Reviewed by the Foxmole editorial team · 2026-07-29

Key takeaways

  • Any 2FA beats none.
  • An authenticator app or passkey beats SMS.
  • Protect your email and bank first.

Two-factor authentication (2FA) means logging in needs two things: something you know (your password) and something you have (your phone or a security key). Even if someone steals your password, they can’t get in without the second factor. It’s one of the highest-value security steps you can take in five minutes.

The types, weakest to strongest

  • SMS codes, a text with a code. Better than nothing, but vulnerable to SIM-swapping and interception. Use it only if it’s the sole option.
  • Authenticator apps, generate a rotating code on your device, no signal needed, not interceptable by SIM-swap. A big step up, and free.
  • Passkeys / hardware security keys, cryptographic keys tied to your device or a physical key. The strongest widely-available option and resistant to phishing.

At a glance

Method Security Convenience Best for
SMS codes Low–medium High Only if nothing else is offered
Authenticator app High Medium Most people, most accounts
Passkey / hardware key Highest Medium Email, banking, critical accounts

Turn it on here first

  • Email, it can reset every other account, so protect it first.
  • Banking and payment apps.
  • Password manager master account.
  • Social and cloud storage, which attackers use to reach your contacts and files.

Practical tips

  • Save backup codes when you enable 2FA, somewhere offline, so you’re not locked out if you lose your phone.
  • Prefer an authenticator app or passkey over SMS wherever both are offered.
  • Enrolling a second device or key as backup avoids lockouts.

Why it’s worth the minor hassle

The extra step costs you seconds occasionally; it costs an attacker the entire attack, because a stolen password alone no longer works. That trade is heavily in your favor.

Related guides

Guide
How to shop online safely

Guide
Is public Wi-Fi actually dangerous?

Guide
What to do after a data breach