Two-factor authentication improves account security, but methods differ. Learn the strengths and limitations of SMS, authenticator apps, passkeys and keys.
Why a password alone is not enough
Reused or stolen passwords can expose accounts.
SMS codes
Convenient, but dependent on mobile-number security.
Authenticator apps
Reduce dependence on SMS but require a recovery plan.
Passkeys
Can provide strong phishing-resistant authentication on supported services.
Security keys
Physical keys can provide strong protection for high-value accounts.
Plan for phone loss
Store recovery codes securely and register more than one trusted authentication method where appropriate.
Frequently asked questions
Is SMS 2FA better than no 2FA?
Usually yes, but stronger phishing-resistant methods may be available.
What is an authenticator app?
It generates time-based codes on a trusted device.
What is a passkey?
A passkey is a modern cryptographic sign-in credential.
Why keep backup codes?
They can restore access if the phone is lost.
Should recovery codes be stored on the same phone?
Prefer a secure separate location.