The six-digit code that lands on your lock screen isn’t just a convenience — it’s a signal traveling through infrastructure designed when phone networks were built on trust. In a home office, that code is also visible to anyone who walks past your desk, picks up your phone, or glances at a notification preview. The same SMS-based two-factor authentication that’s supposed to protect your accounts can become a weak link, especially when your workspace overlaps with family life.
SMS 2FA Risks
Family Privacy
Home Office Security
Authentication Methods
This post contains affiliate links.
The Notification That Stays Visible on a Locked Screen
Most smartphones display notification previews on the lock screen by default. That means the six-digit code your bank or email provider sends arrives in plain text, readable by anyone within arm’s reach — your partner grabbing a drink, your teenager walking through the room, a houseguest passing the desk. You don’t need to hand over your phone for someone to see the code; they just need to glance at the screen while it’s sitting on your desk or charging on the nightstand.
It’s unsettling to realize that your two-factor codes are effectively posted on a bulletin board in your own home. The same convenience that makes SMS codes easy for you also makes them easy for everyone else. And if someone in your household has access to your unlocked phone — say, to take a call or check a message — they can read the full code, not just a preview.
The fix is straightforward but often overlooked. On both iOS and Android, you can adjust notification previews to show content only when the phone is unlocked, or hide sensitive notifications entirely. Go to Settings > Notifications and look for “Show Previews” or “Notification Privacy.” While you’re there, review which apps are allowed to display sensitive content on the lock screen. This single change closes the most immediate gap in a shared workspace.
- Disable lock screen notification previews for apps that send 2FA codes.
- Set your phone to require authentication before showing notification content.
- If you share a device or workspace, assume anyone with physical access can read your codes — act accordingly.
Even with previews off, an unlocked phone is an open book. If you hand your phone to a family member to make a call or look up a recipe, they could see incoming codes. Consider using a separate device for authentication codes, or at least keep your phone face-down when not in use.
How SMS Codes Travel Through a Network You Don’t Control
Lock screen visibility is the surface problem. The deeper issue is that SMS was never designed for security. Text messages travel over Signaling System 7 (SS7), a protocol from the 1970s that assumes trust between carriers — an assumption that broke decades ago. Researchers have demonstrated live interception of SMS codes using SS7 gateways available to telecom partners abroad, rerouting a target’s texts without the phone owner noticing. As Morning Overview explains, “carriers added monitoring and filtering for fraudulent SS7 requests but the protocol itself never redesigned, so the underlying interception path remains available to anyone with access.”
Most of the documented specifics about that interception come from Bloomberg and Lighthouse Reports, as covered by 9to5Mac and ZDNet. The scale is sobering: at least one million data packets containing authentication codes were siphoned from the network, and recipients were spread across more than 100 countries. The UK phone regulator Ofcom banned global title leasing for UK carriers in April 2025, citing the threat to mobile phone users. But the infrastructure that made that interception possible still exists.
If you receive a 2FA code when you haven’t tried to log in, that’s an immediate red flag — someone else triggered it. Sudden loss of cellular service, or your carrier saying your SIM was changed without your request, could indicate a SIM swap attack. In that scenario, your phone number is moved to an attacker’s SIM, and every text message — including password reset links and 2FA codes — lands on their device instead of yours. Contact your carrier immediately and set up a port-out PIN to lock down your number.
What NIST Says About SMS as a Restricted Authenticator
The U.S. National Institute of Standards and Technology (NIST) now classifies SMS-delivered one-time codes as a “restricted” authenticator in its digital identity guidelines. That’s a new category that didn’t exist in earlier versions of the standard, and it signals that organizations relying on text-message codes should document the associated risk, offer an alternative method, and monitor for signs of compromise. According to Morning Overview, “NIST guidelines shape security requirements in banking regulations, cyber-insurance policies, and corporate compliance programs across the private sector.” So this isn’t just academic — it affects how your bank, employer, and insurance provider treat SMS authentication.
Choose an Authenticator App
Apps like Google Authenticator, Microsoft Authenticator, or Authy generate codes locally on your device. No text message is sent, so there’s nothing to intercept on the network. Download one from your app store.
Link Your Accounts
In your account security settings, look for “Two-Factor Authentication” or “Authenticator App.” Most services will show a QR code. Open your authenticator app, tap the + icon, and scan the code. The app will start generating six-digit codes that refresh every 30 seconds.
Remove SMS as a Backup
After the app is working, go back and disable SMS as a second factor or remove your phone number from the recovery options. Some services let you keep SMS as a fallback — if possible, remove it entirely. If you must keep it, at least move your primary factor to the app.
If you’re managing accounts for work — especially if you handle client data or access company systems — switching to an authenticator app should be a priority. Many organizations now require it, and some are moving toward passkeys or hardware security keys for higher-value accounts.
Authenticator Apps and Hardware Keys Close the Gap
Authenticator apps eliminate the network-level interception problem entirely. The code never leaves your device. But they’re not impervious to every threat. Real-time phishing attacks — where a fake login page captures your password and the 2FA code you type in — can still bypass app-based codes. Hardware security keys, like those using FIDO2 or WebAuthn standards, are the strongest option because they cryptographically verify the domain you’re logging into. The key won’t respond to a fake site. Security researchers note that “passkeys and security keys reduce risk because the secret cannot be typed into a fake site.”
Yes, if you type the code into a fake website, the attacker can forward it to the real site in real time. That’s why hardware keys or passkeys are better for high-value accounts. But an authenticator app is still vastly safer than SMS, because it removes the possibility of SIM swapping and network interception.
Push-based 2FA, where you approve a login prompt, can be abused through MFA fatigue — attackers spam you with approval requests until you accidentally say yes. This was used in the 2022 Uber breach. Authenticator apps that require you to open the app and enter a code are less susceptible to that kind of social engineering.
For WFH setups, a hardware key like a YubiKey is a reasonable investment for accounts that control your income — banking, payroll, email, and cloud storage. It’s a physical object that lives on your keychain, and it works with most modern browsers and password managers. ZDNet recommends using a physical security key or authenticator app as the primary method, and treating SMS as a fallback at best.
Securing Your Two-Factor Flow in a Shared Home
The family-angle risk doesn’t end with lock screen previews. If you store backup codes in your email or in a notes app that syncs across devices, anyone who uses your shared home computer could find them. Treat backup codes like house keys — store them offline, in a physical safe or a password manager that’s locked behind its own strong authentication. Security guidance from Hacked.com emphasizes that “backup codes are single-factor if an attacker can read where they’re stored.”
Your primary email account is the control plane for everything else. If a family member or roommate has access to your unlocked email — even accidentally — they can reset passwords and intercept recovery links. Use a unique, strong password for your email and protect it with the strongest 2FA method available, ideally a hardware key or authenticator app. Home office security tips from this site cover the broader picture of device access and data privacy in shared spaces.
- Disable lock screen notification previews on all devices used for work.
- Switch at least your most critical accounts (email, banking, work logins) from SMS to an authenticator app.
- Add a port-out PIN to your mobile carrier account to prevent SIM swapping.
- Store backup codes offline — not in email or cloud notes.
- If you share a computer, use separate user accounts and never stay logged in to sensitive services.
- Consider a hardware security key for accounts that control your income or data.
If you suspect your account has already been compromised — unexpected password reset emails, unfamiliar devices in your session list, or 2FA codes arriving without a login attempt — act quickly. Change passwords from a trusted device, sign out everywhere, and review recovery options. Getting expert advice can help you trace what happened and lock down the entry point before it’s used again.
Two-factor authentication remains one of the best defenses we have, but only when we choose the right method for our actual circumstances. For anyone working from home, that means treating your authentication flow as part of your home office security — not as a personal afterthought. Start by switching one account from SMS to an authenticator app. The rest will follow.