Recommendations: Two-factor authentication: which second factor to choose

Your priority: I want the practical default Authenticator apps: free, offline, strong enough.

How to compare your options

The criteria we recommend checking, in order of importance.
CriterionWhy it matters
Resistance to phishingThe first thing to verify — it decides day-to-day satisfaction.
Works offlineCheck during the refund window before committing.
Recovery and backup designCheck during the refund window before committing.
CostCheck during the refund window before committing.
Breadth of site supportCheck during the refund window before committing.

These placements are paid. Sponsorship never changes the criteria above — evaluate every option against them.

Methodology

Criteria-based editorial content. We describe the trade-offs between factor types; sponsored placements are always labelled.

Frequently asked questions

Is SMS two-factor useless?
No — it still blocks the most casual attacks. But it can be phished or SIM-swapped, so prefer an app or key for anything important.
What happens if I lose my authenticator or key?
You fall back to recovery codes, so save them when you set up two-factor. For hardware keys, register a second key as a backup.

← Back to the guide