Skip to content

Don’t use SMS for 2FA

2FA is two-factor authentication, which is when you need to enter in a code to access your account. You should have this on every financial account you have.

But you should not use SMS, or Simple Message System, for it. You should not get it as a text message because it’s not encrypted and can be intercepted.

Instead – use an authenticator app of some kind. Google has one that I use.

One Million Two-Factor Authentication Codes Were Recently Exposed [Lifehacker] – “An investigation led by Bloomberg and Lighthouse Reports—based on data received from an industry whistleblower—found that more than a million text messages containing 2FA codes were visible to Swiss company Fink Telecom Services during June 2023. As an intermediary between the companies that generate authentication codes and the users logging into their accounts, Fink handled the messages and had access to their content.”