methods into tiers, with passkeys and hardware keys in the phishing-resistant group and text codes at the bottom of everything else. Here is why, and what to actually do about it.

The three ways a text code fails

SIM swapping. Someone convinces your phone carrier to move your number to their SIM. Your phone loses service, their phone starts receiving your texts, and every code meant for you arrives at their device. You cannot prevent this from your end because it happens at a carrier’s retail counter or call center. The FCC adopted rules in 2023 requiring carriers to verify identity before a SIM change, which helped, and social engineering a call center still works often enough to be a business.

Real-time phishing. A fake login page collects your password, then asks for the code. You type it, the attacker relays it to the real site within the thirty seconds it lives, and they are in. Your second factor did exactly what it was designed to do and it did not matter, because you handed it over yourself.

The account recovery path. Many services let a phone number reset a password. When that is true, your number stops being a second factor and becomes a master key, and anyone holding your number owns the account outright.

An authenticator app removes the first and third. It does not remove the second, because a code you type into a convincing fake page is compromised whatever generated it.

The four tiers, ranked

  1. Passkeys or a hardware key. Phishing-resistant, because the credential is bound to the real site’s domain and will not release on a lookalike. A fake page cannot collect what your device refuses to hand over. This is the only tier that survives a convincing phishing attempt.
  2. An authenticator app. Codes generated on your device with nothing transmitted over the phone network. Immune to SIM swaps, still phishable.
  3. Push notifications. Roughly equal to an app, with one extra failure: people approve prompts they did not trigger, either from habit or from being worn down by repeated requests at 3am.
  4. Text messages. Everything above plus the carrier problem.

Most people should be somewhere in the top two on the accounts that matter and can leave the rest wherever they are.

Where it actually matters

Nobody has the patience to migrate forty accounts, and nobody needs to. Two-factor strength should follow the damage an account can do.

Move these off text codes this week:

  • Your primary email. It resets everything else. If you do one, do this one.
  • Your bank and any brokerage.
  • Your password manager, if you use one.
  • Your phone carrier account, which is the account that protects every other text code you still rely on.
  • Anything holding money on file. PayPal, Venmo, Cash App, the payment side of your shopping accounts.

Leave alone: your grocery store loyalty account, a newsletter login, the forum you post on twice a year. Text codes there are fine and the switching cost is not worth it.

If you would rather work through this as a once-a-year sweep than a vague intention, The Annual Security Reset is that sweep, with the account inventory, the order to work in, and the carrier lockdown step most guides leave out. $18.99.

The switching order

Do this and it takes an evening rather than a project.

  1. Install an authenticator app and pick one with encrypted backup, because the classic disaster here is losing your phone and locking yourself out of everything at once.
  2. Start with your email. Add the app as a method before removing the text option, and confirm the app works.
  3. Save the recovery codes each service gives you. Print them or write them down, then put them somewhere a housefire or a thief would not reach both them and your phone.
  4. Only then remove SMS as a method on that account.
  5. Repeat down the list of accounts that hold money or reset other accounts.
  6. Call your carrier and add a port-out PIN or account lock. Ask for it by name. This is fifteen minutes on hold and it is the single highest-value call in the list, because it protects every text code you keep.

The order matters. Removing text codes before the app works is how people lock themselves out.

What about passkeys

Where they are offered, take them. Google, Apple, Microsoft, Amazon and most large banks support them now, and they remove the phishing problem rather than reducing it.

The awkward part is coverage. You will end up with passkeys on some accounts, an app on others and text codes on the ones that support nothing else, and that mixture is normal. It is not a failure to have three systems running. It is what a transition looks like from the inside.

“What happens if I lose my phone?”

This is the real objection, and it is the reason most people never switch. It deserves a straight answer rather than reassurance.

If your codes live only on a phone you lose, you are locked out of every account that used it. That is a genuine risk and it is entirely preventable, in three ways.

Use an app with encrypted cloud backup. Most now offer it. Your codes restore onto a new phone by signing back into the app. Turn this on when you install it, not later.

Save every recovery code. Each service gives you a set of one-time codes when you enable two-factor. Print them. Put them with your passport or in a small safe, somewhere a house fire or a burglar would not reach both them and your phone. This is the actual safety net and it is the step people skip.

Register a second device. An old phone in a drawer, running the same authenticator, is a perfectly good backup.

Do one of the three and losing your phone becomes an inconvenient evening. Do none and it becomes a month of identity verification with support teams. Text codes survive a lost phone because the number moves to your new one, which is a real advantage and the reason to sort out backups before you remove SMS rather than after.

The bottom line

Do not turn off text codes. Any second factor beats none, and an account with SMS two-factor is far harder to take than an account with a password alone.

Do move your email, your bank, your password manager and your phone carrier onto an authenticator app or a passkey, in that order, and call your carrier about a port-out lock while you are at it. That is an evening of work covering the accounts that can actually hurt you, and the rest can wait until you happen to be in the settings anyway.