Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
PRACTICAL 13 JUN 2026 · 3 MIN

Two-factor codes by text: better than nothing, worse than an app

A code by text is a real improvement on a password alone. It is also the one second factor an attacker can steal without touching your phone.

FFION DAVIES · SUPPORT LEAD
SHARE LinkedIn X Email
PRACTICAL cover image

Two-factor authentication by text works the obvious way: you sign in, the service sends a six-digit code to your number, you type it back. For most people, most of the time, it does the job. The password alone is the weak link, and adding any second step blocks the overwhelming majority of the automated attacks that reuse a leaked password.

The problem is the “SIM swap”. Someone who knows enough about you rings your mobile network, claims to be you with a lost handset, and has your number moved to a SIM they control. Every text code then arrives on their device, not yours. It is rare, it takes effort, and it is aimed at accounts worth the trouble - which is exactly why we move email and banking off text codes first.

The better options do not depend on your phone number at all. An authenticator app generates the code on the device itself, so there is nothing to intercept in transit and nothing to redirect at the network. A passkey goes further: it ties the sign-in to the physical device and your face or fingerprint, and there is no code for anyone to phish out of you.

You do not have to change everything at once. Start with the two accounts that unlock the rest - your main email and your bank - because whoever controls your email can reset most of your other passwords. Leave text codes switched on where an app is not offered; keep a couple of backup codes printed and put away. The aim is progress, not a perfect sweep in one evening.

One honest caveat for sole traders and growing teams: if you move to an app or a passkey, you must also plan for the lost or broken phone. Save the recovery codes each service gives you, store them somewhere that is not the phone, and make sure a second person in the business can get back in if you are unreachable.

WHAT TO DO
  • ✓Move your main email to an authenticator app or a passkey this week.
  • ✓Do the same for online banking, using the app or passkey the bank offers.
  • ✓Keep text codes only where no app is available, and never read a code to a caller.
  • ✓Print the backup recovery codes and store them off the phone.