SMS 2FA no longer protects anything: what to use instead

SMS 2FA is now a restricted authenticator under NIST rules. SIM swapping, SS7 interception, real-time phishing, and what to concretely replace it with.

|

Reading time: 13 minutes

SMS 2FA no longer protects anything: what to use instead

On 9 January 2024, the official X account of the Securities and Exchange Commission, the US financial markets regulator, announced the approval of Bitcoin ETFs, a decision the market had been waiting on for months. Within minutes, Bitcoin gained more than 1,000 dollars per coin. Then the SEC denied it: the account had been hacked. The price fell back by more than 2,000 dollars.

What makes the case instructive is not the size of the market move, it is how ordinary the method was. According to the US Department of Justice press release, Eric Council Jr., 26, printed a fake ID with a portable card printer, walked into an AT&T store, and convinced an employee to transfer the phone number tied to the account onto a SIM card he controlled. He received the password reset codes by SMS and passed them to his co-conspirators. He was sentenced on 16 May 2025 to 14 months in prison.

One clarification is needed, and it changes how the case reads without weakening its lesson. According to the SEC’s official statement, multi-factor authentication had been disabled on that account in July 2023, at staff request. SMS was therefore not the second factor at the time, it was the recovery channel. And that is precisely what makes the example useful: second factor or back door, the phone number remains the point where the chain gives way.

What a second factor is supposed to guarantee

The principle fits in one sentence. A password alone is something you know; to it you add something you have (a phone, a physical key) or something you are (a fingerprint). An attacker who steals your password from a breach does not thereby hold your physical object.

The reasoning rests on an assumption that is rarely spelled out: that the second factor is genuinely tied to an object in your possession, and that presenting it proves something about where you are logging in. SMS fails on both counts.

SMS is not a possession factor

Receiving a code by SMS does not prove you hold a device. It proves that a phone number, assigned by a carrier and changeable by that carrier, points to a handset. These are not the same thing. Three vectors exploit that gap, and they are not fixed the same way.

SIM swapping

This is the attack used in the SEC case, and it relies on no technical flaw. The attacker gathers personal details about the target, often already available in public breaches, then contacts the carrier posing as them: phone lost, please move the number to a new SIM. If they are convincing, or if an employee is complicit, the number switches over and every SMS lands with them. The FBI’s 2024 IC3 annual report records 982 SIM swap complaints for that year alone and close to 26 million dollars in reported losses, counting only victims who filed a complaint. No software update fixes this vector: it does not target software, it targets a human business process.

SS7 interception

Signaling System 7 is the protocol that lets telephone networks worldwide talk to each other: routing a call, handling roaming, delivering an SMS from one carrier to another. It was designed in 1975, when the club of operators was closed, small, and each treated the others as trustworthy by construction. It therefore carries no native authentication between networks: a request that looks legitimate is treated as legitimate.

This is not a theoretical weakness. In December 2014, German researchers Tobias Engel and Karsten Nohl demonstrated it publicly at the Chaos Communication Congress: locating a subscriber and intercepting their SMS from the phone number alone. In 2017, real-world exploitation was confirmed: German carrier O2-Telefónica acknowledged that customers had had their bank accounts emptied, the attackers having obtained access to a foreign operator’s network and then set up SMS forwarding to capture banking confirmation codes.

Real-time phishing

The third vector matters most, because it depends on no telecom flaw and survives anything you might fix in the other two.

A fake site mirrors a service’s login page perfectly. You enter your username and password, which the fake site immediately relays to the real one, which then sends an SMS to your phone. The SMS does reach you, and it is genuine. You type the code into the fake site, which relays it in turn within seconds. The session opens, and the attacker is the one holding it.

This is called an adversary-in-the-middle attack. It is industrialised: tools such as Evilginx, a reverse proxy that appeared in 2017, or kits sold on monthly subscription, put it within reach of anyone. What is stolen is not just the code either, it is the session cookie that then allows the attacker to stay logged in without going through any authentication again.

The point is architectural. The code sent by SMS carries no information about the site that requested it. It therefore cannot tell the real from the fake: it is valid wherever it is typed.

This is no longer an opinion, it is an official position

The strongest argument against SMS does not come from vendors, it comes from the institutions that write the standards.

In July 2025, the US NIST published the final version of SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management. The text creates an explicit category of restricted authenticators, reserved for mechanisms whose ability to resist attack has degraded as threats evolved. Section 3.1.3.3 places use of the public switched telephone network there, meaning codes sent by SMS or voice call: “Use of the PSTN for out-of-band verification is restricted as described in this section and SHALL satisfy the requirements of Sec. 3.2.9.” In practice, a service still relying on it must offer an unrestricted alternative, inform its users of the risk, and hold a migration plan.

In December 2024, CISA, the US cybersecurity agency, had published its Mobile Communications Best Practice Guidance, following the Salt Typhoon espionage campaign in which actors affiliated with the Chinese state penetrated several US telecom carriers. The wording leaves no room for interpretation: “Do not use SMS as a second factor for authentication. SMS messages are not encrypted”, and further on, bluntly: “Only FIDO authentication is phishing-resistant.” The document explicitly recommends hardware FIDO keys, naming Yubico and Google Titan, and specifies that once FIDO is enabled, SMS must be disabled, failing which it remains as an exploitable fallback.

Authenticator apps: real progress, a partial solution

TOTP apps, for Time-based One-Time Password, generate a six-digit code that changes every thirty seconds, computed locally from a secret shared at setup and the current time. Nothing travels over the phone network.

The gain is immediate: SIM swapping becomes irrelevant since the number is no longer involved, and so does SS7 interception since no message is carried. Migrating to an authenticator app is worth doing on every account that cannot go further.

But the third vector remains intact. A TOTP code typed into a fake site is relayed to the real site exactly like an SMS code. The app has no idea where you are logging in: it displays a number, and that number is valid for whoever presents it inside its thirty-second window. CISA says as much in the same terms, authenticator codes are better than SMS but remain vulnerable to phishing.

TOTP is an honest intermediate step, not a destination.

Why a FIDO2 key changes the nature of the problem

A FIDO2/WebAuthn hardware key does not merely make the attack harder, it removes its mechanical possibility.

When you register it with a service, the key generates a cryptographic key pair dedicated to that service. The public half goes to the service, the private half never leaves the chip and is neither exportable nor readable. No shared secret that could be copied, no six-digit code to intercept.

Then comes the decisive mechanism, origin binding. At login, the browser passes the key the real domain name of the page on screen. That information is included in the signed data, and the browser enforces it: the page’s JavaScript can neither alter nor forge it.

A FIDO2 key does not make phishing harder to pull off. It makes the result of phishing unusable.

Take the adversary-in-the-middle attack again, this time with a key. The fake site is perfect, the victim notices nothing and touches the key. The browser passes the real domain of the page, the fraudulent one. The key finds that no pair exists for that domain, or signs for it, producing a signature the real service will reject. Either way, the attacker gets nothing usable.

That is where the difference in kind lies. With SMS or TOTP, security ultimately rests on the user’s vigilance, on their ability to spot a spoofed domain in an address bar at a moment when they are rushed and the page looks normal. With FIDO2, that check is performed by a machine, every time, without depending on anyone’s attention. It is that transfer of responsibility that counts, more than the cryptographic strength.

The effect is measurable. Google made keys mandatory for its employees in early 2017 and reported in 2018 that it had recorded no account compromise across more than 85,000 people.

The real limits of hardware keys

Presenting them as perfect would be dishonest, and useless for preparing the decisions that matter.

The cost is real. Expect 25 to 60 euros depending on the model, more for biometric versions, and to double that.

Losing a key is the real risk. A single key on a critical account is a design error. You need two registered on every important account, one of them kept elsewhere, with a relative or in a safe. The second is not a convenience, it is what makes the first usable without fear.

Coverage is incomplete. Many services, banks in Europe in particular, do not yet support FIDO2, hence the prioritisation that follows.

A key can be stolen. Hence the need to set a PIN on the key, or to choose a fingerprint model: without that, the object alone is enough for whoever picks it up.

The fallback remains the weak link. Enabling FIDO2 without disabling SMS protects nothing: an attacker simply takes the route left open. Migration is only finished once the old mechanism is removed from the account, recovery options included.

On hardware, the YubiKey range covers the widest span of protocols, Google Titan keys are cheaper and limited to FIDO, Nitrokey and SoloKeys offer alternatives with open, auditable firmware, and Token2 makes models with a built-in keypad where the PIN is entered on the key rather than on a keyboard. There is no bad choice among FIDO2-certified keys, the protocol is the same and only the side uses differ.

Where to start when you cannot change everything

The order of migration is not a matter of preference, it follows from the dependencies between your accounts.

  1. Your main mailbox first. It receives the reset links for almost everything else. An attacker who controls it takes the other accounts one by one, without attacking any of them directly. Nothing deserves to be secured before it.
  2. The password manager. It concentrates the first factor for all your access, so its protection must match that of the best-protected account it holds. This is the moment to check the quality of the master password, a subject covered in detail in our article on entropy and the science behind your security.
  3. Financial accounts and crypto platforms. Targets of immediate value, where a compromise becomes an irreversible loss within minutes.
  4. Social accounts with an audience. The SEC case shows what the word of a followed account is worth, and the damage is not always to its owner.
  5. The rest can wait, with a TOTP app replacing SMS. A forum or a streaming service does not justify the same effort.

For accounts that do not yet support FIDO2: move to TOTP wherever possible, and ask your carrier to lock number portability, a free option with most of them.

What this says about Arpokrat’s approach

This piece describes a problem that exists only because an identifier was placed at the centre of the system. The phone number was never designed as proof of identity: it became the backbone of online authentication out of habit, and all three attacks described above exploit that repurposing.

That is the reasoning behind the design of the Arpokrat Messenger protocol: no phone number, no email address, no account. The user exists as a set of cryptographic keys held on their own device, and connections are made through single-use invitation links. The logic is FIDO2’s, one level up: what a third party does not hold cannot be extracted from them, whether by social engineering against a carrier or by legal compulsion. This consistency with Zero-Knowledge architecture is developed in our article on harvest now, decrypt later.

A hardware key that signs without ever exposing its secret is, incidentally, also how an offline crypto wallet works, as detailed in our complete cold wallet guide: keep the secret part in a dedicated object, and let nothing out but a signature.

Conclusion

SMS 2FA was not badly designed. When it became widespread, in the early 2010s, it was a considerable step up from the password alone, and it had going for it the one quality that counts at scale: everyone already owned a phone.

The problem is not its invention, it is its survival. The SS7 demonstrations date from 2014, the real banking exploitation from 2017, the industrialisation of real-time phishing from the end of that decade. CISA wrote that it should no longer be used in 2024, NIST formalised the restriction in 2025. Roughly a decade separates the moment the flaws became exploitable at scale from the moment institutions put it in writing. And SMS remains the default second factor for most consumer services.

That gap is the real information in this piece. Security mechanisms do not disappear when they stop working, but when something equally simple comes along to replace them, and that takes far longer. The question is therefore not whether you should abandon SMS, which has been settled for years. It is which other protections you take for granted are already, without anyone having written it down yet, in the same situation.

Sources