A password on its own is a single point of failure. If it is phished, guessed or leaked in someone else's breach, the account is open. Two-factor authentication (2FA) adds a second check, so a stolen password is not enough. But not all second factors are equal. Some stop almost every attack; others can be bypassed by a well-built phishing page. Here is how the common methods compare and which to use where.
The three kinds of factor
Authentication factors fall into three categories:
- Something you know: a password or PIN.
- Something you have: a phone, an authenticator app, a hardware security key.
- Something you are: a fingerprint or face scan.
Two-factor authentication combines two different categories. A password plus a security question is not 2FA, because both are things you know. You will also see the term multi-factor authentication (MFA), which covers two or more factors; in everyday use the terms are interchangeable.
Two-factor authentication methods compared
SMS and voice codes
A one-time code is sent by text message or phone call. It is easy for everyone and far better than nothing. The weaknesses: attackers can sometimes take over a phone number through SIM swapping, convincing a mobile carrier to move the number to their SIM; messages can be intercepted in some circumstances; and, like any typed code, the user can be tricked into entering it on a fake site. Use SMS where it is the only option, and avoid it for admin and finance accounts.
Authenticator apps (TOTP)
Apps such as Google Authenticator, Microsoft Authenticator and many password managers generate a new six-digit code every 30 seconds. The method is called TOTP, Time-based One-Time Password, and is standardized in RFC 6238. During setup, you scan a QR code containing a shared secret; the app and the server then calculate the same code from that secret and the current time.
Because nothing travels over the phone network, SIM swapping does not help an attacker. TOTP is a strong, free, widely supported choice. Its main weakness is shared with SMS: a real-time phishing site can ask for the code and relay it to the genuine site within the 30-second window.
Push notifications
The service sends a prompt to an app on your phone and you tap Approve. It is convenient, but attackers who already have a password can trigger prompt after prompt, hoping a tired user taps Approve to make them stop, a technique known as MFA fatigue or push bombing. Better implementations use number matching, where the login screen shows a number the user must type into the app. That simple change defeats blind approvals and is worth enabling wherever offered.
Hardware security keys (FIDO2/WebAuthn)
A small USB, NFC or Bluetooth device that you tap or touch to log in. Security keys use public-key cryptography under the FIDO2 and WebAuthn standards, and crucially they check the website's real domain as part of the login. A key registered for example.com will simply not respond to examp1e-login.com, no matter how convincing the page looks. This makes them phishing-resistant, which no code-based method is.
The costs are buying keys (and spares, since each user should register at least two), and the occasional service that does not support them.
Passkeys
Passkeys use the same FIDO2/WebAuthn technology as security keys, but the credential is stored in your phone, computer or password manager and unlocked with your fingerprint, face or device PIN. They are phishing-resistant, need no extra hardware, and often replace the password entirely. Support is growing quickly among major services. Synced passkeys are only as secure as the account they sync through, so protect that account well.
Summary
| Method | Phishing-resistant | SIM-swap risk | Cost and effort |
|---|---|---|---|
| SMS / voice code | No | Yes | Lowest |
| Authenticator app (TOTP) | No | No | Free, small setup |
| Push with number matching | Partly | No | Free with supported apps |
| Passkey | Yes | No | Free on modern devices |
| Hardware security key | Yes | No | Purchase per user |
Which method should your business use?
- Everyone, everywhere possible: at least an authenticator app. Make it mandatory for email, file storage and any cloud service holding customer data.
- Administrators and finance staff: hardware security keys or passkeys. These accounts are the most targeted and the most damaging to lose. This includes accounts at your domain registrar (a WHOIS lookup shows which registrar holds your domain), DNS provider, hosting or cloud provider, and payroll or banking.
- Shared service accounts: store TOTP secrets in a business password manager's shared vault rather than on one person's phone.
- Servers: for SSH, prefer key-based logins over passwords, and consider requiring a hardware-backed key for administrators as part of your server management routine.
Plan for lost devices
The most common 2FA problem is not an attack but a broken or lost phone. When you enable two-factor authentication:
- Save the recovery codes the service shows you, in a password manager or printed and stored securely.
- Register a second method, such as a backup security key or a second device.
- For business accounts, make sure an administrator can reset a user's factors through a documented, identity-checked process. Attackers frequently target help desks with "I lost my phone" calls.
Key takeaways
- Any two-factor authentication is far better than a password alone.
- Authenticator apps beat SMS; push prompts should use number matching.
- Only FIDO2 security keys and passkeys are truly phishing-resistant; use them for admin and finance accounts.
- Always set up recovery codes and a backup factor before you need them.