Back to guides
Guide5 min read

Two-Factor Authentication: Which Kind Is Worth Using

Every service you use nags you to turn on two-factor authentication, and most people either ignore it or pick whichever option pops up first. The kind you choose matters more than the nags suggest.

The decode

The decode. Two-factor authentication means logging in requires something beyond your password — usually a code. SMS codes are the most common and the weakest: phone numbers can be hijacked through SIM-swap attacks, where someone convinces your carrier to move your number to their phone. Authenticator apps like Authy, 1Password, or Google Authenticator generate codes on your device and aren't vulnerable to SIM swaps, making them the right default for most people. Hardware keys — small USB or NFC devices like a YubiKey — are the strongest option because they can't be phished: the key checks the site's real address before responding, so a fake login page gets nothing. Passkeys, now supported by Google, Apple, and Microsoft, build on the same idea and remove the password entirely.

The catch

The catch. Any two-factor method is only as safe as your recovery setup. Losing your phone without backup codes can lock you out of your own accounts permanently, and those backup codes are themselves a weak point if you store them in your email inbox — the same account an attacker may already have. It's also worth knowing that determined attackers phish two-factor codes in real time using fake login pages that relay what you type; only hardware keys and passkeys resist this.

The bottom line: Turn on two-factor everywhere it's offered, use an authenticator app rather than SMS where you can, and store your backup codes somewhere that isn't your email.

Read our reviews

Cyphera Press may earn a commission from some of the links on this site. This doesn't affect our reviews or opinions.