12 Jul 2026
Two-factor authentication is one of the single most effective things anyone can do to protect an online account, and turning it on for anything important is genuinely good advice. But not every 2FA method offers the same level of protection, and the most common one — a code sent by text message — happens to be the weakest widely available option.
SMS messages aren't encrypted the way app-based codes or hardware keys are, and phone numbers can be hijacked through SIM swap attacks — where an attacker convinces a mobile carrier to move your number to a SIM card they control, then receives your codes instead of you. This doesn't require access to your actual phone, just a successful social-engineering call to a carrier's support line.
Most major services now support authenticator apps as an alternative to SMS, and it's usually a quick change in account security settings. For accounts that matter most — email, banking, primary cloud storage — a hardware security key or passkey offers noticeably stronger protection, since the underlying credential can't be phished the same way a six-digit code can.
Absolutely. The comparison here is between different levels of good, not between good and bad. If SMS is the only option a service offers, using it is still far better than leaving an account protected by a password alone. But where a stronger option exists, it's worth the few extra minutes to switch.
Yes, significantly better. The concern with SMS codes is relative to other 2FA methods, not compared to having no second factor at all — any 2FA meaningfully reduces the risk of a stolen password being enough to break into an account.
It's when an attacker convinces your mobile carrier to transfer your phone number to a SIM card they control, often through social engineering or a compromised support agent. Once that happens, they receive your SMS codes instead of you, without needing physical access to your phone.
Not really — most involve scanning a QR code once during setup, after which the app generates a new code every 30 seconds without needing an internet or phone signal connection at all, since the codes are generated locally on the device.
Hardware security keys and passkeys are generally considered the strongest, since they're resistant to phishing in a way that one-time codes typically aren't — the credential itself is tied to the specific website, so it can't be tricked into working on a fake copy of that site.