Two-factor authentication: what it is and which method suits you

Two-factor authentication is the one security measure that turns a stolen password into a minor problem. It is also the one most people have half-finished: switched on where it mattered least and switched off exactly where it mattered most.
A password is something you know. The problem with things you know is that they can be copied without you noticing: they leak, they get guessed, or someone talks you out of them.
Two-factor authentication adds a proof of a different kind: something you have. A phone, an app, a key. Even if someone gets your password, without that second element they do not get in.
It is the measure with the best ratio of effort to protection that exists. It takes two minutes to switch on and it neutralises the most common attack against personal accounts.
The three methods, weakest to strongest
SMS: better than nothing, worse than the rest
The service texts you a six-digit code. It works on any phone, there is nothing to install, and that is why it is the most widespread.
Its two weaknesses are real:
SIM swapping. A fraudster gathers details about you, calls your mobile operator pretending to be you, and asks for a replacement SIM with your number. From that moment the codes go to them. You suddenly lose signal: that is the warning sign.
Dependence on the network. No coverage, no code. Abroad, with a different SIM in the phone, you can end up locked out of your own account.
Even so, it is worth saying plainly: SMS switched on protects far more than two-factor switched off. If a service only offers SMS, turn it on.
Authenticator app: the right balance
An app on your phone generates a six-digit code that changes every thirty seconds. The server and the app share the same initial secret and compute the same code from the current time. That is why it works without signal and without data.
It is the recommended method for almost everything. It does not depend on your operator, it is not vulnerable to SIM swapping, and it is available on practically every serious service.
Two pieces of advice when enabling it:
- When the service shows you the QR code, also save the text key printed underneath. It lets you register the app on a second device.
- Download the recovery codes and keep them off the phone. On paper in a drawer is perfectly fine.
Its weak point is that a six-digit code can be asked for. If you fall for a convincing phishing page and type your password and code there, the attacker relays both to the real site in real time and walks in. It is an attack that exists and works.
Physical key: the one that cannot be fooled
It is a small device, about the size of a USB stick, that you confirm at sign-in by touching it or holding it near your phone.
What makes it different is not that it is “harder to copy”. It is that the key checks the website’s address before responding. If you are on an imitation, however perfect it looks, the key does not sign. Phishing stops working — not because the user got smarter, but because the method does not depend on the user being smart.
That is why it is the only genuinely solid defence against deception. The sensible move for an ordinary person is not putting keys on everything, but putting one on the main email account, which is where everything else is recovered from.
Buy two: one for daily use and a spare kept elsewhere. Losing your only key with no recovery codes is a bad day.
Passkeys: the replacement that has already arrived
More and more services let you sign in without a password, using your phone’s fingerprint or face. Underneath they use the same cryptography as physical keys, with the key stored on your phone or computer. They combine a key’s phishing resistance with the convenience of unlocking your phone.
The order to turn it on
You do not have to do it all today. The order by real impact:
- Email. It is the master key: whoever controls it requests a reset on everything else. If you do one thing, do this.
- Banking and accounts holding money. Many already require it by regulation.
- Your password manager, if you use one.
- Social media and messaging. From there, people impersonate you to scam your contacts.
- Shopping and subscriptions with a saved card.
The three mistakes that leave the protection half-built
Not saving the recovery codes. By a wide margin, the most common reason people lose an account permanently. The day the phone breaks, those codes are the only way back.
Saving the recovery codes on the same phone. If they live on the same device as the app, they are not a backup: they are the same single point of failure twice.
Approving notifications without looking. Some services send a “was this you?” prompt. If one arrives that you did not trigger, it is not a glitch: it is someone testing your password. Reject it and change the password.
What two-factor does not fix
Do not get complacent. Two-factor does not protect you if:
- Your session is already open and someone has physical access to your unlocked machine.
- Malware on your computer steals the already-validated session cookie.
- You fall for phishing and hand over password and code together — unless you use a key or a passkey.
Everything else still applies: a unique password per site, an updated system, and suspicion of any message in a hurry.
In short
- Turning on two-factor makes a stolen password a minor problem.
- SMS if there is nothing else; an authenticator app as the default; a physical key on email.
- Save the recovery codes off your phone the same day you enable it.
- Start with email. Everything else is recovered from there.
Frequently asked
The questions that keep coming up
What is two-factor authentication?
It is asking for a second proof besides your password when you sign in, usually a temporary code, a phone notification or a physical key. That way a stolen password is not enough on its own.
Is receiving codes by SMS safe?
It is much better than nothing, but it is the weakest method. An attacker can take over your number through a porting fraud known as SIM swapping, and texts can be intercepted. If the service offers an authenticator app, prefer it.
What happens if I lose the phone with my authenticator app?
That is why you save the recovery codes the service gives you when you enable two-factor, somewhere other than the phone. Many apps also offer an encrypted backup.
Are physical keys worth it for an ordinary user?
For most accounts they are unnecessary. For your main email, where everything else is recovered from, a physical key is the strongest protection against phishing that exists today and costs about as much as a dinner.


