Two-Factor Authentication Explained (and Which Kind to Pick)
SMS codes, authenticator apps, push prompts and hardware keys compared, how each second factor works, how attackers defeat them, and the right choice for every budget.
Published · Updated · 8 min read
Passwords keep failing for a structural reason: they are shared secrets that websites store and attackers steal. Two-factor authentication (2FA) fixes the structural problem by requiring something that isn't sitting in a database, a device in your pocket, or a chip on your keyring. Accounts protected by a decent second factor shrug off leaked passwords entirely, which is why enabling 2FA is the highest-value ten minutes in personal cybersecurity.
Not all second factors are equal, though. This guide ranks the common methods, explains the real-world ways each gets defeated, and gives a pragmatic recommendation for typical accounts.
The threat 2FA solves
Billions of username/password pairs circulate from past breaches. Criminal automation tests them against every popular service, this credential stuffing works purely because people reuse passwords. A second factor breaks the chain: the attacker has your password but not your possession, and moves on to the millions of accounts without one.
SMS codes, better than nothing, weaker than the rest
Texted one-time codes were 2FA's first mass-market form. They work, and they stop naive stuffing cold, but the delivery channel is the vulnerability: SIM-swapping, convincing or bribing a carrier to port your number, transfers your texts to the attacker. Weaknesses in global telephony routing expose codes to sophisticated interception too.
Use SMS where it's the only option offered. Treat it as a bridge, not a destination.
Authenticator apps, the everyday sweet spot
TOTP apps generate rolling 30-second codes computed from a shared seed set up once via QR code. No network is involved in generating codes, so there is nothing to intercept at login time and no carrier to attack.
- Back up the seed: many apps support encrypted export, and most services show recovery codes during setup, save those offline.
- Beware phishing sites relaying codes in real time; TOTP defends against bulk stuffing, not a human attacker proxying your login live.
- Keep seeds for critical accounts on two devices if your app supports it.
Push approvals, convenient, phishable, occasionally fatigued
Vendor apps pop a prompt you tap to approve. Frictionless when it is you; also frictionless for an attacker who already has your password, which produced the infamous wave of approval-fatigue attacks. If your provider supports number matching (typing the on-screen number into your phone), enable it; plain approve/deny prompts deserve suspicion.
Hardware keys, the ceiling
FIDO2/WebAuthn security keys implement challenge-response cryptography bound to the true site origin. Phishing a key is essentially impossible: a fake domain cannot obtain a usable assertion. The failure modes are physical, lose both keys, rather than digital.
Buy two, register both, attach one to your keychain and store the backup separately. For email, banking, password-manager and developer accounts, keys are worth every cent, and passkeys now extend the same technology to consumer-friendly syncing across devices.
A pragmatic tier list
One caveat worth internalizing: account-recovery flows are the side door around 2FA. Harden recovery email and phone with their own second factors, or attackers simply reset around your careful setup.
- Primary email and password manager: hardware key or passkey, with authenticator-app backup.
- Banking, cloud consoles, social media: authenticator app minimum.
- Long-tail accounts: whatever the service offers, even SMS, plus a unique password from a manager.
- Everywhere: save recovery codes offline during setup, and review registered devices twice a year.
Start by checking which of your accounts appear in known breaches, exposed credentials are precisely the ones an attacker will try tonight. Then layer the strongest second factor each service supports. Our Data Breach Checker takes seconds and costs nothing.