"Turn on two-factor authentication" has been standard advice for so long that it's easy to tick the box and stop thinking about it. But not all two-factor is equal, and the most common kind — a code texted to your phone — is also the weakest. If you set it up years ago and haven't looked since, it's worth five minutes to check which kind you're actually using.
Why SMS codes are the weak option
A text-message code protects you from a stolen password alone, which is genuinely useful. What it doesn't protect against is SIM swapping: an attacker who has gathered enough of your personal information convinces your phone carrier to move your number to a SIM card they control. From that point on, your "second factor" texts go straight to them, not you. This isn't a rare, exotic attack — it's a well-established technique specifically because SMS-based two-factor is still so widely used.
SMS codes can also be intercepted through network-level attacks that don't even require fooling your carrier, and phishing kits now exist that can capture and relay a one-time code in real time as you type it into a fake login page.
The stronger options, in order
Making the switch without locking yourself out
- Set up the new method before removing the old one. Most account security pages let both exist temporarily — add the authenticator app or key first, confirm it works with a test sign-out and sign-in, then remove SMS.
- Save your backup codes somewhere durable. Every major service generates one-time backup codes when you enable two-factor. Write them down or store them in your password manager — not a photo on the same phone that might be lost alongside them.
- Register a second method if the service allows it. A backup authenticator app or second hardware key means a lost phone is an inconvenience, not a lockout.
The takeaway
Two-factor authentication isn't a single feature you either have or don't — it's a spectrum, and where you sit on it matters. Moving from SMS to an authenticator app or hardware key closes the exact gap that SIM-swapping and real-time phishing kits are built to exploit, for the cost of a five-minute settings change.