Buying Guides

Why SMS Two-Factor Is Not Safe Enough

SIM swapping makes text-message codes the weakest form of two-factor. What to move to instead, and why backup is the feature that decides which app you pick.

GetSmartStuffs BUYING GUIDES

Disclosure: GetSmartStuffs is reader-supported. When you buy through links on our site, we may earn an affiliate commission — at no extra cost to you. We only recommend gear we'd use ourselves. Learn more.

Two-factor by text message is far better than no second factor at all — but it is the one form of it an attacker can take without touching your phone. A SIM swap moves your number to their device, usually by social-engineering a carrier rep, and every code you rely on then arrives on their handset. Codes generated on your device instead of sent to your number remove that entire attack. Which app you use to generate them matters much less than making the switch, and the feature that should decide it is backup.

Why texted codes fail

If you take one thing from this guide: move your two-factor codes off SMS and onto an app. Texted codes were a huge step up when they arrived, but they carry a specific weakness — SIM-swapping. An attacker convinces or bribes your mobile carrier to move your phone number onto their SIM card, and every code texted to “you” now arrives on their phone. It happens, it’s targeted, and there’s nothing you can do from your side once your number’s been moved.

An authenticator app sidesteps this entirely. It generates codes on your device, from a secret shared once at setup plus the current time — no phone number involved, nothing to reroute. That’s the whole security case, and it’s a strong one. (Where a service offers a passkey, that’s better still, because it’s phishing-proof too — see our passkey guide. But plenty of accounts offer app-based 2FA and not passkeys yet, so a good authenticator remains essential.)

The one nuance worth stating plainly: SMS 2FA still beats no 2FA. For an account that offers nothing but SMS, turn it on rather than skipping a second factor entirely. Just don’t choose SMS when an app or passkey is on the table.

The feature that actually matters: backup

Most authenticator apps generate the same standard codes (called TOTP — time-based one-time passwords), so on pure security they’re near-identical. The thing that separates a good experience from a miserable one is what happens when you lose, break, or replace your phone.

  • An app with encrypted cloud backup or account sync restores all your codes on a new phone by signing in. Painless.
  • An app with no backup strands every code on the old device. Your only way back into each account is the one-time recovery codes that service gave you — and if you didn’t save those, you’re into slow, uncertain account-recovery support queues.

So when you compare apps below, read the “backup” column first. It’s the difference between a cracked screen being an annoyance and being a weekend lost to lockouts.

The main free authenticator apps, compared

These are free and non-affiliate — we’re listing them on merit. Details like exact backup mechanics change, so verify current specifics before relying on them.

AppCostBackup / syncBest forWorth knowing
Google AuthenticatorFreeCloud backup tied to your Google accountAnyone in the Google ecosystem who wants simple and reliableLong the default; added cloud sync after years of being backup-less. Secure your Google account well, since it now guards your codes.
Microsoft AuthenticatorFreeCloud backup tied to a Microsoft accountWindows/Microsoft 365 households; also handles Microsoft passwordless sign-inDoubles as approval prompts for Microsoft accounts. Ties your backup to your Microsoft account’s security.
Proton AuthenticatorFreeEncrypted sync across devicesPrivacy-minded users; anyone already in the Proton ecosystemFrom the privacy-first Proton team; fits alongside Proton Mail, VPN, and Pass. Cross-platform.
AuthyFreeMulti-device cloud backupPeople who want codes on several devices at oncePopularized encrypted multi-device backup. Check current platform availability before committing.
2FASFree, open-sourceOptional backup to your own cloud storagePeople who want open-source and control over where backups liveCommunity-favored open-source option; you control the backup location.
Aegis (Android)Free, open-sourceEncrypted local/manual exportAndroid users who want open-source and offline-first controlAndroid-only; encrypted exports you manage yourself rather than automatic cloud sync.

A few honest reads on the table:

  • You can’t really go “wrong” among these on security — they generate the same codes. Pick on backup, ecosystem fit, and whether you value open-source.
  • Backup convenience and backup control are a trade-off. Automatic cloud sync (Google, Microsoft, Proton, Authy) is easiest; open-source options (2FAS, Aegis) hand you more control over where your backup lives, at the cost of a little more setup.
  • Ecosystem fit is a real tiebreaker. If your life is already in Google, Microsoft, or Proton, using their authenticator keeps things tidy — one fewer account to secure separately.

The option most people overlook: your password manager

Here’s the recommendation that surprises people. If you already use a password manager, it can store your two-factor codes too — and for many people that’s the best home of all. Your password for a site and its 2FA code then live in the same vault, sync to every device together, and get backed up together. No separate app, no separate backup to worry about.

1Password

1Password

Stores your 2FA codes right alongside each login and autofills them — passwords and codes sync together across every device, with the category's smoothest apps and family setup.

From $2.99/mo (Individual, billed annually) (verified 2026-07-10)

The trade-off is real and worth stating: putting the password and its code in one vault means that if someone fully compromises your vault, they have both factors. For most people that risk is small — a properly secured vault (strong master passphrase, its own second factor) is very hard to breach — and the convenience plus guaranteed backup outweighs it. Security purists prefer to keep codes in a separate app so the two factors live apart, and that’s a perfectly defensible choice. Both are far better than SMS; pick based on whether you value one-place convenience or factor-separation more.

One caveat if you go this route: put the second factor on the vault itself using a different method — ideally a passkey or a separate authenticator — so your manager isn’t guarding its own front door with a key kept inside. We cover securing the vault in the guide to ending password reuse.

Building a whole privacy stack? Consider Proton

If you’re assembling a privacy-first toolkit rather than just picking one app, keeping your authenticator in the same family as your email and VPN has a tidiness appeal.

Proton

Proton

Proton Authenticator sits alongside Proton Mail, VPN, and Pass — if you want one privacy-focused company across your email, browsing, passwords, and 2FA, the suite is a legitimately simple answer.

Free, or from $3.99/mo (Mail Plus, billed annually) — full suite (Unlimited) from $9.99/mo (verified 2026-07-10)

This isn’t necessary — a standalone free authenticator is completely fine — but if you’re already leaning toward Proton for email and VPN (see our guide to whether you need a VPN), using its authenticator too means one company, one account to secure, one privacy philosophy across the stack.

How to choose: the criteria that actually matter

Cutting through the feature lists, here’s what we’d weigh, in order:

  1. Backup and recovery. Non-negotiable, and covered above. If losing your phone would strand your codes, you’ve chosen wrong. Favor an app with encrypted cloud sync, an open-source app with a backup you configure, or your password manager.
  2. Where it runs. It has to be on the devices you actually use. Most of these are cross-platform; a couple (like Aegis) are single-platform, so check before you commit.
  3. Ecosystem fit. Already deep in Google, Microsoft, or Proton? Their authenticator means one fewer separate account to secure.
  4. Open-source vs convenience. If you value inspectable code and controlling your own backup location, 2FAS and Aegis lead. If you value automatic, hands-off sync, the big-ecosystem apps lead.
  5. Consolidation vs separation. Password manager holding your codes = maximum convenience and unified backup. Separate app = your two factors live apart. Both beat SMS; choose your preference deliberately.

Notice what’s not on the list: fancy interfaces, extra features, brand prestige. On core security these apps are equivalent, so don’t overthink the pick — the mistake that actually hurts people is staying on SMS, not choosing the “wrong” excellent app.

What’s not worth it

  • Staying on SMS out of habit. It’s the SIM-swap weak point. Move important accounts to an app (or a passkey) and keep SMS only where nothing else is offered.
  • An authenticator with no backup, in 2026. Being stranded after a lost phone is an avoidable, self-inflicted problem now that good backup options are free.
  • Paying for a standalone authenticator. The free options here are excellent. The only thing worth paying for adjacent to this is a password manager or a privacy suite you’d want anyway — the authenticator rides along.
  • Screenshotting your backup codes to your camera roll. Synced, searchable, and exposed if your cloud account is. Put recovery codes in a secure note or on paper.

Don’t skip the recovery codes

Whichever app (or vault) you choose, when you enable 2FA a service hands you a set of one-time backup codes — your way in if your authenticator and its backup both fail. Treat them as part of setup:

  • Good homes: a secure note attached to that login in your password manager, or a printed sheet somewhere safe at home. Both is reasonable for critical accounts.
  • Bad homes: a screenshot in your photo library, an email to yourself, a file called codes.txt on the desktop.

This is the same discipline we walk through in the afternoon plan to secure your accounts — the authenticator is one piece of that larger setup.

The bottom line

Pick a free authenticator with solid backup, or — if you already use one — let your password manager hold your codes. Move your important accounts off SMS onto whichever you choose, save the recovery codes properly, and turn on passkeys wherever they’re offered on top. That’s the whole job, and it closes the most common remaining gap after a password manager. This guide is part of our Privacy & Security Kit, alongside the password manager comparison and the account-security plan that ties it all together.

Frequently asked questions

What is the best authenticator app?

For most people the best authenticator app is the one that's free, works on your devices, and backs up your codes so a lost phone isn't a disaster — Google Authenticator, Microsoft Authenticator, and Proton Authenticator all qualify. If you already use a password manager, letting it hold your codes is often the smartest choice of all, because your logins and 2FA codes then live and sync in one secured place. There's no single winner; there's the right fit for your setup.

Are authenticator apps better than SMS for two-factor?

Yes, meaningfully. SMS codes can be intercepted by SIM-swap attacks, where someone convinces your carrier to move your number to their SIM. An authenticator app generates codes on your device with no phone number involved, so there's nothing to reroute. Use an app (or a passkey) wherever it's offered, and keep SMS only as a last-resort fallback for accounts that support nothing else.

What happens to my 2FA codes if I lose my phone?

That depends entirely on whether your authenticator backs up. Apps with encrypted cloud backup or account sync — or a password manager holding your codes — let you restore everything on a new phone by signing in. An app with no backup means every code is stranded on the lost device, and you're relying on the one-time recovery codes each site gave you. This is why backup capability is the single most important feature to check.

Is it safe to keep 2FA codes in my password manager?

It's safe and, for many people, the sensible choice — provided the manager itself is properly locked down with a strong master passphrase and its own second factor. The mild trade-off is that your password and its code then live in one place; if someone fully compromises your vault, they have both. For most people the convenience and reliable backup outweigh that, especially since a well-secured vault is very hard to breach. Purists prefer to keep codes in a separate app.

Do authenticator apps work without internet?

Yes. The standard time-based codes (TOTP) are generated on your device from a shared secret and the current time, so they work with no signal or Wi-Fi at all — useful on a plane or abroad. The only thing that needs syncing is the initial setup and any cloud backup; the code generation itself is fully offline.

Can I use the same authenticator app for all my accounts?

Yes — one app can hold the codes for as many accounts as you like, and that's the normal way to use it. Each account you enable app-based 2FA on adds an entry, and the app shows a rolling list of six-digit codes. You don't need a separate app per service; you just need one you trust and that backs up.

What are backup codes and do I still need them with an authenticator app?

Backup codes are one-time recovery codes a service gives you when you enable 2FA, meant to get you in if you lose access to your authenticator. Yes, you still need them — they're your safety net if your phone and your backup both fail. Store them somewhere durable: a secure note in your password manager, or a printed copy in a safe place. Not a screenshot in your camera roll.

Free download

Get the free Digital Security Checklist

The afternoon lockdown plan on two pages — passwords, two-factor, and the phishing red-flag card. Honest security picks in your inbox, no fear-mongering.