Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

Not all two-factor authentication is equal, and codes by text are the weak one

The second factor exists to survive a stolen password, and the methods differ enormously in whether they actually do.

Close-up view of a mouse cursor over digital security text on display.
Photograph by Pixabay via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Both approaches to two-factor authentication work. What differs is what they cost you, and the cost is what this sets out.

The difference in one place

  • Text message codes can be intercepted by transferring a phone number.
  • App-generated codes are better and still phishable in real time.
  • Hardware keys resist phishing because they check the site identity.

Why a second factor helps at all

A password can be stolen in bulk from a breach, guessed, or reused from another site, and none of those give an attacker anything else. Requiring a second, different proof means a stolen password alone is insufficient. The value therefore depends entirely on whether the second factor can be stolen by the same means as the first.

That is the question that separates the methods.

Text messages are the weakest common option

A phone number can be transferred to an attacker by persuading or bribing a mobile operator, an attack known as number porting or subscriber swapping. The signalling protocols underlying international messaging have documented weaknesses that allow interception in some circumstances. Messages also appear on lock screens by default, which is a simpler failure entirely.

It remains vastly better than no second factor, which is why it persists and why it should not be the choice where alternatives exist.

App-generated codes are a real improvement

A shared secret established at setup lets your device and the server independently compute the same short-lived code from the current time. Nothing is transmitted, so there is no message to intercept and no phone number to steal. The secret lives on the device, which means backing it up or enrolling a second device matters or a lost phone locks you out permanently.

In practice, the code can still be phished: a convincing fake site collects it and uses it within its short validity window.

Push approvals introduced fatigue attacks

Approving a prompt is easier than typing a code, which is why it became popular. Attackers with a stolen password trigger repeated prompts until somebody approves one out of irritation or confusion, which has succeeded against large organisations. Number matching, where the prompt displays a value that must be typed from the login screen, defeats this and is now widely deployed.

A prompt you did not initiate is always a signal that your password is already compromised.

Hardware keys break phishing structurally

A security key performs a cryptographic challenge that includes the identity of the site requesting it. A fake site has a different identity, so the key produces a response that is useless to the attacker, without the user needing to notice anything.

This is a structural defence rather than a matter of user vigilance, which is why it is the recommended method for high-value accounts. Passkeys apply the same principle using the device itself, which is why they resist phishing in the same way.

Recovery is the neglected weak point

Backup codes, recovery email addresses and support processes are all alternative routes into the account. An account protected by a hardware key and recoverable by answering questions about a childhood pet is protected by the questions.

In the datasheet, store backup codes offline, secure the recovery email with the same strength, and enrol a second key rather than relying on a weaker fallback. Attackers target recovery paths precisely because they are usually the weakest part of the design.

Side by side

ConsiderationWhat it means in practice
Why a second factor helps at allText message codes can be intercepted by transferring a phone number.
Text messages are the weakest common optionApp-generated codes are better and still phishable in real time.
App-generated codes are a real improvementHardware keys resist phishing because they check the site identity.

The takeaway

Rank them: hardware key, then app codes, then push, then text. And secure the recovery path to match.

The constraint is almost always physical, and marketing rarely mentions which one.

Questions readers ask

Is text-message two-factor worth using?

Yes, if it is the only option offered — it defeats bulk credential attacks. Move to an app or a hardware key wherever the service supports one.

What happens if I lose my authenticator phone?

You need the backup codes or a second enrolled device. Setting one of those up at enrolment time is the difference between an inconvenience and losing the account.

Data & Privacyauthenticationtwo-factorphishingsecurity
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas