Do you use SMS for two-factor authentication? Don't. (2024)

The coronavirus pandemichas lead to a rise in hackers and scammers preying on people's fears during these turbulent times, from SIM swapping to phishing scams meant to look like stimulus check emails. You would be wise to be on the lookout for coronavirus scams, and you'd be even wiser to use two-factor authentication to protect your personal information and online accounts. And if you are using two-factor authentication, you'd be wiser still to use an authentication app rather than receiving codes through text, also known as SMS.

Using an authentication app is a win-win. Not only is it more secure than getting codes texted to you, but it also makes the login process faster. Time for a quick Q&A:

Wait, what is two-factor authentication?

Two-factor authentication (2FA) -- also known as two-step verification or multifactor authentication -- adds a layer of security to your online accounts, from Amazon, Apple and Google to Facebook, Instagram and Twitter. Instead of entering only your password to access an account, you need to enter your password -- the first verification factor -- and then a code sent via SMS or a prompt through an authentication app -- the second factor. This means a hacker would need to steal both your password and your phone to break into your account.

Do you use SMS for two-factor authentication? Don't. (1)

Watch this: In a world of bad passwords, a security key could be your new best friend

Upgrade your inbox

Get cnet insider

From talking fridges to iPhones, our experts are here to help make the world a little less complicated.

So, why the move away from SMS?

For the simple fact that receiving 2FA codes via SMS is less secure than using an authentication app. Hackers have been able to trick carriers into porting a phone number to a new device in a move called a SIM swap. It could be as easy as knowing your phone number and the last four digits of your Social Security number, data that tends to get leaked from time to time from banks and large corporations. Once a hacker has redirected your phone number, they no longer need your physical phone in order to gain access to your 2FA codes.

Also, if you sync text messages with your laptop or tablet, then a hacker could gain access to SMS codes by walking off with such a device of yours.

Then there are the weaknesses in the mobile telecom system itself. In what's called an SS7 attack, a hacker can spy via the cell phone system, listening to calls, intercepting text messages and seeing the location of your phone.

All of the above scenarios are bad news for those receiving 2FA codes via SMS.

What should I use instead?

An authentication app such as Google Authenticator, Microsoft Authenticator or Authy. It has the advantage of not needing to rely on your carrier; codes stay with the app even if a hacker manages to move your number to a new phone. And codes expire quickly, usually after 30 seconds or so. In addition to being more secure than SMS, an authentication app is faster; you need only to tap a button to verify your identity instead of manually entering a six-digit code.

If you have an Android phone or an iPhone with the Google Search or Gmail app, you can set up Google prompts to receive codes without needing a separate authentication app. You'll receive 2FA prompts as push notifications on your phone that require a simple tap to approve.

Do you use SMS for two-factor authentication? Don't. (2)

Do I even need two-factor authentication if SMS is so vulnerable?

Yes! In addition to creating strong passwords and using different passwords for each of your accounts, setting up 2FA is the best move you can make to secure your online accounts -- even if you insist on receiving codes via SMS. Two-step verification via SMS is better than one-step verification where a hacker needs only to obtain or guess your password in order to gain access to your data. Don't be the low-hanging fruit with an account that is the easiest target for hackers.

But two-factor authentication is a hassle

That's not a question, but my counter would be that it's less of a hassle when done right and you are receiving codes via Google prompts or an authentication app where you don't need to enter six-digit codes. Sure, even then it does force you to take an extra step of grabbing and tapping your phone after entering your password to log into one of your accounts. I would argue, however, that the hassle of the second step of two-factor authentication pales in comparison to the hassle of getting hacked. At best, getting hacked is a hassle. More often, it's a mix of anger, pain, loss and confusion.

For more ways to keep safe and stay secure, here's how to improve your Zoom security to prevent Zoombombing,the guide to password security (and why you should care), how to secure your Amazon account and how to secure your Gmail account.

Do you use SMS for two-factor authentication? Don't. (2024)
Top Articles
The Mystical Powers of Obsidian: A Guide to Perception, Protection, and Healing
Netflix switches up pricing plans for 2023: Cheapest plan without ads now $15.49
Netronline Taxes
Koopa Wrapper 1 Point 0
My E Chart Elliot
What Are Romance Scams and How to Avoid Them
Craglist Oc
Davante Adams Wikipedia
Us 25 Yard Sale Map
Costco in Hawthorne (14501 Hindry Ave)
Wmlink/Sspr
Becky Hudson Free
Edgar And Herschel Trivia Questions
[2024] How to watch Sound of Freedom on Hulu
MindWare : Customer Reviews : Hocus Pocus Magic Show Kit
Cooking Fever Wiki
Equipamentos Hospitalares Diversos (Lote 98)
Costco Gas Foster City
Niche Crime Rate
Bing Chilling Words Romanized
A Biomass Pyramid Of An Ecosystem Is Shown.Tertiary ConsumersSecondary ConsumersPrimary ConsumersProducersWhich
Blue Rain Lubbock
Morristown Daily Record Obituary
Adt Residential Sales Representative Salary
Violent Night Showtimes Near Century 14 Vallejo
A Cup of Cozy – Podcast
Costco Gas Hours St Cloud Mn
Parkeren Emmen | Reserveren vanaf €9,25 per dag | Q-Park
Strange World Showtimes Near Savoy 16
Hesburgh Library Catalog
New Stores Coming To Canton Ohio 2022
208000 Yen To Usd
HP PARTSURFER - spare part search portal
Guinness World Record For Longest Imessage
2021 Tesla Model 3 Standard Range Pl electric for sale - Portland, OR - craigslist
Osrs Important Letter
Downloahub
Rogold Extension
The value of R in SI units is _____?
Sports Clips Flowood Ms
Forager How-to Get Archaeology Items - Dino Egg, Anchor, Fossil, Frozen Relic, Frozen Squid, Kapala, Lava Eel, and More!
Craigslist Red Wing Mn
Craigs List Jonesboro Ar
Thanksgiving Point Luminaria Promo Code
Daily Times-Advocate from Escondido, California
Download Diablo 2 From Blizzard
VPN Free - Betternet Unlimited VPN Proxy - Chrome Web Store
Yakini Q Sj Photos
How to Find Mugshots: 11 Steps (with Pictures) - wikiHow
Diario Las Americas Rentas Hialeah
Nkey rollover - Hitta bästa priset på Prisjakt
Electronics coupons, offers & promotions | The Los Angeles Times
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 6186

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.