Two-Factor Options Compared: SMS, Apps, Hardware Keys
Three methods with genuinely different security properties. One of them is defeated by a phone call to a carrier.
Account security on an exchange is not about the password. It is about what the second factor actually protects against, and the three common options differ substantially.
The comparison
| Method | Defeats password theft | Defeats phishing | Defeats SIM swap |
|---|---|---|---|
| SMS code | Yes | No | No |
| Authenticator app | Yes | No | Yes |
| Hardware security key | Yes | Yes | Yes |
SMS
A code sent to your phone number.
The weakness: the number is controlled by your carrier, not by you. An attacker who convinces the carrier to move the number to their SIM receives every code. This is a documented, repeated attack, and it typically completes within an hour.
It also fails against phishing, because a code typed into a fraudulent site is immediately usable by the attacker.
When it is acceptable: as a fallback where nothing better is offered, on an account holding nothing of value.
Authenticator applications
A code generated on your device from a shared secret. Nothing is transmitted.
What it fixes: SIM swapping, entirely. A stolen phone number gains the attacker nothing.
What it does not fix: phishing. A code entered into a fraudulent site works for the attacker within its validity window.
Practical note: back up the setup secrets when enabling. Losing the phone without a backup means an account recovery process that can take weeks.
Hardware security keys
A physical device required to authenticate.
What it fixes: both. The key verifies the site’s identity cryptographically before responding, which means a fraudulent site receives nothing usable even if the user is fully deceived.
This is the only method that defeats phishing, and phishing is the most common attack.
The cost: a device, and the need for a backup key registered to the same accounts. Losing the only key means account recovery.
Passkeys
Increasingly supported and functionally similar to a hardware key, bound to a device rather than a separate token. Good security properties, with the caveat that recovery depends on the platform’s synchronisation arrangements.
The configuration that matters
Use the strongest method the venue supports. Where hardware keys are available, use them.
Remove weaker fallbacks. A phone number left as an account recovery option undermines a stronger method on the same account. This is the most common configuration error.
Set a carrier port-out PIN. Prevents number transfer without an additional code. Five minutes, and it is not enabled by default.
Use a dedicated email for financial accounts. Not published, not reused, protected by a hardware key. Email is the recovery path for everything else.
Enable withdrawal address allowlists. Where offered, they convert an instant theft into a delayed one you may be able to interrupt.
What the options tell you about a venue
A platform offering only SMS has made a decision about how much it invests in customer security.
Support for authenticator applications is the minimum. Support for hardware keys and address allowlists indicates a venue taking the problem seriously, and these are documented in the security pages of platforms including venues supporting external addresses.
Checking before opening an account takes two minutes and is a reasonable filter.
Products covered here are bought at full retail price and used for real transactions before anything is written. There are no affiliate links on this site, no sponsored placements and no review units. If that ever changes, it will be disclosed at the top of the article.