Skip to main content
Privacy Tools

Why I Ditched SMS Codes for a Hardware Key (and You Should Too)

SMS codes are better than nothing but far from safe. Here's why I switched to a hardware security key and why you should make the leap to phishing-resistant MFA.

Imagine you're at a coffee shop, logging into your bank account. Your phone buzzes with a six-digit code. You type it in, and you're in. Feels secure, right? But what if I told you that someone could be reading that code right now, thousands of miles away, and you'd never know? That's the reality of SMS-based multi-factor authentication in 2025. It's not just weak—it's a liability.

I'm not a security researcher or a paranoid sysadmin. I'm just a guy who got tired of reading about people losing their life savings to a simple phishing scam. And the more I dug into the facts, the clearer it became: we're all one careless click away from disaster, and the tools to prevent it are right in our pockets—if we're willing to ditch the outdated methods.

Here's my thesis: You should stop using SMS codes for MFA and switch to phishing-resistant methods—specifically hardware security keys like FIDO2 or passkeys—on every account that supports them. Yes, it's an inconvenience, but it's the single most effective step you can take to protect yourself from the most common attacks, and the evidence is overwhelming.

The Problem with SMS: It's Not Just You

Let's start with the basics. Multi-factor authentication (MFA) is supposed to require two or more different authenticators—something you know, something you have, or something you are—so that a stolen password alone can't unlock your account (CISA, Implementing Phishing-Resistant MFA). SMS codes are a classic 'something you have' factor, but they're about as secure as a paper lock on a bank vault.

CISA explicitly lists four ways traditional MFA gets bypassed: phishing, push bombing, SS7 protocol vulnerabilities, and SIM swapping. SMS codes are vulnerable to all four. A determined attacker can convince your cellular carrier to transfer your number to a SIM card they control—a social engineering trick that CISA describes in detail—and then receive your codes themselves (CISA, Implementing Phishing-Resistant MFA).

And it's not a rare attack. Microsoft reports more than 300 million fraudulent sign-in attempts to its cloud services every day (Microsoft Security Blog). That's not a typo. 300 million. Every day. If even a fraction of those target SMS codes, the odds are stacked against you.

The Solution: Phishing-Resistant MFA

So what's the alternative? CISA ranks phishing-resistant MFA—specifically FIDO/WebAuthn and PKI-based methods—as the gold standard, the form resistant to phishing, push bombing, SS7, and SIM swap attacks (CISA, Implementing Phishing-Resistant MFA). WebAuthn, developed by the FIDO Alliance and published by the W3C, is supported in major browsers, operating systems, and smartphones (CISA, Implementing Phishing-Resistant MFA). It's the only widely available phishing-resistant authentication, and it's been around for years.

What does this mean in practice? Instead of typing a code from a text, you plug a small USB key into your computer or tap your phone, and the authentication happens cryptographically. The key never leaves your possession, and it can't be phished because the protocol doesn't rely on a shared secret that can be intercepted.

I made the switch last year. I bought a $20 hardware key (you can find them for less), set it up on my email, bank, and social media accounts, and I haven't looked back. The first week was awkward—I kept forgetting to bring it with me—but now it's as natural as reaching for my wallet. And the peace of mind is worth the minor hassle.

But What About Convenience?

The most common objection I hear is, 'I can't carry a hardware key everywhere.' Fair enough. I don't carry mine everywhere either. But here's the thing: you don't need to use a hardware key for every login. CISA recommends app-based one-time passwords or mobile push with number matching when phishing-resistant MFA isn't available, and says SMS should only be a last resort (CISA, Implementing Phishing-Resistant MFA). So start with your most critical accounts—email, banking, cloud storage—and use app-based codes for the rest.

Another objection is that hardware keys can be lost or stolen. True, but you can buy two and keep a spare in a safe place, just like you'd keep a spare house key. And even if someone steals your key, they'd still need your password to get in—it's MFA, after all.

I'll admit, I used to be dismissive of MFA. I thought, 'I'm not that important; why would anyone target me?' But then I read the FBI's IC3 report: in 2024, they received 859,532 complaints with reported losses of about $16.6 billion—a 33% increase over 2023 (FBI IC3). Attackers aren't targeting you because you're special; they're targeting you because you're vulnerable. And the most common way they get in? Phishing. Verizon's 2024 DBIR found that 68% of data breaches involve a non-malicious human element, including people falling for phishing (Verizon 2024 DBIR).

So, yes, convenience matters. But losing your life savings to a scam is a lot less convenient than carrying a small piece of plastic.

Make the Switch Today

Here's my final recommendation, plain and simple:

  • Start with your email. Your email is the key to everything else. If an attacker gets in, they can reset your other passwords. Enable phishing-resistant MFA on your email provider first.
  • Buy a hardware key. They're cheap, and you can find guides online for which ones work with which services. I recommend YubiKey, but there are other options.
  • If you can't use a hardware key, use an authenticator app. Apps like Google Authenticator or Authy generate codes that don't rely on SMS.
  • Check if you've been in a breach. Use Have I Been Pwned to see if your email has been exposed, and change any passwords that show up (CISA, Secure Our World).

This isn't just about you. It's about making life harder for the attackers who are out there every day, trying to break in. Microsoft claims that enabling MFA can block over 99.9 percent of account compromise attacks (Microsoft Security Blog). That's a number I can get behind.

The single most important thing to remember is this: Your password is no longer enough. Stop treating it as if it is. Switch to phishing-resistant MFA today, and you'll sleep better tonight.

Sources

  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About

Share this article:

Comments (0)

No comments yet. Be the first to comment!