Recommendations: Two-factor authentication: which second factor to choose

Any second factor beats none, but they are not equal. App-based codes are the practical default; a hardware key is the strongest; SMS is the weakest and should be a last resort.

How to compare your options

The criteria we recommend checking, in order of importance.
CriterionWhy it matters
Resistance to phishingThe first thing to verify — it decides day-to-day satisfaction.
Works offlineCheck during the refund window before committing.
Recovery and backup designCheck during the refund window before committing.
CostCheck during the refund window before committing.
Breadth of site supportCheck during the refund window before committing.

These placements are paid. Sponsorship never changes the criteria above — evaluate every option against them.

Methodology

Criteria-based editorial content. We describe the trade-offs between factor types; sponsored placements are always labelled.

Frequently asked questions

Is SMS two-factor useless?
No — it still blocks the most casual attacks. But it can be phished or SIM-swapped, so prefer an app or key for anything important.
What happens if I lose my authenticator or key?
You fall back to recovery codes, so save them when you set up two-factor. For hardware keys, register a second key as a backup.

← Back to the guide