Which two-factor method should I actually use?
Text message, email, authenticator app, push approval, hardware key and passkey ranked by what each actually defends against, and how to choose per account rather than in general.
- Difficulty
- beginner
- Time
- 12 min
- Read
- 3 min
- Safety
- caution
Short answer
Ranked weakest to strongest: email codes, SMS codes, push approvals, authenticator app codes, then passkeys and hardware security keys, which are the only ones that resist phishing outright. Any second factor is dramatically better than none, so use SMS rather than nothing — but move email, banking and your password manager to an app or a passkey.
The important question is not which method is best in the abstract but what each one actually stops. All of them stop a leaked password being enough on its own. Only some of them stop a live phishing site relaying your code in real time, and only some resist someone taking over your phone number.
Safety
Step by step
- Understand what all of them fix.Every second factor breaks automated attacks using leaked passwords, which is the largest category of account takeover by volume. That alone is why any method beats none.
- Rank email codes lowest.A code sent to an email address is only as strong as that email account, and if the same password leaked for both, it protects nothing. Use it only where nothing else is offered.
- Understand the specific weakness of SMS.Text codes are vulnerable to SIM swapping, where someone takes control of your number, and to being read out under pressure. They are still far better than nothing, and for some UK banks they are the only option.
- Treat push approvals as convenient but fatiguable.A prompt saying "approve this sign-in?" is quick, but people approve them reflexively, and attackers send repeated prompts until someone taps yes. Prefer versions that show a number you must match.
- Use an authenticator app for most accounts.Codes generated on your device, working offline, immune to SIM swapping. The practical default for email, cloud storage, social accounts and shopping. Choose one that can be backed up or synced, or you will lose everything with the phone.
- Use passkeys and hardware keys where the account really matters.Both are bound to the site's real address, so a phishing site cannot use them — the browser simply will not offer the credential to the wrong domain. This is the only category that defeats live relay phishing.
- Choose per account, not once for everything.Email, password manager and banking deserve the strongest method available. A newsletter account does not. Spending your effort where the consequences are largest is the whole skill.
- Set up recovery before you finish.Save the recovery codes, register a second factor as backup where possible, and keep the recovery route somewhere physical. Being locked out of your own email is the most common self-inflicted harm in this area.
Alternatives
- SMS code: Universal, works on any phone, needs no app. Vulnerable to SIM swap and to being talked out of you. Use where nothing better is offered, and never as the only factor on email.
- Authenticator app: Six-digit codes generated on your device, offline, immune to SIM swap. The right default for most accounts. Needs a backup plan for a lost phone.
- Push approval: Fast and low friction, and the version that shows a matching number is genuinely good. The plain yes/no version is defeated by repeated prompts and reflex approval.
- Passkey: A key stored on your device and unlocked by fingerprint, face or PIN, bound to the real site. Nothing to phish and nothing to leak. Use wherever offered; keep another sign-in route for now.
- Hardware security key: A physical key on the keyring, tapped or plugged in. The strongest widely available option and the one used where compromise would be catastrophic. Buy two and register both, because losing the only one is painful.
Questions people ask
Is SMS two-factor worth using at all?
Yes, where it is the only option. It stops the automated attacks that cause most account takeovers. It is simply the weakest of the good options, and worth upgrading on email and banking.
What happens if I lose the phone with the authenticator app on it?
You use your recovery codes, which is why you save them at setup. Several authenticator apps now sync across devices, which removes most of this risk.
Do I need a hardware key?
Most people do not. They are worth it if you hold something exceptionally valuable — a business email account, significant cryptocurrency, or an account whose compromise would harm others.