You Shouldn’t Use Your Phone Number for Two-Factor Authentication, Anyway (2024)

Jake Peterson

You Shouldn’t Use Your Phone Number for Two-Factor Authentication, Anyway (1)

Credit: Pheelings media - Shutterstock

You should be using two-factor authentication (2FA) with each and every one of your accounts that allows it. You probably already do for at least some accounts, and it probably pisses you off from time to time. Every time you try to log in, you need to find your phone, check the code they texted you, and enter it to proceed. It’s all worth it in the name of account security though, right? Well, kinda. If you’re using your phone number to log into accounts, you’re actually putting yourself at unnecessary risk.

Why 2FA makes your accounts more secure

The problem with passwords is everyone knows yours. Sure, that’s hyperbole, but password leaks are all too common, and add up to billions of known passwords living on the internet for anyone to find and use. Worse yet, many of us forgo the advice to use a strong and unique password for every one of our accounts, opting to reuse the same, weak password for “easier” logins. If that password is leaked, all the accounts you use it for are compromised.

2FA fixes this problem by requiring both your password and access to a trusted device in order to authenticate yourself. Once you enter the correct password, 2FA then requires a corresponding code or device to let you in. Depending on the 2FA method you set up, the system might text that code to you (SMS-based), ask you to retrieve the code from an authenticator app, or require you to connect to a physical security key to confirm your identity.

When you set up 2FA, it doesn’t matter if a hacker steals your password: Without access to the 2FA authentication code or device, they’re stuck.

SMS-based 2FA is the weakest kind

Any additional form of authentication is better than nothing. However, SMS is the weakest method available. Phone numbers simply aren’t a secure form of identification. Bad actors can trick network carriers into transferring your phone number to their SIM card, in an attack known as SIM swapping, or pay another company to reroute your text messages to their number. In either scenario, they’ll receive your SMS 2FA codes, and will be able to break into your accounts without issue.

It isn’t just a 2FA problem, either. Relying on your phone number as a username for your accounts poses risk as well. There are so many recycled phone numbers in this country, there’s a good chance you have a number that used to belong to someone else. And if that person also used that number for an account without changing it, signing in with those digits might grant you access to their account. It’s a big problem for WhatsApp, with reports of users losing access to accounts because someone logged in with their old number.

We can thank Twitter for the renewed SMS-based discussion

SMS 2FA is in the news thanks to Elon Musk’s Twitter, which is doing away with the authentication method for free accounts. Starting March 20, only Twitter Blue subscribers will have access to SMS-based 2FA. The app will then deactivate SMS 2FA for any customers who continue to greedily horde their $8 from Musk.

Twitter will continue to support other forms of 2FA for free. Even still, the move is stupid. It’s hard enough to get users to adopt advanced security methods like 2FA in the first place. While some might take the time to set up another form of 2FA, many will not, meaning a significant slice of Twitter’s user base will be vulnerable come March 20. What would be smart would be to encourage your user base to switch to a more secure form of 2FA. Since Elon won’t, I will: Please use a more secure 2FA method.

You should use authenticator apps or security keys for 2FA instead

Whether you’re trying to protect your free Twitter account or any other, choosing a different 2FA option when available can shore up your security.

The most convenient alternative is using an authenticator app. A dedicated authenticator app, like Google Authenticator (iOS | Android) or Microsoft Authenticator (iOS | Android) ties your account to a 2FA code that generates every 30 seconds. When it’s time to log in, you open the app, check the code, then enter it. It eliminates the risk of someone remotely hijacking the process, since they’ll need physical access to the device containing the authenticator app to see the code. Apple even has a built-in authenticator in the password managers on iPhone and Mac, so you don’t need to download anything extra to get started.

Another secure 2FA option is the security key, which acts like an authenticator app in physical form. With this option set up, your account will ask you to connect your device to the security key, either by directly plugging it into the device, or through wireless communication like NFC. It’s far less convenient than using a free authenticator, but provides serious security for your accounts.

So, let’s let phone numbers be phone numbers, and reserve them for calls and texts. Leave the authenticating to the pros, and we’ll all be a little safer online.

You Shouldn’t Use Your Phone Number for Two-Factor Authentication, Anyway (2)

Jake Peterson

Senior Technology Editor

Jake Peterson is Lifehacker’s Senior Technology Editor. He has a BFA in Film & TV from NYU, where he specialized in writing. Jake has been helping people with their technology professionally since 2016, beginning as technical specialist at New York’s 5th Avenue Apple Store, then as a writer for the website Gadget Hacks. In that time, he wrote and edited thousands of news and how-to articles about iPhones and Androids, including reporting on live demos from product launches from Samsung and Google. In 2021, he moved to Lifehacker and covers everything from the best uses of AI in your daily life to which MacBook to buy. His team covers all things tech, including smartphones, computers, game consoles, and subscriptions. He lives in Connecticut.

Read Jake's full bio

More by Jake

AI

ChatGPT Now Shows You Its Thought Process

Gaming

Here's What's New In the Latest PS5 Update

Related Articles

How to Use FTP to Get Files to and From Your Android Phone

iPhone's New Passwords App Makes Two-Factor Authentication Easier

How to Use Two-Factor Authentication in the New macOS Passwords App

Use 'Bridgy Fed' to Connect Mastodon and Bluesky

You Shouldn’t Use Your Phone Number for Two-Factor Authentication, Anyway (2024)
Top Articles
Why mortgages and credit card rates could stay high through 2025
Overview of Double Entry
Barstool Sports Gif
Sdn Md 2023-2024
Lakers Game Summary
Lexi Vonn
Phone Number For Walmart Automotive Department
Die Windows GDI+ (Teil 1)
Owatc Canvas
Waive Upgrade Fee
123 Movies Babylon
Gt Transfer Equivalency
2021 Lexus IS for sale - Richardson, TX - craigslist
Taylor Swift Seating Chart Nashville
Chile Crunch Original
Stihl Km 131 R Parts Diagram
Hell's Kitchen Valley Center Photos Menu
Aberration Surface Entrances
Craigslist Sparta Nj
The BEST Soft and Chewy Sugar Cookie Recipe
Maxpreps Field Hockey
Titanic Soap2Day
Walgreens 8 Mile Dequindre
Surplus property Definition: 397 Samples | Law Insider
Greensboro sit-in (1960) | History, Summary, Impact, & Facts
Meridian Owners Forum
Cowboy Pozisyon
Enduring Word John 15
Motorcycle Blue Book Value Honda
They Cloned Tyrone Showtimes Near Showbiz Cinemas - Kingwood
Ryujinx Firmware 15
Dairy Queen Lobby Hours
Vip Lounge Odu
Worlds Hardest Game Tyrone
Joplin Pets Craigslist
Whitehall Preparatory And Fitness Academy Calendar
Babylon 2022 Showtimes Near Cinemark Downey And Xd
Kornerstone Funeral Tulia
Homeloanserv Account Login
Lamp Repair Kansas City Mo
Free Crossword Puzzles | BestCrosswords.com
Deepwoken: How To Unlock All Fighting Styles Guide - Item Level Gaming
Quiktrip Maple And West
Studentvue Calexico
Interminable Rooms
The Sports Academy - 101 Glenwest Drive, Glen Carbon, Illinois 62034 - Guide
Accident On 40 East Today
Euro area international trade in goods surplus €21.2 bn
Coleman Funeral Home Olive Branch Ms Obituaries
Edt National Board
Craigslist Centre Alabama
Wayward Carbuncle Location
Latest Posts
Article information

Author: Dan Stracke

Last Updated:

Views: 6540

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Dan Stracke

Birthday: 1992-08-25

Address: 2253 Brown Springs, East Alla, OH 38634-0309

Phone: +398735162064

Job: Investor Government Associate

Hobby: Shopping, LARPing, Scrapbooking, Surfing, Slacklining, Dance, Glassblowing

Introduction: My name is Dan Stracke, I am a homely, gleaming, glamorous, inquisitive, homely, gorgeous, light person who loves writing and wants to share my knowledge and understanding with you.