Skip to main content
Threat Alerts

SMS Codes vs. Authenticator Apps: Which MFA Actually Stops Phishing?

SMS codes are the weakest MFA, yet many still rely on them. Here's why authenticator apps and hardware keys win, and what you should actually use.

You've been told to turn on two-factor authentication, and you did. Good for you. But here's the uncomfortable truth: the SMS code you get every time you log in isn't the shield you think it is. It's more like a screen door—better than nothing, but a determined attacker can walk right through it. In fact, CISA (Implementing Phishing-Resistant MFA) explicitly ranks SMS as the weakest form of MFA, vulnerable to SIM swapping, a social engineering attack where a criminal convinces your carrier to port your number to a SIM they control. That's not paranoia; it's a documented attack path.

So what's the alternative? You've got three main options: SMS codes, authenticator apps (like Google Authenticator or Authy), and hardware security keys (like YubiKey) or passkeys. This is a head-to-head comparison to help you choose, because your accounts depend on it.

The Contenders: SMS, Authenticator Apps, and Hardware Keys

Let's define the players. SMS codes are the ones you receive via text message—convenient, universal, but inherently insecure. Authenticator apps generate time-based one-time passwords (TOTP) on your device, so the code never travels over the cellular network. Hardware security keys, which use the FIDO2/WebAuthn standard, are physical devices that you plug in or tap, providing phishing-resistant authentication. Passkeys, which are essentially FIDO2 credentials stored on your device, fall into this same category. CISA (Implementing Phishing-Resistant MFA) calls FIDO/WebAuthn and PKI-based methods the gold standard—the only forms that resist phishing, push bombing, SS7 attacks, and SIM swapping.

Criteria 1: Security Against Phishing

This is the battleground. Phishing is the most-reported crime category to the FBI's IC3 (2024 Internet Crime Report), with 193,407 complaints in 2024 alone. Traditional MFA, including SMS and app-based codes, can be bypassed by phishing. CISA (Implementing Phishing-Resistant MFA) documents four ways traditional MFA fails: phishing, push bombing (where an attacker spams you with push notifications until you accept), SS7 protocol vulnerabilities, and SIM swapping. SMS is vulnerable to all four. Authenticator apps are better—they don't rely on your phone number—but they're still phishable if you're tricked into entering the code on a fake site. Hardware keys and passkeys, however, are phishing-resistant by design. They use cryptographic challenge-response, so the code never leaves the device, and the key is tied to the specific site, making it useless on a lookalike domain.

Criteria 2: Cost and Convenience

Here's where SMS seems to win—it's free and requires no setup. But that convenience is a trap. Authenticator apps are also free, but you have to install one and scan a QR code. Hardware keys cost money—typically $20 to $50 each—and you should buy two so you have a backup. Passkeys are free if you have a modern phone or laptop, but they require a platform ecosystem (Apple, Google, Microsoft). If you're the average user, an authenticator app is the sweet spot: it's free, more secure than SMS, and you probably already have a smartphone. Hardware keys are the choice for high-value accounts—email, bank, crypto—where you can afford a few extra seconds and a few dollars.

Criteria 3: Ease of Setup and Recovery

SMS is the easiest to set up, but recovery is a nightmare if you lose your phone number. Authenticator apps are slightly more complex, but you can back up your secrets or use recovery codes. Hardware keys are the most secure but the hardest to recover if you lose the key—that's why you buy two. CISA (Secure Our World) recommends MFA on every account that supports it, starting with email, banking, and cloud. Microsoft (Microsoft Security Blog) reports that enabling MFA can block over 99.9% of account compromise attacks. That statistic is so compelling that it should drive your decision: any MFA is better than none, but phishing-resistant MFA is the only one that truly closes the door.

Comparison Table

CriterionSMS CodesAuthenticator AppsHardware Keys/Passkeys
Phishing resistanceLow (vulnerable to SIM swap, SS7)Medium (not phishing-resistant)High (FIDO2/WebAuthn)
CostFreeFree$20-$50 for a key
Setup complexityLowMediumHigh (need to buy and manage hardware)
RecoveryEasy (but can be hijacked)Moderate (backup codes)Hard (need backup key)

Who Each Option Is For

SMS is for the person who refuses to install another app and understands the risk. I'd say it's better than nothing, but CISA (Implementing Phishing-Resistant MFA) says SMS should be a last resort. If you're a casual user with no sensitive data, SMS might be acceptable—but you likely have email and banking, so you're not that casual. Authenticator apps are for the vast majority: they're free, secure enough for most threats, and don't require extra hardware. Hardware keys are for the security-conscious, the high-profile, the journalists, the executives—anyone who might be targeted by sophisticated phishing campaigns. Passkeys are the future, but they're not available everywhere yet.

Which Wins?

There's no one-size-fits-all, but here's my blunt take: if you're not using a hardware key, you're leaving a door open. For most people, an authenticator app is a massive upgrade over SMS, and it's the minimum I'd recommend. But if you're a target—and you might be, because attackers don't discriminate—spring for a hardware key. The cost is trivial compared to the potential loss. The FBI's IC3 (2024 Internet Crime Report) received 859,532 complaints in 2024 with reported losses of about $16.6 billion, a 33% increase over 2023. That's not a statistic; that's your future if you're complacent.

Quick tip: If you must use SMS, at least set up a separate phone number for it that's not your main number, or use a VoIP service. But really, just switch to an app.

What I'd Actually Do

Here's my concrete recommendation. For your primary email and financial accounts, buy a hardware key (or use a passkey if supported) and register it. For everything else, install an authenticator app like Aegis or Raivo OTP (both free and open-source) and use that. Turn off SMS where possible; if a service only offers SMS, ask yourself if you really need that service. And check your passwords at Have I Been Pwned—that free service, run by Troy Hunt since 2013, lets you see if your email has appeared in a breach (Have I Been Pwned). Rotate any compromised passwords immediately. The bottom line: MFA is non-negotiable, but not all MFA is equal. Upgrade to phishing-resistant methods, and you'll be ahead of 99.9% of the internet.

Sources

  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About

Share this article:

Comments (0)

No comments yet. Be the first to comment!