Explainers
Two-factor authentication explained: factor types and setup
Two-factor authentication adds a second proof of identity to your password. Compare SMS, app codes, security keys and passkeys, and keep recovery codes safe.
Two-factor authentication (2FA) asks for a second proof of identity when you sign in, in addition to your password. An attacker who learns only the password cannot finish the sign-in. The second proof is called a factor, and factors are usually grouped into three kinds: something you know (a password or PIN), something you have (a phone, a code generator or a security key), and something you are (a fingerprint or face scan, which usually unlocks a device rather than proving identity to a website).
2FA is one of the most useful protections you can add to an account, and it is not equally strong in every form. The method you choose matters as much as turning it on.
The factor types, from weakest to strongest
SMS codes. The service texts a one-time code to your phone number. Setup is easy and almost every phone can receive a text. The weakness is that the code travels over the phone network, where it can be intercepted or redirected, for example through a SIM swap in which an attacker convinces a carrier to move your number to their SIM. SMS codes are also easy to phish: a fake page can ask for the code and pass it on. NIST's digital identity guidelines class out-of-band methods such as SMS as not phishing-resistant. SMS is still better than a password alone for many accounts, but it is the option to replace when a stronger one is offered.
Authenticator app codes (TOTP). An app on your phone generates a six-digit code that changes about every 30 seconds, based on a secret shared at setup. Nothing is sent over the network, so SMS interception does not apply. The code can still be typed into a fake login page, and a fast attacker can relay it within its short window. The app is only as safe as the phone it runs on.
Push approvals. The service sends a prompt to an app, and you tap approve. These are convenient, but they can be abused. NIST notes "authentication fatigue" attacks, in which an attacker sends many requests until someone approves one to stop the annoyance. Deny any prompt you did not start.
Hardware security keys. A small device that you plug in or tap. It signs a challenge from the site and checks that the site matches the address it was registered for, so a look-alike domain gets nothing useful. Because the sign-in is bound to the address the key was registered with, a look-alike domain gets nothing useful. NIST's phishing-resistant category is built around this kind of binding. Keys cost money and can be lost, and not every service supports them.
Passkeys. A passkey is a FIDO credential tied to an account. You approve sign-in with the same unlock your device uses, such as a fingerprint, face or PIN. The FIDO Alliance describes passkeys as phishing-resistant and as a way to sign in without a username and password. Unlike the other factors, a passkey can replace the password rather than sit next to it. Your passkeys may sync through a platform account, which is a convenience and a dependency to understand.
| Factor | Protects if the password leaks | Resists phishing | Main weakness |
|---|---|---|---|
| SMS code | Yes | Weak | Interception, SIM swap, lost number |
| Authenticator app code | Yes | Partial | Code can be entered into a fake page |
| Push approval | Yes | Partial | Approval fatigue |
| Hardware key | Yes | Strong | Cost, loss, limited support |
| Passkey | Replaces the password | Strong | Tied to your device and platform account |
How to set up 2FA safely
- Start with the accounts that unlock others. Your primary email address is the usual first choice, because password resets for many other services go there. Mail apps in the email clients ranking read that mailbox, but the 2FA setting itself lives in the account provider's settings. Then add banking, cloud storage and developer accounts.
- Choose the strongest option the service offers. Prefer a passkey or security key, then an authenticator app, and use SMS only if nothing else is available.
- Scan the setup code only from the service's own settings page. Do not scan a QR code that arrived in an email or message, because it may belong to an attacker.
- Save the recovery codes before you finish. The next section explains why.
- Test a sign-in from a second browser or device while your current session is still open. Only sign out of the first session after the test works.
- Keep a second method enrolled where the service allows it, such as a key and an app, so losing one device does not lock you out.
Telegram is one example from the rankings. Its Two-Step Verification is turned on in Settings, under Privacy and Security. Check the current settings screen after any app update, because menu names change.
Recovery codes
Recovery codes are one-time codes that let you sign in when your usual factor is unavailable. NIST describes such codes as a secret for recovering an account you can no longer authenticate to. Treat them as passwords:
- Store them offline, in a place you control, such as a printed copy in a safe or a paper copy kept with important documents.
- Do not keep them in the same unlocked phone or cloud note that holds the account they protect.
- Each code works once. Generate a new set after you use one, and retire the old set.
- Note that NIST classes look-up secrets, including saved recovery codes, as not phishing-resistant. Never type one into a page you reached from a link you did not start.
If you lose the phone and the recovery codes at the same time, you may be locked out with no route back. Services differ on account recovery, so read how yours handles that before you need it.
Mistakes to avoid
- Turning on 2FA and skipping the recovery codes. Many people discover the gap only when they change phones.
- Keeping every factor on one device. If the same phone holds your authenticator app, your messages and your email, a single loss or theft hits everything at once.
- Relying on a phone number you no longer control. Update the number on each account when you change carriers.
- Approving prompts you did not start. Treat an unexpected approval request as an attack and change the password.
- Giving codes to anyone who asks. Legitimate support staff do not need a one-time code from you. Anyone who asks for it is trying to sign in as you.
- Assuming 2FA stops everything. A compromised computer can still act inside a signed-in session, and a stolen session cookie can bypass a sign-in prompt. Keep devices updated and sign out of shared machines.
What to do next
Start with your email account, then move through banking and cloud storage. If you use messaging apps, check whether their privacy settings offer a second step as well. The messaging apps ranking compares several of them. For the encryption side of messaging, read the end-to-end encryption explainer. 2FA protects the sign-in. End-to-end encryption protects the content, and neither covers the other's gaps.
Compare head to head
Mentioned in this article
Keep reading
All articles- Explainers · 5 min readWhat end-to-end encryption means and what it does not coverEnd-to-end encryption means only the sender and recipient hold the keys. Learn how it differs from in-transit and at-rest encryption, and how to check claims.
- Guides · 5 min readHow to choose a messaging app: encryption, numbers, groupsCompare messaging apps by encryption by default, phone number requirements, metadata, group features, backups and platforms, with picks from the messaging ranking.
- Comparisons · 5 min readSignal vs Telegram: Which Messaging App Fits You?Signal encrypts chats by default and is run by a nonprofit, while Telegram suits large groups and channels. Compare encryption, platforms, cost and openness.



