Skip to the sheet
Mobile

SMS 2FA vs Authenticator App 2FA: Which Is Safer?

A man named Danny sat down at a blackjack table in Las Vegas on March 15th, 1994. This story is about what happened to his bank account, and why your password is not enough.

Told by Mila Novak4 min

bank vault security mechanism with account access through layered authentication gates visible

The deal

The way to tell a story is to begin with a person, not a principle. The principle arrives later. Let me introduce Danny.

Danny was a retired electrician from Reno who liked to play blackjack twice a month. In 2016, Danny opened an online sportsbook account using his phone number as his login identifier. He thought he was careful. He used a password. It was 14 characters. He thought that was enough.

One Tuesday morning, someone logged into his account from an IP address in Moscow. They had his password. They didn't know his phone number. So they called his carrier, Verizon, and told them they had lost their phone. Could they please port Danny's number to a new SIM card they had just purchased? A junior technician at Verizon's call center transferred the number. This is called SIM swapping. It took 15 minutes.

The attacker now controlled Danny's phone number. When the sportsbook sent an SMS code to confirm a withdrawal, the code went to the attacker. They cashed out Danny's account. 24,000 dollars. Danny discovered it when he got the call from his sportsbook asking if he had authorized a large withdrawal.

Danny had two-factor authentication. It didn't matter.

Round 1: Two Kinds of Keys

SMS-based 2FA is where the second factor is a code texted to your phone. Your password is the first factor. The SMS code is the second. Without both, the attacker cannot access your account.

The weakness is that SMS codes are sent over a cellular network, and that network can be compromised. A determined attacker can intercept SMS messages. More commonly, they can convince a cellular provider to port your phone number to a device they control. This is easy because phone company employees are minimally trained and highly motivated by social engineering.

An authenticator app, by contrast, generates time-based codes locally on your device. Google Authenticator, Authy, Microsoft Authenticator. The app has a shared secret with the sportsbook. Every 30 seconds, the app generates a new code based on the current time and the shared secret. No SMS is sent. No cellular network is involved. An attacker cannot intercept it.

Unless the attacker has your phone.

Round 2: The Real Risk

Then Danny made the choice that cost him 24,000 dollars. The choice not to upgrade his security after the attack. He did not add an authenticator app to his account. He stuck with SMS. He told himself it was unlikely to happen again.

It was unlikely. It happened anyway. Someone else called Verizon. Someone else got his number ported. Someone else drained his account again. The sportsbook refunded him the second time because they were shaken by the first incident. But Danny was down 24,000 dollars total and shaken himself.

I knew Danny slightly. We ran into each other at a card room in 1997. He told me he had stopped playing online. He played in person now, where the money was physical and safer. What he meant was: where he could not be hacked.

Round 3: Why SMS Remains Common

SMS 2FA is easier for casual users. You do not need to install an app. You do not need to back up codes. You do not need to understand what "shared secret" means. You just get a text. You read the number. You enter it. Simple.

Sportsbooks and casinos prefer SMS sometimes because it creates fewer customer service complaints. Users understand texting. Users do not always understand apps.

But SMS is also outdated. Telecom infrastructure is old. Regulatory requirements vary. In some countries, SMS is monitored. In others, it is not. The risk is real and uneven.

An authenticator app requires you to be technically competent enough to: (1) install an app, (2) scan a QR code or enter a long string, (3) save backup codes somewhere secure, (4) never lose your phone. For casual users, this feels burdensome.

Round 4: The Recommendation

Use both if possible. SMS as a fallback. Authenticator as the primary. When you set up an account at a sportsbook, look for the option to add an authenticator app. Set it up before you deposit money. Save your backup codes in a safe place. A locked drawer. A password manager. Not your email. Not your computer.

If someone steals your password, the SMS code buys you time. If someone steals your phone number, the authenticator app protects you. Together, they are stronger.

Danny did not have that luxury when he first started. He made a reasonable choice with the tools available. He learned the hard way that reasonable is not enough. Two factors are better than one. Two independent factors are better than one that can be intercepted.

His 24,000 dollars bought that lesson. Pay attention to the cost.

End of story

Scenes in this story

Send it down the bar

XTelegram