openideurope.eu

SMS codes as a second factor: risks and better options

SMS codes beat having no second factor but are the weakest kind. Learn why they can be intercepted or redirected, when they are fine and what to use instead.

Login securityPublished

An SMS code is a second factor delivered as a text message. It is much better than a password alone, and it is easy, which is why so many services still use it. But among the common second factors it is the weakest, because the message travels through the mobile network and is tied to a phone number that can be taken over. The German Federal Office for Information Security (BSI) lists authenticator apps and hardware-based methods as better choices, and warns against receiving the text on the same device you log in with.

This does not mean you must panic. It means you should know where SMS falls short and upgrade the accounts that matter most.

Why SMS is weaker

1. The phone number can be taken over

In a SIM swap, a criminal convinces your mobile provider to move your number to a SIM card they control. From then on, your calls and texts, including login codes, go to them. They need personal data about you and a weak identity check at the provider, not any hacking skill.

2. The network was not built for security

Text messages are not end-to-end encrypted. Signalling systems used between mobile operators have known weaknesses that can, in targeted attacks, allow messages to be redirected. Such attacks require access to operator networks and are rare against everyday users, but the risk exists and is one reason security bodies steer away from SMS.

3. Phishing works just as well

A code you type into a fake website can be passed on to the real one in seconds. SMS offers no protection against that. The same is true of authenticator-app codes. Only phishing-resistant methods stop it.

4. Malware and previews

Malicious apps on a phone can read incoming messages. A code that appears on a locked screen can be read by anyone nearby. If you receive the code on the same phone you use for the login, an infection compromises both factors at once.

5. Practical limits

Messages arrive late or not at all with poor coverage or when roaming. Phone numbers get recycled when a contract ends, and an old number can end up with a stranger who then receives your codes or password-reset messages if you never updated the account.

When SMS is acceptable

  • When it is the only second factor on offer. Use it. A weak second factor is better than none.
  • For low-risk accounts. The effort to attack you may be higher than the value of the account.
  • As a temporary step while you set up something stronger.

Even then, protect the phone number itself: ask your provider for an additional PIN or password for changes to the contract or SIM, and do not use your mobile number as a public contact detail where you can avoid it.

A quick risk ladder

Situation Realistic risk with SMS
Everyday account, low value Low. Phishing is the more likely problem
Email, cloud storage, social media Moderate. Takeover can cascade to other accounts
Banking, crypto, business accounts Higher. These are the typical targets of SIM swaps
Travelling or roaming Practical problems, such as delayed or missing codes

If you travel often, remember that a text code needs mobile coverage and your own SIM. An authenticator app or hardware key works without either, which is a quiet advantage when your phone is abroad or in flight mode.

What banks and security agencies say

Many banks are moving customers from SMS codes to app-based approval, and security agencies have advised for years on methods where the secret does not travel over the mobile network. That does not mean SMS has suddenly become dangerous. It means stronger options exist that take hardly more effort. If your bank or email provider offers an app approval or a passkey, that is usually the better choice.

Better options, in order

  1. Passkeys. No code to type or intercept, bound to the real site. See passkeys explained.
  2. Hardware security keys. The strongest widely available second factor, see hardware security keys.
  3. Authenticator apps. Codes calculated on your device, no phone number needed. Compare options in our authenticator app review and read how TOTP codes work.
  4. Push approval from a trusted app, with number matching, where offered.
  5. SMS, where nothing else exists.

How to move away from SMS

  1. Log in to the account and open its security settings.
  2. Add a stronger method: authenticator app, passkey or security key.
  3. Save the backup codes in a safe place.
  4. Test the new method in a private window.
  5. Remove SMS as a login method, if the service lets you. Some keep it as a recovery option, so also check the recovery settings and update the phone number or remove it.

Be careful about the last step. Many accounts allow reset by SMS even when a stronger factor is on. An attacker will use the easiest route, so a strong factor next to an SMS reset is only partly protected. Read our page on account recovery for how to tighten this.

The takeaway

SMS codes are a reasonable starting point and a poor finishing point. If you use them today, you have already done the most important thing, which is having a second factor. Upgrade your email, platform and banking accounts first, and take the rest at your own pace.

In short

  • SMS is better than nothing, and the weakest common second factor.
  • The main weak points are SIM swapping, network weaknesses, malware and phishing.
  • Upgrade email, platform and banking accounts first.
  • Keep SMS only where there is no alternative, and protect your number with a provider PIN.

Frequently asked questions

Should I turn off SMS codes?

Not if SMS is the only second factor you have. Switch to something stronger where you can, then remove SMS as a login method if the service lets you. Never leave an account with no second factor just because SMS is imperfect.

Can someone really read my text messages?

It is uncommon for ordinary users, but possible through SIM swapping, weaknesses in the telephone signalling network, malware on the phone or a visible lock-screen preview. Targeted attacks are the realistic concern, not mass surveillance.

Why do some banks still use SMS?

SMS reaches almost everybody and needs no app. Many banks are moving customers to app-based or push approval, which is generally stronger. If your bank offers an alternative, take it.

Is a code by email better than SMS?

It depends on your email account. If your mailbox is well protected with its own strong second factor, an email code is not worse, but both are weaker than an authenticator app or a security key.

More in Login security