I finally caught my bank's two-factor code in a phishing sim... then read the fine print
I was at a security conference in Austin last Saturday and overheard two SOC analysts arguing about whether SMS 2FA is worse than no 2FA at all. One said the sim swap risk makes it a trap, the other claimed it still stops 90% of script kiddies. That got me thinking about my credit union, which still uses six digit texts. I read their terms later and they basically waive liability if your SIM gets ported. So is SMS better than nothing or a false sense of safety? Weigh in with what you tell your non-tech friends to use.
That claim about stopping 90% of script kiddies is the part that gets me, because that number comes from old Microsoft research and it lumps SMS in with all 2FA. The problem is it counts failed logins, not real-world breaches where the attacker specifically targets you. A sim swap takes one bribed phone store employee and about 15 minutes, and then your six digit code lands on the attacker's phone, not yours. Your credit union's fine print is the real tell here: if they won't cover you when the SIM gets ported, they already know SMS is the weak link. I tell my non-tech friends to use an app like Aegis or Ente or a hardware key, and only fall back to SMS for stuff like a pizza account.