🎙️
2

Hot take: 2FA through SMS is not better than nothing

Last year I was sitting in a Starbucks in Nashville when I got a text with my 2FA code for my bank account. I hadn't logged in. Someone had already gotten my password through a data breach and was trying to break in. The SMS 2FA actually saved me because I could deny the request immediately and change my password. But here's the thing - I later found out SIM swapping is way too common now and SMS codes can get intercepted. Has anyone else had to switch to an authenticator app after a close call?
2 comments

Log in to join the discussion

Log In
2 Comments
hayden144
hayden1441mo ago
Switched to Authy after my phone number got ported out without my permission last spring. Took me two days to get it back from T-Mobile. Those SIM swap attacks are real and way easier than people think. SMS is still better than nothing for most people but once you have a close call you don't want to rely on it anymore. Get an authenticator app and make sure you backup the recovery codes somewhere safe. Also check if your bank supports hardware keys like YubiKeys, those are even better.
6
taylor_miller10
oh man, i had almost the exact same thing happen to me last year. got a random 2FA code from my email and i live in a different state, so i knew something was up. SMS saved me that time too, but then i started reading about SIM swapping and it freaked me out. i switched to Google Authenticator like two weeks later, and honestly it feels way more secure. maybe it's just me but i'd rather have my codes not sitting on some carrier's network where anyone with a fake ID can steal them.
1