Two-factor authentication improves account security, but methods differ. Learn the strengths and limitations of SMS, authenticator apps, passkeys and keys.

Why a password alone is not enough

Reused or stolen passwords can expose accounts.

SMS codes

Convenient, but dependent on mobile-number security.

Authenticator apps

Reduce dependence on SMS but require a recovery plan.

Passkeys

Can provide strong phishing-resistant authentication on supported services.

Security keys

Physical keys can provide strong protection for high-value accounts.

Plan for phone loss

Store recovery codes securely and register more than one trusted authentication method where appropriate.

Frequently asked questions

Is SMS 2FA better than no 2FA?

Usually yes, but stronger phishing-resistant methods may be available.

What is an authenticator app?

It generates time-based codes on a trusted device.

What is a passkey?

A passkey is a modern cryptographic sign-in credential.

Why keep backup codes?

They can restore access if the phone is lost.

Should recovery codes be stored on the same phone?

Prefer a secure separate location.