The most common forms of two-factor authentication (2FA) are SMS text messages and apps which generate codes which change every 30 or 60 seconds or so. To many, these choices might seem negligible. You are just essentially opening an app to get a 6-digit code whenever prompted. To the end-user, this probably feels like basically the same experience. I feel very strongly that authenticator apps are much safer and more secure than SMS-based text messages for 2FA. Let's take a look at a few reasons why.
Apps Don't Expose Your Phone Number
Tech companies don't always use your data in the way they claim when they request it. The Electronic Frontier Foundation documented how Facebook took phone numbers provided for security purposes and used them to serve targeted ads. Once they have your data on file for one reason (such as security) they may turn around and sell it to advertisers. In the case of a phone number, this means more spam phone calls.
Phone Numbers Are Only As Secure As Their Service Providers
Social engineering attacks against high-profile individuals commonly involve their wireless carrier. For example, a cryptocurrency investor filed a lawsuit against AT&T for $224 million after what he claims was the carrier's willing cooperation with a hacker, resulting in roughly $24 million worth of stolen cryptocurrency.
Phones connected to wireless carriers have an inherent liability that authenticator apps do not have. The potential for a carrier employee to intentionally or accidentally expose your account to an attacker is a real concern. Celebrities, political figures, and C-Suite leaders at any organization should start to think of themselves as potential targets of this kind of attack and take relevant precautions.
What Should You Use?
There are several good, reliable options out there for authenticator apps so that you can replace the use of SMS text-based authentication wherever possible.
Google's app has been a staple of this space for a long time. It is simple, clean, and easy to use, and is available cross-platform.
If you aren't comfortable using a Google product for any reason, Authy is a great option. It works on Android and iOS devices and is compatible with all of the same apps and services as Google Authenticator.
Best Possible Option: Physical Authentication Keys
If you are really serious about security, consider acquiring a physical authenticator key. The
Yubikey made by Yubico was so successful at Google that they
claimed it eliminated employee account takeovers for accounts protected solely with Yubikeys.
Google now also makes their own version known as the
Google Titan Security Key. Both products retail for about $50.
Michael Wilson, CPM
AI and digital strategy consultant and Certified Public Manager serving solopreneurs, businesses, nonprofits, and government. 15+ years at the intersection of technology and real-world results.