Two-Factor Authentication Methods: Security Keys, Apps and SMS
MFA combines independent authentication factors; cryptographic security keys and passkeys provide the strongest phishing resistance, while authenticator codes, push prompts and SMS offer different tradeoffs.
Timeline
- Choose: Prefer a phishing-resistant passkey or security key where the service supports it, then compare app, push and SMS fallbacks.
- Enroll: Register more than one recovery route, store recovery codes safely and protect the email account used for recovery.
- Use and review: Reject unexpected prompts, remove obsolete devices and recheck recovery options after changing a phone number or device.
Two-factor authentication, or 2FA, requires two different kinds of evidence, while multifactor authentication, or MFA, can require two or more. NIST groups factors as something a person knows, something a person has and something a person is. A password plus another password or PIN still uses only the knowledge factor, so it is not true two-factor authentication. A password plus a registered security key combines knowledge and possession. [1][2]
Adding a second factor can stop an attacker who has only obtained a password. CISA therefore recommends enabling MFA on every account that offers it, especially email, financial, cloud-storage and administrator accounts. The practical benefit depends on the method, however. MFA is a category rather than a single security level, and recovery procedures can become the easiest path into an otherwise well-protected account. [1][3]
A FIDO security key or properly implemented passkey uses cryptographic authentication bound to the legitimate website. NIST calls this verifier-name binding and recognizes WebAuthn, used by FIDO2 authenticators, as a phishing-resistant approach. Because the authenticator responds to the real domain rather than handing the user a reusable code, a convincing fake login page cannot simply relay that response to the genuine service. [2][4]
Authenticator apps commonly generate time-based one-time passwords. They avoid dependence on text-message delivery and are a useful improvement when a security key or passkey is unavailable. NIST nevertheless says manually entered OTP authentication is not phishing-resistant: a fraudulent site can ask for the current code and immediately relay it. Users should still inspect the address and should never disclose a code to a caller or message sender. [2][3]
Push approval can be convenient, but an unexpected prompt should be treated as evidence that somebody may know the password. Repeated prompts can pressure a user into approving by mistake. When a service offers number matching or displays the requesting device and location, check those details instead of reflexively accepting. A biometric used to unlock an authenticator generally stays on the device; it does not automatically make every remote login system phishing-resistant. [1][2]
Codes delivered by SMS or email are usually the weakest common fallback because the delivery account or phone number may itself be taken over, and the code can still be phished. They can remain better than a password alone when stronger choices are unavailable. Protect the email account with its own strong MFA, add a carrier account PIN where appropriate, and move to a cryptographic option when the service adds support. [1][3]
Good setup includes recovery before an emergency. Register a second compatible key or device when allowed, print or securely store one-time recovery codes, and confirm which support process can reset the account. Never keep the only recovery code solely on the phone it is meant to replace. After losing or selling a device, revoke it from account settings, update recovery contacts and review recent sessions for unfamiliar access. [1][2][3][4]
Sources
- CISA — Require Multifactor Authentication
- NIST SP 800-63B — Authenticator and Verifier Requirements
- CISA — Turn On MFA
- NIST SP 800-63B — Syncable Authenticators