A woman in the next town over lost 4,000 dollars without her phone ever leaving her pocket. Someone walked into a phone store, convinced the clerk they were her, and moved her number to a new SIM card. Minutes later the login codes her bank texted were landing on the attacker’s phone, not hers.
That attack has a name, SIM swapping, and it is the reason security folks quietly wince when text-message codes are your only protection. So which second factor should you actually trust? Let us settle it.
Key takeaways
- Any two-factor login beats none, so if texts are your only option, keep them on.
- An authenticator app is meaningfully safer than text-message codes.
- Text codes are vulnerable to SIM swapping, where an attacker steals your phone number.
- Authenticator apps work offline and cannot be intercepted over the phone network.
- Switching from texts to an app takes about five minutes per account.
How each one works
Both methods do the same job, proving you hold your phone. They just prove it in very different ways, and the difference is where the safety gap lives.

With text-message codes, the service sends a code to your phone number when you log in. You read it off your messages and type it in. Simple, and no extra app needed.
With an authenticator app, a small app on your phone generates a six-digit code that changes every 30 seconds. The code is calculated on your device from a shared secret, so nothing is sent over the network at all. If you have not turned either on yet, start with our step-by-step guide to setting up two-factor authentication.
Why the app is safer
The gap comes down to one thing: text codes travel over the phone network, and that network can be attacked. The app’s codes never leave your device.
SIM swapping
This is the big one. An attacker who knows enough about you can trick your mobile carrier into moving your number to their SIM card. Once they control your number, every text code goes to them. An authenticator app is immune, because your number is irrelevant to it.
Phishing and interception
Text codes can also be phished. A fake login page prompts you for the code, and a scammer relays it in real time. App codes can be phished the same way, so neither is perfect here, but the app removes the SIM-swap risk entirely, which is the attack that actually drains bank accounts.
Authenticator apps work with no signal at all. On a plane, in a basement, or abroad without roaming, your codes still appear. Text codes need a working cellular connection, which fails at the worst moments.
Side by side
Here is the honest scorecard. Notice that texts are not useless, they are just second-best.
| Factor | Text-message codes | Authenticator app |
|---|---|---|
| Safe from SIM swapping | No | Yes |
| Works with no signal | No | Yes |
| Works when traveling abroad | Often not | Yes |
| Setup effort | Very low | Low |
| Extra app needed | No | Yes, one free app |
| Better than no 2FA | Yes | Yes |
When text codes are still fine
Do not let perfect be the enemy of good. There are real cases where texts are the right call, and turning them off would leave you less protected, not more.
If a service only offers text codes, use them. Many banks and older sites still do not support authenticator apps, and text-based 2FA is far better than a password alone.
If a family member finds the app confusing and would otherwise switch off 2FA entirely, texts keep them protected with something they will actually use. A second factor they tolerate beats a stronger one they disable in frustration.
Whatever you do, protect your phone-carrier account itself. Add a PIN or port-freeze with your carrier so nobody can move your number without it. This is the single best defense against SIM swapping, and it is free.
How to switch over in five minutes
Moving an account from texts to an app is quick, and you can do your most important accounts in one sitting.
- Install a free authenticator app, or use the code feature in your password manager.
- Open the account’s Security settings and find two-factor authentication.
- Choose to add an authenticator app. The site shows a QR code.
- Scan the code with your app, then type the six-digit code back to confirm.
- Save the new backup codes somewhere off your phone.
- If the option exists, remove text codes as a fallback, or leave them as a last resort.
I moved my own email and bank over on a Sunday morning, and the longest part was hunting for the setting. Once you have done one account, the rest feel like muscle memory.
What happens when you get a new phone
The one worry people raise about authenticator apps is losing them with a broken or replaced phone. It is a fair concern, and it has a clean answer built into modern apps.
Most authenticator apps now offer an encrypted cloud backup or a transfer feature. Microsoft Authenticator can restore your codes to a new phone from your account, and Google Authenticator syncs codes to your Google account when you turn that option on. Set this up the day you install the app, not the day your old phone dies.
If you would rather not sync to the cloud, the manual method still works: on the old phone, use the app’s export or transfer option to move codes to the new one before you wipe the old device. Your saved backup codes for each account are the final safety net if all else fails.
Fit this into the bigger picture
Two-factor choice is one piece of a small, sturdy routine. Pair a strong unique password from a manager with an authenticator app, and you have closed the two doors attackers use most.
If you have not sorted your passwords yet, our guide to choosing a password manager handles the first half, and the password security basics overview ties the whole plan together.
For a deeper explanation of why app-based codes hold up better, the Electronic Frontier Foundation’s guide to enabling two-factor authentication is clear and trustworthy.
Your afternoon checklist
- Install a free authenticator app on your phone.
- Add a PIN or port-freeze to your phone-carrier account.
- Switch your email from text codes to the app.
- Do the same for your bank if it supports an app.
- Save fresh backup codes somewhere off your phone.
- Leave text codes on for any service that offers nothing better.
- Check one login to confirm the app codes work.
Text codes are the training wheels of two-factor login: helpful, and far better than nothing, but not where you want to stay. Spend five minutes moving your most valuable accounts to an app, and you sidestep the one attack that empties bank accounts.