Text size:
Tuesday Tidbit #2

Text codes vs. authenticator apps: which 2FA is actually stronger

The second lock on your accounts comes in three flavors — here's the one worth switching to, and why.

August 25, 2026

Last week was about passkeys — the sign-in that skips the password entirely. Most of your accounts don’t offer that yet, though, so here’s the tool protecting them today: two-factor authentication. This week’s tidbit isn’t about turning it on — you may already have it on. It’s about which kind you picked, because they’re not equally strong.

The lock you already have

A password alone is one lock on the door. Two-factor authentication adds a second one: after your password, the site asks for a short code before letting you in. Even if someone steals your password, they’re stuck at the second lock.

If you followed the password guide’s advice to turn on “a texted code at sign-in,” you already have this. Good — that’s real protection, and it’s better than a password alone every time. But a texted code is only one of three ways to receive that second lock, and it happens to be the weakest one.

Why the delivery method matters

Think of the three kinds as three ways a spare key can reach you:

  1. A code texted to your phone. The code travels over the phone network to reach you — and anything that travels can, in rare cases, be redirected.
  2. A code from an authenticator app (like Google Authenticator or Microsoft Authenticator). The code is generated right there on your phone, never sent anywhere, so there’s nothing in transit to redirect.
  3. A physical security key. A small device you plug in or tap — the strongest option, and basically what a passkey is built on under the hood.

The honest catch

The reason texted codes are weaker has a name: a SIM swap. A scammer calls your phone carrier, convinces them to move your phone number onto a SIM card the scammer controls, and from that moment your texted codes go to them, not you. It’s not common, and it takes real effort on the scammer’s part — but it’s a documented attack, and it only works against the texted-code method. An authenticator app closes that door completely, because there’s no text message for anyone to redirect.

This isn’t a reason to panic about codes you’re already using — it’s a reason to upgrade the accounts that would hurt most if someone got in: email, banking, anything with saved payment info. Everything else can stay as-is.

(If your accounts don’t offer passkeys yet — most banks don’t — this is the next-best lock. And if you already turned one on last week, you’re already using the strongest version of this.)

One thing to try this week

Open your email account's security settings — it's the one to start with, since it can reset everything else. If it offers a choice between a texted code and an authenticator app, switch to the app. Takes about five minutes; Google Authenticator and Microsoft Authenticator are both free.

Where this comes from

Got a thought on this issue? Tell us what you think — takes about 30 seconds.

Want help putting this into practice?

If you'd rather walk through it with a person than a page, just call — no rush, no judgment.