top of page

Why SMS-Based 2FA Is Not Enough — And What to Use Instead

1 day ago
7 min read

Any MFA beats none. But "better than nothing" is a low bar, and text-message codes are the weakest rung on the ladder. Here's why — and where to step up.


Back in Week 1 of 31 Days Safer, Day 5 asked you to turn on multi-factor authentication — and if a service only offered text-message codes, to use them anyway, because any MFA beats none. That's still true. A lot of people stop there, thinking they've solved the problem. 


So let me expand that day into the full picture: why SMS codes are the weakest kind of MFA, how they actually get beaten, and what to switch to instead.


The short version, so you can act on it even if you read nothing else: Keep SMS 2FA if it's the only option a service gives you — it's still far better than a password alone. But anywhere you can, move your second factor onto an authenticator app or a passkey.

Your email, your bank, your password manager, and your main social accounts are where this matters most.


The problem: your second factor is traveling over something you don't control


The whole point of a second factor is that even if someone steals your password, they still can't get in without the second thing. SMS breaks that promise in a quiet way — the "second thing" is a text message, and a text message doesn't actually belong to your phone. It belongs to your phone number, and your phone number lives on a carrier's network that you have no control over.


That's the crack. Two different attacks pry it open.


Attack 1: SIM-swapping (the one that actually happens to people)


This is the common one, and it's the one worth understanding first.

Your phone number isn't tied to your physical phone — it's tied to the SIM your carrier has associated with your account. A SIM-swap attack is when an attacker convinces your carrier to move your number to their SIM. Once they do, your texts — including your login codes — start arriving on the attacker's device instead of yours.


How do they pull it off? Usually not with any hacking at all. They call your carrier's support line pretending to be you, armed with personal details scraped from data breaches and your social media — your address, your birthday, the last four of a card, your mother's maiden name. They fail a few times, hang up, and call back until they get an agent who waves it through. Sometimes they just bribe a store employee.


The tell that you've been hit is chilling in its simplicity: your phone suddenly loses signal and won't make calls. That's your number going dark on your SIM as it lights up on theirs. By the time you notice, they're already working through your accounts.


This is not theoretical or rare. It's a documented, repeatable attack that has drained crypto wallets and hijacked high-profile accounts for years, and the only thing it requires is that your valuable accounts fall back to SMS.


Attack 2: SS7 interception (the rarer, deeper one)


This is the one that gets dramatized, so I want to be honest about where it actually sits.

SS7 is the aging signaling protocol that phone networks use behind the scenes to route calls and texts between carriers worldwide. It was designed decades ago for a small club of trusted telecom operators, with almost no authentication built in — because back then the threat model didn't include anyone outside that club getting access. Today, access to SS7 is far more widespread than it was ever meant to be, and someone with that access can, in principle, intercept the text messages routed to a number — including 2FA codes — without touching your phone or your carrier account at all.


Here's the honest framing, because this is where a lot of security content oversells: SS7 interception is real, but it is not something a random scammer is doing to you. It generally requires network-level access that sits with telecom insiders, surveillance vendors, and state-level actors. It's a genuine, demonstrated weakness in the foundation SMS is built on — which is exactly why SMS can never be considered truly secure — but for the average person, SIM-swapping is the practical threat, and SS7 is the structural one. You defend against both the same way, so the distinction is more about understanding than action.


The takeaway isn't "someone is reading your texts right now." It's that the system carrying your login codes was built on trust assumptions that stopped being true a long time ago, and you shouldn't hang your most important accounts on it.


The fix: put the second factor on a device, not in a text message


The solution to both attacks is the same move — stop letting the code travel over the phone network at all.


Authenticator apps (TOTP). An authenticator app generates those rolling six-digit codes right on your device. The technical name is TOTP — time-based one-time password. Here's why it's fundamentally safer: when you first set it up, your device and the service share a secret once, and from then on both sides independently generate the same code from that secret plus the current time. Nothing is ever sent over the network for an attacker to intercept or redirect. No text message, no SIM, no SS7. A SIM-swap gets the attacker your number and nothing else — the codes are being generated on a phone they don't have.


Passkeys. The newer, stronger option, and where things are heading. A passkey replaces the password and the second factor with a cryptographic key stored on your device and unlocked by your face, fingerprint, or PIN. There's no code to phish, type, or intercept — the authentication happens between your device and the service directly. Where a service offers a passkey, it's the best choice available. Not everything supports them yet, which is why authenticator apps are still the practical workhorse for most accounts today.


Picking an authenticator app: Google Authenticator vs. Aegis vs. Authy


If you're ready to switch, the next question is which app. All three generate standard TOTP codes, so any of them beats SMS. The difference is in backup, portability, and how much you trust the company in the middle. Here's the honest comparison.


  • Google Authenticator — the simplest on-ramp. Free, everywhere, and if you already live in Google's ecosystem, the least friction. The trade-offs: it's closed-source, and its cloud backup ties your 2FA recovery to your Google account — which is convenient until you remember that your Google account is often one of the things you're trying to protect. Fine for getting started; just know what you're leaning on.


  • Aegis — the privacy pick, if you're on Android. Open-source, which means its code can be independently audited rather than taken on faith. Its standout feature is backups you control: encrypted export files you own and store wherever you choose, instead of a vendor's cloud. The catch is that it's Android-only, and the responsibility for not losing that backup is yours. For anyone who wants their security tooling transparent and in their own hands, this is the one I'd point to.


  • Authy — the convenience pick. Its selling point is multi-device sync and encrypted cloud backup, so if you lose your phone, you're not locked out — your tokens restore to a new device. That genuinely solves the single scariest part of switching off SMS. The trade-off is philosophical: you're trusting Authy's cloud to hold your 2FA seeds, a bigger surface than codes that never leave one device. A reasonable trade if the alternative is never switching because you're afraid of being locked out.


The honest bottom line: the best authenticator app is the one you'll actually set up and keep using. If backup anxiety is the thing stopping you, Authy's sync removes that excuse. If you want control and transparency and you're on Android, Aegis. If you just want to start today, Google Authenticator is right there. Any of the three is a massive upgrade over a text message.


What to actually do this week


Don't try to migrate every account at once — that's how people stall out. Work in priority order:


  1. Pick one authenticator app from the three above and install it. Decide now; don't research for a week.

  2. Start with your email. It's the master key that can reset everything else, so it's where the upgrade matters most. In your email account's security settings, add the authenticator app as a 2FA method.

  3. Then your password manager, your bank, and your main social accounts — the high-value targets, in that order.

  4. Save your recovery codes as you go (this was Day 7 of the challenge — store them somewhere separate from your phone). This is your safety net if you ever lose the device.

  5. Where you see "passkey" offered, take it. It's the strongest option and the direction everything is moving.

  6. Leave SMS on only where it's the only choice — and now you know exactly why it's the fallback, not the goal.


Fifteen minutes on your email account alone closes the biggest gap. The rest can roll out over the week.


How I'd explain this in a SOC interview


Ask me why SMS-based MFA shows up as a finding in a security assessment, and here's the answer: because it moves a trust boundary onto infrastructure the organization doesn't control. The second factor is only as strong as the channel it travels over, and SMS travels over the carrier network — which means the real attack surface isn't the user's phone; it's the carrier's support desk (social-engineered in a SIM-swap) and the SS7 signaling layer underneath (a structural weakness in the protocol itself). TOTP and passkeys close that gap by keeping the authentication secret on an endpoint instead of putting it on the wire. That's defense in depth in one example: you don't just ask "is there a second factor?" — you ask "what is that factor trusting, and do we control it?" The tool changes; the question doesn't.


So that's Day 5, expanded all the way out. SMS 2FA isn't worthless — it's the floor. The move this week is to lift the accounts that matter up off that floor and onto something an attacker can't redirect with a phone call.


A quiet milestone to note at the bottom here: this is the 50th post on DataSec Chronicles. Fifty entries of storm-to-SOC, one honest step at a time — no tidy fictions, every number real, the whole map built in public. Thank you for reading along. The next fifty are about going deeper.


Storm to SOC — read the map, then move. 💜

Comments


Let's learn this together. Have a question, a better query, or just want to say hi? Drop a line below.

© 2026 by DataSec Chronicles. Data-Inspired, Instinct-Driven.    Privacy Policy    Terms & Conditions

bottom of page