Two-factor authentication is a must on all important accounts. But enabling 2FA is not the only choice: there are several methods, and their security varies.
SMS Codes
The most common option: when logging in, the bank or service sends a 6-digit code via SMS. Easy to enable, works on any phone.
Serious downsides:
- SIM-swap. An attacker transfers your SIM card to their phone and receives all your SMS codes. This is not uncommon in the US and Russia; banks in 2024–2025 have publicly acknowledged the issue several times.
- SS7 attacks. A vulnerability in the SS7 protocol allows intercepting SMS without physical access to the SIM. These attacks are technically more complex but are used for high-value targets.
- SIM in roaming. Codes may arrive late or not at all.
SMS is better than nothing, but it's the worst 2FA option available.
Authenticator Apps
Google Authenticator, Authy, Microsoft Authenticator, FreeOTP, Aegis (Android), or Raivo (iOS) — apps that generate 6-digit codes locally, without internet. The standard is TOTP, RFC 6238.
Pros: independent of the mobile operator, nothing to intercept via SS7, works offline.
Cons: if you lose your phone without a backup of recovery codes, you lose access. Therefore, when enabling 2FA via an app, always save recovery codes in a secure place.
Authy and Microsoft Authenticator support cloud backup (with encryption), which reduces the risk of loss but also adds a single point of failure in the form of a Microsoft/Twilio account.
Hardware Keys
YubiKey, Google Titan, SoloKeys — physical USB/NFC devices. Plug into USB or tap to phone — press the button.
Pros: resistant to phishing. Even if an attacker presents a fake site, the key won't confirm the login because the URL in the signing request doesn't match the real one. This is the only method that protects against advanced real-time phishing.
Cons: cost ($25–50 per key), need a backup (if you lose the only one — trouble), not all services support it.
What to Choose in Practice
For major accounts (banking, work Google/Microsoft account, crypto exchange) — a hardware key, plus a backup. It's definitely worth the $50.
For everything else — an authenticator app. Never SMS if you can avoid it.
If a service only supports SMS — check if you can detach the phone number from account recovery and password reset; otherwise, SMS becomes the primary factor and the whole point of 2FA is lost.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.