Activation Hub Online Blog
Internet Security

Two-factor authentication: which method is actually safer

Text codes, authenticator apps and security keys all count as two-factor. They protect against very different attacks, and the weakest one is still far better than none.

A computer screen showing an authentication prompt

Two-factor authentication means a password alone isn't enough to get into your account. That idea is simple, but the methods that deliver it are not equal. A text message code, an authenticator app and a physical security key each stop different attacks, and one of them stops almost all of them.

The first thing worth saying is the reassuring part. Any second factor blocks the most common attack by far: someone who has your password from an old data breach trying it on other sites. If you have text codes turned on today, you're already far better protected than with a password alone.

Text message codes

The service sends a six-digit code to your phone number when you sign in. It's the easiest method to set up and works on any phone.

It has two weaknesses. The first is SIM swapping: a criminal persuades your mobile network to move your number to a new SIM, and your codes go to them. This is targeted and takes effort, so it's aimed mostly at people with valuable accounts, but it does happen. The second is phishing: a convincing fake login page asks for your password and then your code, and passes both to the real site within seconds.

Worth doing if you rely on text codes: ask your mobile network whether it offers a port-out PIN or extra account verification, and set it up.

Authenticator apps

An authenticator app generates a new code every 30 seconds from a secret shared with the service when you set it up, usually by scanning a QR code. Nothing is sent over the phone network, so SIM swapping doesn't affect it. Many password managers can also store these codes.

It's still phishable. If you type the current code into a fake site, the attacker can use it straight away. It's a clear step up from text messages, not a complete answer.

One practical point: check whether your authenticator app backs up its codes, and to where. If it doesn't, losing your phone means losing every code at once. Save the backup codes each service offers when you enable two-factor.

Push approvals

Some services send a prompt to an app on your phone asking "Is this you trying to sign in?". It's convenient, and not vulnerable to SIM swapping.

The known weakness is prompt fatigue: an attacker with your password triggers repeated prompts, hoping you tap Approve to make them stop. Better implementations show a number on the login screen that you must match in the app, which largely solves it. The rule is simple: never approve a sign-in you didn't start just now.

Security keys and passkeys

Security keys are small USB or NFC devices built on the FIDO2 open standard. Passkeys use the same standard, but the credential lives on your phone, computer or password manager, unlocked with your fingerprint, face or device PIN.

Both are phishing-resistant, and this is the important difference. The key checks the web address it is talking to and will only respond to the genuine site. A fake login page on a lookalike domain gets nothing, however convincing it looks and however distracted you are. You don't have to spot the fake; the technology does it for you.

Passkeys are now supported by the major operating systems, browsers and a growing list of services. When a site offers one, it's usually quicker than a password plus code. Physical keys make most sense for high-value accounts such as your main email, and it's worth registering two, keeping the spare somewhere safe.

How they compare

MethodStops password reuseStops SIM swapStops phishing
Text message codeYesNoNo
Authenticator appYesYesNo
Push with number matchingYesYesPartly
Passkey or security keyYesYesYes

Account recovery is the catch in all of this. If a service still allows you to reset everything by text message, your account is only as strong as that route. Where a service lets you remove the phone number as a recovery option after adding stronger methods, consider doing so for your most important accounts.

What to do, in order

  1. Your main email account first. It resets everything else, so it deserves the strongest method it offers — a passkey or security key if available.
  2. Then banking, your phone's platform account and your password manager.
  3. Save the backup codes for each, somewhere that isn't the device they protect. A printed copy at home is fine.
  4. Add a second method where the service allows it, so losing one phone doesn't lock you out.
  5. Everything else: turn on whatever the service offers. Text codes are better than nothing.

If you're setting up a password manager at the same time, plan the recovery side before you start, because the two protect each other.