Two-factor authentication is one of the best ways to protect your online accounts. But if you rely on text message codes, you are using the weakest form of two-factor security available. SMS-based codes can be intercepted through a technique called SIM swapping, where attackers convince your phone carrier to transfer your number to a device they control.
Authenticator apps eliminate this risk. They generate time-based codes directly on your phone, with no reliance on your cell carrier or text messages. The setup takes five minutes per account, and the protection is significantly stronger.
Why SMS Codes Are Vulnerable
When you enable two-factor authentication via text message, your bank or email provider sends a six-digit code to your phone number. You enter that code to prove you own the device. The problem is that your phone number is controlled by your wireless carrier, not by you.
In a SIM swap attack, a criminal calls your carrier pretending to be you. They claim they lost their phone and need the number transferred to a new SIM card. If the carrier's verification process fails, the attacker gains control of your phone number. Every text message you receive, including two-factor codes, now goes to them.
This is not a theoretical risk. SIM swapping has been used to drain bank accounts, hijack social media profiles, and steal cryptocurrency. In 2019, a Twitter CEO had his account compromised this way. Victims often do not realize the attack is happening until their phone stops receiving calls and texts.
How Authenticator Apps Work
Authenticator apps generate codes based on a shared secret between you and the service you are logging into. When you enable two-factor authentication, the service shows you a QR code. You scan it with your authenticator app, and the app begins generating six-digit codes that refresh every 30 seconds.
These codes are created using a mathematical formula that combines the shared secret with the current time. Because the process happens entirely on your device, there is no text message to intercept and no phone number for an attacker to hijack.
Popular authenticator apps include Google Authenticator, Microsoft Authenticator, Authy, and 1Password. All of them work the same way and are compatible with most services that offer two-factor authentication.
Setting Up an Authenticator App
Start by downloading an authenticator app to your phone. Google Authenticator and Microsoft Authenticator are free and simple. Authy offers cloud backup, so you do not lose access to your codes if you lose your phone. If you already use a password manager like 1Password or Bitwarden, many of them include built-in authenticator features.
Next, log into an account where you want to enable two-factor authentication. Go to the security settings and look for options labeled two-factor authentication, two-step verification, or multi-factor authentication. Most services offer both SMS and authenticator app options. Choose the authenticator app option.
The service will display a QR code on the screen. Open your authenticator app and tap the button to add a new account. Point your phone's camera at the QR code. The app will scan it and immediately start generating codes for that account.
Before you finish, the service will ask you to enter a code from your authenticator app to confirm everything is working. Type in the six-digit code displayed in the app. Once confirmed, two-factor authentication is active.
Managing Backup Codes
When you enable two-factor authentication, most services provide a set of backup codes. These are one-time-use codes you can use if you lose access to your authenticator app. Save these codes in a secure location, such as a password manager or a locked file cabinet.
Do not skip this step. If your phone is lost, stolen, or factory reset, you will not be able to log into your accounts without either the authenticator app or a backup code. Some services allow account recovery through email, but others lock you out permanently if you lose both your authenticator and your backup codes.
What to Do If You Lose Your Phone
If you lose your phone and you use Google Authenticator or Microsoft Authenticator without cloud backup, you will need to use your backup codes to log into each account. Once logged in, disable two-factor authentication temporarily, then re-enable it with your new phone.
If you use Authy, your codes sync across devices. Install Authy on your new phone, verify your identity, and all your accounts will reappear. This is why many people prefer Authy over apps that store codes only on a single device.
Some password managers, including 1Password and Bitwarden, also sync authenticator codes across devices. If you already use a password manager, check whether it includes this feature before installing a separate app.
Prioritize Your Most Important Accounts
You do not need to enable authenticator-based two-factor authentication on every account you own. Start with the accounts that matter most. Your email account is the highest priority because it can be used to reset passwords on every other service. Your bank, investment accounts, and any account with payment information should be next.
Social media accounts, cloud storage, and work-related tools are also worth protecting. If losing access to an account would cause financial harm, personal embarrassment, or business disruption, enable two-factor authentication.
For accounts that do not matter as much, a strong unique password may be enough. Focus your effort where the risk is highest.
Turn Off SMS-Based Two-Factor Where Possible
Once you have your authenticator app set up, go back into your account security settings and disable SMS-based two-factor authentication if the option is available. Some services allow you to have both enabled at the same time, but this creates a vulnerability. If an attacker can bypass the authenticator app by requesting an SMS code, the stronger protection is pointless.
A few services still only offer SMS-based two-factor authentication. In those cases, SMS is better than nothing. But wherever you have the choice, use an authenticator app instead.
If you need help evaluating your current security setup or want to ensure your business systems are protected, our security services can perform an audit and recommend specific improvements.
Final Thoughts
Switching from SMS codes to an authenticator app takes less than an hour if you focus on your most critical accounts. The protection you gain is worth the effort. SIM swap attacks are real, and they happen to ordinary people, not just celebrities or executives.
Download an authenticator app today, enable it on your email and bank accounts, and save your backup codes. Your accounts will be significantly harder to compromise, and you will no longer depend on your phone carrier to keep you safe.
Image credit: Photo by Jakub Zerdzicki on Pexels.