The Different Kinds of Two-Factor Authentication, and Which One I Actually Trust
The Different Kinds of Two-Factor Authentication, and Which One I Actually Trust
People hear "turn on two-factor authentication" so often that it's started to sound like one single thing you either do or don't do. It isn't. There are several genuinely different ways to add that second step, they don't offer the same level of protection, and which one you end up with matters more than whether you've technically switched it on at all. I've used most of them myself at one point or another, and I've settled on a clear order of preference that I now recommend to almost everyone I talk to.
Why I Don't Treat All Two-Factor Methods as Equal
The whole point of two-factor authentication is that a stolen password alone shouldn't be enough to get into your account. But that second step can be intercepted, tricked, or bypassed depending on how it's built, and the gap between the strongest and weakest options is bigger than most people realise. Someone who's added a text message code to their accounts has done something genuinely worthwhile compared to a password on its own, but they haven't done the same thing as someone using an authenticator app or a hardware key, even though both would tick the same "2FA enabled" box on a settings page. I'd rather people understood the difference than assumed all forms of it are interchangeable.
Text Message Codes: Better Than Nothing, But I'd Skip Them If I Could
SMS codes are the most common form of two-factor authentication because they're the easiest to set up and need nothing extra installed, and for a long time they were treated as the gold standard. The problem is a technique called SIM swapping, where a scammer convinces your mobile provider to move your number onto a SIM card they control, after which every code meant for you lands with them instead. It's not a common event, but it's not a theoretical one either, and it specifically targets the exact accounts most worth protecting, banking and email among them. I still think SMS codes beat having no second factor at all, so I'd never talk someone out of using them if it's genuinely the only option in front of them, but I always mention there's something better if the account matters.
Why Authenticator Apps Are My Default Recommendation
An authenticator app generates a fresh code every thirty seconds directly on your phone, without that code ever travelling over the mobile network where it could be intercepted or redirected. That one difference removes the SIM swapping risk entirely, and it's why apps like this have become my standard recommendation for anyone asking where to start. Setting one up usually takes a couple of minutes, a quick scan of a QR code on the account's security settings page, and from then on the app just quietly generates what you need each time you log in. It works offline too, which surprises people the first time their phone has no signal and the code still appears without any trouble.
Where Hardware Keys and Passkeys Actually Earn Their Place
A small physical hardware key, the kind you plug into a USB port or tap against your phone, is about as close to unphishable as this category gets, because there's no code being displayed or typed anywhere for a scammer to trick you into handing over. Passkeys, the newer option built into most phones and browsers now, work on a similar principle using your fingerprint or face instead of a password at all. I don't think either of these is essential for most personal accounts, but for anything genuinely high value, the account tied to a business, or an email account that everything else can be reset through, I'd actively recommend moving up to one of these rather than stopping at an authenticator app. It's a bit more setup for a noticeably stronger result.

The One Thing I Tell Everyone Before They Turn Any of This On
Whichever method you choose, the step people skip is saving the backup codes that get generated during setup, and it's the step that causes the most panic later. Lose the phone your authenticator app lived on without those codes saved somewhere safe, and you can end up locked out of your own account with no quick way back in. I keep mine stored inside a password manager rather than as a screenshot or a note on the same phone that might get lost alongside them, which keeps them accessible to me and nowhere useful to anyone else. It's a five minute step that people only regret skipping once, and by then it's too late to matter.
None of this needs to be complicated, and you don't need to fix every account at once. Start with whichever one would hurt the most if someone got into it, usually your email account since so much else can be reset through it, move it up to an authenticator app if it's still sitting on text message codes, and save the backup codes properly while you're there. I've written more on why I treat my own email login as the one that gets the most protection of all, and the excuses I used to make before I actually got round to doing any of this. If you want a password manager that makes storing backup codes and everything else this involves genuinely simple, NordPass is the one I recommend, I've covered the fuller picture in a free Safety Toolkit if you want it all in one place, and the NCSC has its own guidance on two-factor authentication if you want a second source to check mine against.
