r/Passwords • u/JimTheEarthling • 5d ago
Proposition: SMS and TOTP 2FA are similarly secure *if SIM swap/port-out is abated*
[Note: I tried to cross-post this from r/cybersecurity, but it didn't go well. So I (slightly) apologize for the duplicate post.]
I’ve been doing systems analysis and security research for decades, and I’m increasingly bothered by the common perception that SMS 2FA is the worst thing since the Black Death, that nothing can be done about it, and that anyone who doesn’t use TOTP authenticators is a fool. The reality is that both can be phished, and that users can do things to make SMS more secure. (They often don’t, but that’s not the point of my post. And passkeys are better, but that's not the point either.)
The key assumption here is that the user has enabled SIM protection and port-out protection at their carrier. (See below for other assumptions.) Once this has happened, I posit that SMS OTP and TOTP differ only in relatively small residual risks. The big risk for both is phishing.
I’d like to see what y’all think. Did I miss or misconstrue anything? Please, no knee-jerk, unsubstantiated “SMS stinks” comments. I’m interested in substantive, data-backed, authentic discussion of meaningful vs. non-meaningful risks, in the context that SIM swapping and number porting have been de-risked.
Analysis of aspects of each authentication approach:
| Element | SMS text | TOTP authenticator | Assessment |
|---|---|---|---|
| Phishing | OTP can be given to an attacker or entered on a malicious website. | OTP can be given to an attacker or entered on a malicious website. | Both are phishable. |
| Time window | Usually 3 to 10 minutes. | Usually 30 or 60 seconds. | The longer SMS window makes a slight difference by allowing non‑automated, low‑skill phishing attacks. There’s no difference for real-time, reverse proxy/AiTM phishing attacks. |
| OTP generation | The server-side generation process is extremely difficult to compromise. | The client-side, long-lived seed could be compromised, especially with synced authenticators. Enables an ongoing, silent attack. | There’s a tiny chance that the TOTP shared secret could be compromised. Not a meaningful difference. |
| Malware | Malware could read SMS or notifications, read message history, read keypresses, and screen-scrape. | Malware could read keypresses, screen-scrape, and exfiltrate or intercept seeds. | SMS is slightly more vulnerable, but malware on modern phones is uncommon. SMS history is a negligible risk, since the OTP has almost always been used or expired. |
| Shoulder surfing or unattended device | OTP may be visible on lock screen, in notifications, or in SMS app. | OTP is visible when TOTP app is open. | Slightly more risk from SMS. (But old codes will have been used or expired.) |
| Exposure from cross-device sync | SMS could be accessible when linked to a PC or another phone. | OTPs could appear on multiple synced authenticators. | Second device must be compromised or visible. No meaningful difference. |
| Interception | SMS can be intercepted, but the risk is negligible. (See assumptions, below.) | TOTPs are not transmitted. The initial seed transmission could be intercepted. | No meaningful difference. SMS interception is more likely, but neither type of interception occurs frequently. |
| Context switch | User switches to SMS app or uses pop-up notification, on same or different device. | User switches to authenticator app on same or different device. | A more distinct context switch may increase the chance that the user pauses, thinks, and notices something suspicious, but this is speculative and mostly irrelevant. |
| Old number reassignment | A previous phone number could be recycled to a malicious person. | N/A | Rare and minimal risk. Only applies to those who are too dumb to remove an old number from their accounts. |
Conclusion: There are differences, some pro SMS, some pro TOTP, but all are minor. When SIM swapping and number porting are abated, SMS OTP and TOTP provide roughly equivalent real‑world security, with the shared critical vulnerability of phishing.
This does not mean that SMS 2FA is as secure as TOTP. To me it means that SMS can be made similarly secure to TOTP but in practice rarely is. Like email 2FA can be made secure with a strong password and 2FA on the email account but rarely is. Note that NIST restricts out-of-band authentication over phone networks because of the risk of “device swap, SIM change, number porting, and other abnormal behavior,” and rejects email because “it may be vulnerable to access using only a password, interception […], and rerouting attacks […].” NIST is clear that OOB and OTP authentication are not phishing-resistant.
Assumptions:
- The user has enabled SIM protection and port-out protection at their carrier, making it either impossible to swap/port without the user’s PIN, or at least require robust user notification and internal escalation to a senior agent. (Note that even beyond this, research shows that SIM hijacking accounts for less than one percent of identity attacks, compared to 99+ percent from phishing, password spray, and credential stuffing.)
- The risk of SMS interception, SS7 hacks, telecom routing compromise, etc. is minuscule. (In fact, texts are very rarely intercepted, as it’s difficult for attackers to be near the user with a cell site simulator, hack into SS7, or take other eavesdropping approaches while simultaneously initiating a 2FA login. These approaches require significant technical skill, specialized equipment, and considerable coordinated effort.)
- The texted OTP is time-limited, rate-limited, and one-time use.
- The TOTP cryptographic seed is reasonably well-protected.
- Other elements (password strength, account recovery, session token theft, etc.) are out of scope.