Skip to main content
FixMyTech

Authenticator App vs SMS Codes: Which to Use

By

Published

7 min read

Share

Short answer

Use an authenticator app wherever it is offered. SMS codes depend on your phone number, which can be moved to someone else's SIM by convincing your carrier — an app's codes are generated on the handset and cannot be redirected that way. SMS is still far better than no second factor, so keep it where it is the only option.

On this page

The advice to “switch from SMS to an authenticator app” gets repeated without the reason, so it reads like generic hardening and most people ignore it. The reason is specific and worth understanding, because it also tells you when SMS is perfectly acceptable.

SMS is the only second factor that depends on something you do not control: a record at your mobile carrier, maintained by staff who can be persuaded to change it.

What each one is actually tied to

An authenticator app stores a secret on the handset at setup time. From then on the app and the service independently compute the same six digits from that secret and the clock. Nothing travels over a network, there is no message to intercept, and the code exists only on that device.

An SMS code is generated by the service and sent to your phone number. A number is a routing entry at your carrier, not a property of your phone. Change the entry and the messages follow: a new SIM, an eSIM, or a different handset entirely.

That is the whole difference, and everything below follows from it.

The comparison that matters

Authenticator app SMS code
Tied to The device’s stored secret Your phone number
Works with no signal Yes No
Can be redirected by a third party No Yes, via the carrier
Survives changing carrier or country Yes No
Phishable by a fake login page Yes Yes
Recovery if the phone is lost Codes or sync, or nothing Replacement SIM
Setup effort Scan a QR code, save codes None

Two rows deserve attention because they cut in opposite directions.

“Can be redirected” is the security case for the app, and it is decisive. The attack is a number takeover: someone contacts your carrier with enough personal detail to pass their checks and has your number moved to a SIM they hold. Every SMS code for every account then arrives on their phone. This is a known, repeatedly documented attack pattern, and no setting on your phone prevents it, because the vulnerability is at the carrier.

“Recovery if the phone is lost” is the honest case for SMS, and it is why so many people quietly prefer it. Lose your phone with SMS 2FA and you walk into a shop, get a replacement SIM, and every account works again within a day. Lose it with an authenticator app and no recovery codes, and some of those accounts are gone permanently. What happens when the 2FA phone disappears sets out exactly which ones.

So the app is more secure and less forgiving. Switching without saving recovery codes trades one risk for a larger one.

What neither of them fixes

Both are six-digit codes you type into a page, which means both are phishable in the same way. A convincing fake login page asks for your password and your code together, and relays both to the real service inside the code’s 30-second window. The app’s secret is never exposed, but the attacker gets a session anyway.

Only passkeys and hardware keys close that gap, because they verify the site’s domain before responding and a lookalike domain gets nothing. What passkeys are and what they replace covers whether that is a switch worth making yet.

Push prompts sit between the two. They cannot be phished by a text field, but they can be approved by reflex, which is why the better implementations now show a number on screen that you must match.

When SMS is still the right answer

Not a reluctant concession. There are cases where SMS is correct:

  • The service offers nothing else. Many banks, utilities, government portals and older retailers only do SMS. SMS 2FA beats password-only by a wide margin.
  • Shared or low-stakes accounts. A streaming service or a loyalty scheme does not warrant a recovery-code regime.
  • The person using it will not manage an app. A parent who will lose the recovery codes and panic at a QR screen is genuinely safer on SMS. The best second factor is the one that stays switched on.
  • As a temporary bridge while you set up something stronger, then removed.

What makes SMS dangerous is not SMS itself. It is SMS on the account that controls everything else: your main email, your password manager, your carrier account. That is where a number takeover converts into total access.

How to switch without breaking anything

Work through this per account, and do not batch it.

  1. Install an authenticator and turn on its cloud backup before adding anything. Setting up Google Authenticator properly covers the order.
  2. Add the account by scanning the QR code in the service’s security settings, then confirm with a code so the pairing is actually active.
  3. Save the recovery codes. Before closing the page. This is the step that makes the switch safe rather than reckless.
  4. Sign out and back in once to confirm the app genuinely works for that account.
  5. Then remove SMS, if the service allows it. Some require a phone number on file regardless; where that is forced, the number stays as a recovery route and you accept it.

Step five is the one people skip, and skipping it means you have added effort without removing risk. An attacker chooses the weakest enabled method, not the one you prefer.

Lock down the number itself

Whatever you decide, protect the number, because it underpins far more than you think: password resets, bank verification calls, delivery confirmations.

Most carriers offer a port-out PIN, a number lock, or an account password separate from your online login. The names differ and the setting is usually buried, so ask them directly rather than hunting the app. It is the only control that addresses SIM swapping at the layer where it happens.

Realistic expectations

For most people the realistic outcome is a mix: authenticator apps on email, password manager and anything financial that supports it, SMS on the dozen services that offer nothing better, and a port-out lock on the carrier account. That is a reasonable place to land and does not require a weekend.

The failure worth avoiding is the half-switch — an app configured on your main email, recovery codes never saved, SMS left on as a fallback. That version is less secure than where you started and considerably easier to lock yourself out of.

Frequently asked questions

Is SMS two-factor authentication actually unsafe?
It is weaker rather than useless. It stops the common case of someone buying your password from a breach and trying it, which covers most real attacks on ordinary accounts. It fails against anyone who specifically targets you and can take over your number.
Why do banks still use SMS codes?
Partly because it works on every phone ever made with no setup, and partly because banks carry the fraud liability and have other controls — transaction monitoring, device fingerprinting, call-back verification. The code is one signal among many for them, rather than the whole defence.
Should I remove SMS once the app is set up?
Where the service allows it and you have recovery codes saved, yes. A weak fallback method is still a usable route into the account, so leaving SMS enabled keeps the weakest door open regardless of what you added.
Do authenticator apps work if I change phone number?
Yes, which is one of their quiet advantages. The secrets are tied to the app, not the number, so moving country or changing carrier does not break anything. SMS codes stop arriving the moment the number changes.
Is one authenticator app better than another?
They all implement the same TOTP standard and generate identical codes, so the differences are backup and convenience rather than security. What matters more is whether yours syncs or exports, because that decides what happens when the phone is gone.

All Accounts guides