Recommendations: Two-factor authentication: which second factor to choose
Your priority: I am worried about lockout — Prioritize backup codes and recovery paths.
How to compare your options
| Criterion | Why it matters |
|---|---|
| Resistance to phishing | The first thing to verify — it decides day-to-day satisfaction. |
| Works offline | Check during the refund window before committing. |
| Recovery and backup design | Check during the refund window before committing. |
| Cost | Check during the refund window before committing. |
| Breadth of site support | Check during the refund window before committing. |
Sponsored options
Sponsored
Example authenticator app
Example partner (demo) — Demo sponsored card — in production this slot holds a real, labelled partner offer.
Visit site ↗Sponsored
Example hardware security key
Example partner (demo) — Demo sponsored card — in production this slot holds a real, labelled partner offer.
Visit site ↗Sponsored
Example endpoint protection
Example partner (demo) — Demo sponsored card — in production this slot holds a real, labelled partner offer.
Visit site ↗Methodology
Criteria-based editorial content. We describe the trade-offs between factor types; sponsored placements are always labelled.
Frequently asked questions
- Is SMS two-factor useless?
- No — it still blocks the most casual attacks. But it can be phished or SIM-swapped, so prefer an app or key for anything important.
- What happens if I lose my authenticator or key?
- You fall back to recovery codes, so save them when you set up two-factor. For hardware keys, register a second key as a backup.