Skip to content
GuideEvergreen guide

Why the text message code is the weakest lock on your accounts

Six-digit texts feel secure and aren't. A practical ladder from SMS to hardware keys, plus the backup step almost everyone skips.

By Dean Shaw · Gear & Garage5 min read
Share

Start with your email. Not your bank, not your brokerage. Your primary email address is the skeleton key to everything else you own, because every "forgot password" link in your life lands there. Go into the security settings of that account today and add an authenticator app or a passkey. Then remove the phone number as a recovery method if the service lets you.

That one change does more than anything else on this page.

The reason is simple. A text message code isn't protected by your password, your phone's lock screen, or your fingerprint. It's protected by your mobile carrier's customer service desk, and that desk is staffed by people whose job is to help whoever's on the line get their service working again.

What actually goes wrong with SMS

The attack has a name. SIM swapping. Somebody calls your carrier, says they've lost their phone, gives your name, your address, maybe the last four of a card they pulled from a data breach, and asks for the number to be moved to a new SIM. Sometimes they don't even call. They walk into a store. Sometimes they pay a store employee.

The first sign you get is your phone dropping to "No Service" while you're sitting in a room with full coverage. By the time you've restarted it twice and decided the tower must be down, the codes are arriving on somebody else's handset. Email first, then whatever that email can reset.

There's a second problem that doesn't need a carrier at all. Codes sent by text are phishable in real time. You click a link in a message that looks like it came from your bank, you land on a page that looks like your bank, you type your password, and the page says "we've sent you a code." You did get a code. The site you're looking at typed your password into the real bank a second earlier, and it's waiting for you to hand over the six digits so it can finish the job. The whole thing takes under a minute.

A code is just a short string. Anything you can read and retype, you can be tricked into reading and retyping to the wrong person.

The ladder, worst to best

SMS and voice call codes. Bottom rung. Vulnerable to SIM swap and to live phishing. Still better than nothing, which matters later.

Email codes and magic links. Marginally better, but only as strong as the email account they land in. If that account is protected by SMS, you've built a circle.

App-generated codes (TOTP). The six digits that rotate every thirty seconds in Google Authenticator, Aegis, 2FAS, Authy, or your password manager. These never travel over a network. A SIM swap does nothing. Live phishing still works on them, because they're still a code you can be talked into typing.

Push approval. The "Is this you? Yes / No" prompt from Microsoft, Duo, or your bank's app. Better than a code, because there's nothing to type, and good ones show you the location and a number to match. The failure mode is fatigue. Get pinged at 3am for the eleventh time and some people tap yes to make it stop.

Passkeys and hardware security keys. Top rung, and the only options that are genuinely resistant to phishing. The key is bound to the real website's address. Put it in front of a convincing fake and it simply won't respond, because the domain doesn't match. It's not judging whether the site looks legitimate. It's checking a string, and the string is wrong.

What to actually do this week

Work through these in order. It's maybe forty minutes total.

  • Email. Authenticator app minimum. Remove SMS as a recovery option if the provider allows it.
  • Password manager. Same treatment. If the manager holds your TOTP codes as well as your passwords, understand you've put both factors in one box, and protect that box with a hardware key.
  • Your carrier account. Call them and ask for a port-out PIN, a number lock, or whatever they call it. This is the step people skip, and it's the one that blocks the SIM swap at the source. Ask specifically whether the lock stops in-store transfers, not just online ones.
  • Apple ID or Google account. These control your devices, your backups, and often your photos.
  • Bank and brokerage. Many still only offer SMS. Turn it on anyway and check whether they support an app. Some have quietly added it and never told anyone.
  • Domain registrar, if you own a domain. A stolen domain means stolen email.

Buy two keys, not one

If you go the hardware route, a YubiKey 5 NFC runs somewhere around fifty dollars, and cheaper Security Key models sit closer to thirty. Buy two. Register both on every account. Keep one on your keys and the second in a drawer, a safe, or a parent's house.

The single-key setup is how people lock themselves out permanently. You lose the key at an airport and now you can't get into the account that would let you remove the lost key. There's no customer service line that fixes that quickly, which is rather the point of the whole system.

Same logic for authenticator apps. When you enable one, the service shows you eight or ten backup codes. Print them. Actually print them, on paper, and put them somewhere your house fire insurance would cover. Screenshotting them into your photo library defeats the purpose, because your photo library is in the cloud account you're trying to protect.

The passkey question

Passkeys are the direction everything's heading, and for good reason. No code, no typing, just your face or your fingerprint unlocking a private key that lives on your device. Amazon, PayPal, Google, and a growing list of banks support them now.

The honest trade-off is portability. A passkey synced through Apple's iCloud Keychain works beautifully across your iPhone, iPad, and Mac, and then you buy an Android phone and discover you're doing some work. Cross-platform password managers handle this better, and the standards are improving, but it's not frictionless yet. If you live entirely inside one ecosystem, passkeys are an easy yes. If you hop between them, expect a few hours of housekeeping.

Where the advice bends

Don't refuse SMS because you read that it's weak. If your credit union offers text codes and nothing else, text codes are enormously better than a password on its own. Most account theft isn't a targeted SIM swap. It's a reused password from a breach dump, tried automatically against a thousand sites, and any second factor at all stops that cold.

The people who need to worry hardest about SIM swapping are the ones with something concentrated and liquid behind the login. Crypto holdings. A business bank account. A social account with a following someone would pay for. If that's you, hardware keys aren't optional, and neither is the carrier lock.

And take one more look at your recovery settings after you've made these changes. Half the accounts you just hardened still have your mobile number sitting in a box labeled "if all else fails." That box is the whole front door.

Share this article

Dean Shaw

Gear & Garage

Tests things until they break, then reports what broke first. Trucks, tools, watches, and the cheap version that costs more.

Watch

Worth an hour of your evening

More from Gadgets.

From channels we rate. Plays on YouTube.

    Marques Brownlee22 Sept

    The Apple Watch Has a Problem

    Linus Tech Tips21 Sept

    I Thought These Guys Made Cables

    Marques Brownlee16 Sept

    iPhone 18 Pro Review: All About that Chip

    Linus Tech Tips20 Sept

    Linus vs Robot