SMS texts and phone calls are convenient for getting login codes, but they’re also vulnerable to SIM‑swap fraud, message interception, and phone-number lockouts. You can design media‑free multi‑factor authentication (MFA) that doesn’t depend on cellular voice or SMS at all. This guide walks you through safer options—app codes, hardware keys, and phishing‑resistant prompts—plus practical setup and recovery steps so you don’t get locked out.
Why move beyond SMS and voice codes?
Text and voice factors prove you control a phone number, not that you are you. Attackers can socially engineer carriers to port your number, forward calls, or exploit weak voicemail PINs. SMS also travels unencrypted between carriers and can be delayed or blocked when you travel or change numbers. Media‑free MFA avoids these channels while giving you stronger resistance to phishing, malware, and account takeover.
Your media‑free MFA toolbox
There are three main ways to authenticate without relying on SMS or calls. You can use them separately, or combine them for layered protection.
1) Time‑based one‑time passwords (TOTP) via authenticator apps
- What it is: Rolling 6‑ or 8‑digit codes generated on your device every 30 seconds from a shared secret (no internet or phone signal required).
- How it works: During setup, you scan a QR code from the website into an authenticator app; the secret stays on your device and produces codes offline.
- Why it’s better than SMS: Not tied to your phone number; resilient to SIM‑swap; works without connectivity once set up.
- Popular apps: Aegis (Android), Raivo (iOS), Microsoft Authenticator, Google Authenticator (now supports encrypted cloud backup), 1Password/Bitwarden built‑in OTP, FreeOTP.
2) Hardware security keys (FIDO2/WebAuthn)
- What it is: Physical keys (USB‑A/C, NFC, Lightning) that perform cryptographic challenges with your browser or device. Examples include YubiKey and SoloKey.
- How it works: The site stores a public key; your device keeps the private key inside the hardware. To sign in, you tap the key and sometimes enter a local PIN or use biometrics.
- Why it’s powerful: Strong phishing resistance; your private key never leaves the device; no dependency on phone numbers or SMS delivery.
- Best for: Email, password managers, cloud storage, banking, developer platforms, and any account that would be painful to lose.
3) Passkeys (platform or cross‑device)
- What it is: A passwordless sign‑in based on FIDO2/WebAuthn that uses your device’s secure enclave and biometrics (Face ID, Touch ID, Windows Hello) or a synced credential across your devices.
- How it works: You register a passkey for an account. Next time you log in, you approve with your fingerprint, face, or device PIN—no password or SMS required.
- Why it helps: Eliminates passwords and SMS reliance; resistant to phishing; easy to use on phones and computers.
- Note: Consider how your passkeys sync (Apple, Google, Microsoft, or a password manager). Add a hardware key as a second factor for critical accounts.
Design principles for media‑free MFA
- Prefer phishing‑resistant methods first: Hardware keys and passkeys provide the best defense. Use TOTP as a strong, widely supported fallback.
- Separate factors: Store your codes and keys on different devices to reduce single‑point failure (for example, key on your keychain, TOTP on a tablet).
- Always have at least two ways in: Keep two hardware keys registered, or one key plus authenticator codes. Keep printed recovery codes in a safe place.
- Minimize recovery via phone number: Remove phone numbers from recovery options where allowed, or demote them behind stronger factors.
- Back up secrets safely: Export TOTP secrets to an encrypted vault or record emergency codes offline. Test at least one recovery path.
Step‑by‑step: Build your media‑free MFA baseline
- Inventory your critical accounts. Start with primary email, password manager, banking, cloud drive, social, and any account that can change your identity details.
- Harden your primary email first. Your email resets other logins. Add a hardware key and TOTP, remove SMS where possible, and store recovery codes offline.
- Add two hardware keys. Register both with your top accounts. Keep one on your keychain and one stored securely at home or in a safe deposit box.
- Enable an authenticator app. Scan the site’s QR into your chosen app. If offered, also save the setup key to your encrypted vault for disaster recovery.
- Capture and store recovery codes. When a service offers single‑use backup codes, print them and label them by service. Store with your other important documents.
- Remove or demote SMS and phone recovery. After confirming you have working keys and TOTP, change your account recovery settings to avoid phone dependence.
- Test sign‑in on a second device. Confirm you can authenticate from a different browser or laptop. Verify that your backup key and TOTP both work.
- Document your setup. Keep a simple record: which factors are active per account, where backups are stored, and the date of last test.
Choosing and managing authenticator apps
Pick an app based on where you’ll back up the secrets and how easily you can restore them after a lost or stolen phone.
- Local‑only apps (Aegis, Raivo, FreeOTP): Highest control. You must export and store an encrypted backup yourself.
- Cloud‑sync options (1Password, Bitwarden, Microsoft Authenticator, Google Authenticator with encryption): Easier device migration. Protect with a strong master password and, ideally, a hardware‑backed factor.
- Operational tip: When adding a new account, capture both the QR and the alphanumeric seed. Store the seed in an encrypted vault so you can re‑create codes if you lose the device.
Hardware security keys: picking the right models
- Connector type: Match your devices (USB‑C for modern laptops/phones, USB‑A for older PCs, NFC for phones, Lightning for older iPhones).
- Protocol support: Look for FIDO2/WebAuthn and, if you need it, smart card (PIV) or OTP modes. Many users only need FIDO2/WebAuthn.
- Quantity and storage: Buy at least two keys. Label them and enroll both everywhere. Keep one in daily use, one in a secure location.
- PIN and biometric: Set a key PIN if supported. Some keys can require a PIN or biometric on the host device for added protection.
Passkeys: passwordless where possible
More services now support passkeys that work across your devices or via a hardware key. Where available, register at least two authenticators: your platform passkey (phone or laptop) and a cross‑platform hardware key. Confirm you can sign in on a new browser using either method before retiring your password or removing weaker factors.
Replace push prompts that depend on mobile voice/SMS
Some services still send push approvals through a mobile app attached to a phone number or require a voice callback as backup. Switch to one of these options whenever offered:
- Number matching in authenticator apps: Prevents blind approvals by requiring you to enter a number shown on the login screen.
- Device‑bound push (no phone number): Approvals are tied to the device identity and your biometrics, not your carrier line.
- WebAuthn prompts: Use your hardware key or platform authenticator instead of any phone‑number‑tied push.
Recovery without a phone number
Media‑free MFA is only safe if you can recover access without calling a carrier. Build multiple, tested recovery paths.
- Printed recovery codes: Many services (email, password managers, social) offer single‑use codes. Store them offline and test one during a planned drill.
- Secondary email address: Create a dedicated recovery email with its own strong MFA, separate from your main inbox and not tied to your phone number.
- Backup hardware key: Register it with every critical account on day one. Confirm it works on a different device.
- Vaulted TOTP seeds: Keep encrypted copies of TOTP secrets so you can re‑provision a fresh device if needed.
- Account‑specific recovery: Banks and government services may require in‑person or postal verification. Review the policy now, not during a crisis.
When a site only offers SMS
Not every service supports media‑free MFA yet. If you must use SMS temporarily:
- Pair it with stronger factors: Keep a hardware key or TOTP on your email and password manager so an attacker can’t pivot easily.
- Use number hygiene: Avoid publishing your login number; lock your mobile account with a carrier PIN and port‑out freeze if available.
- Revisit settings regularly: Some platforms add authenticator or passkey options later. Check quarterly and upgrade when possible.
Privacy and identity protection benefits
By cutting SMS and voice dependence, you remove a high‑risk channel that attackers routinely target. Hardware keys and passkeys dramatically reduce phishing risk. TOTP provides offline resilience during travel or outages. Together, these upgrades lower your likelihood of account takeover, which helps protect your personal information, financial life, and the trust signals that follow your identity.
Practical checklist
- Secure primary email with two hardware keys, TOTP, and printed recovery codes.
- Migrate critical accounts to WebAuthn (hardware key or passkey) where supported.
- Enable an authenticator app for all remaining accounts; export encrypted backups.
- Remove phone numbers from recovery where allowed; add a dedicated recovery email.
- Test a complete recovery drill twice a year with your backup key and codes.
- Document your setup and store it with other important records.
How this fits into broader identity safety
Authentication is just one layer. Keep your passwords unique and long with a reputable manager, monitor data breaches, and watch for signs of identity misuse. If your financial identity is exposed or you want more oversight of credit changes after switching your MFA, consider adding dedicated monitoring that alerts you to new accounts, inquiries, or suspicious activity. A good place to start is the resource on privacy, credit monitoring, and identity protection here: SmartCredit for privacy, credit monitoring, and identity protection.
Frequently asked questions
Do I still need passwords if I use passkeys?
Some services are fully passwordless with passkeys, but many still require a password as a fallback. Keep a unique, long password even when you enable passkeys, and add hardware keys as an additional sign‑in method when available.
What if I lose my phone and my hardware key?
This is why you register two keys, keep printed recovery codes, and store TOTP seeds or use a secure, encrypted vault with strong MFA. With those in place, you can restore access without relying on a phone number.
Are authenticator apps tied to my phone number?
No. TOTP codes come from a secret stored on your device, not your phone line. After setup, they work offline and aren’t affected by SIM changes.
Can attackers phish my authenticator codes?
Yes, TOTP can be phished in real time by sophisticated sites. Hardware keys and passkeys offer stronger phishing resistance. Use TOTP broadly, but prefer keys and passkeys for your most sensitive accounts.
How often should I review my MFA settings?
Review quarterly. Confirm backup keys still work, rotate recovery codes if your storage changed, and upgrade any account that adds support for passkeys or hardware keys.
Conclusion
Moving away from SMS and phone calls for MFA is one of the highest‑impact upgrades you can make for identity safety. Start with your primary email and password manager, register two hardware keys, enable an authenticator app, and capture recovery codes. Remove phone‑based recovery where possible, and test your backups. Within a weekend, you can build a media‑free MFA design that is faster, more private, and far more resistant to phishing and SIM‑swap attacks—without risking lockout when your number changes or your signal drops.
Good to Know
If a site only offers SMS codes, add a backup email and an authenticator app as soon as those options appear—many services unlock stronger MFA choices after you complete the first login or verify your account.