Byte Technology
Byte Security 7 min read

Two-Factor Authentication: Which Method to Use, and Which Accounts First

Every second factor ranks on one question: if you used it on a fake page, would the attacker get in? Only passkeys and security keys answer no.

Byte Editorial

“Turn on two-factor authentication.” It is the most repeated piece of security advice there is, and it hides a decision. The methods gathered under the name 2FA are not variations on a theme — they differ by roughly an order of magnitude in what they actually stop. Choosing SMS over a passkey is not a minor upgrade versus a major one; one of them can be defeated by a stranger who convinces your phone company to move your number.

There is also a second decision buried under the first. Which account you protect, and in what order, matters more than which method you pick — because the real attack does not target the account you are thinking about. It targets the one that can reset all the others.

The one question that ranks every method

The usual framing — SMS versus app versus hardware key — invites a features comparison. The better test is a single question: if you were tricked into using this factor on a fake page, would the attacker get in?

That property is called phishing resistance, and it is the line the standards draw. A fake login page can be a perfect copy of the real one. If you type your password and your six-digit code into it, the attacker is sitting between you and the real site and can simply pass both along — a valid login, from the site’s point of view. The only factors that survive this are ones cryptographically bound to the real site’s address, so a response produced for a look-alike domain is worthless. NIST’s digital identity guidelines put the rule plainly: phishing resistance requires cryptographic authentication, and factors that involve typing in a code by hand — one-time passwords and out-of-band codes alike — are not phishing-resistant. CISA’s own ranking of MFA forms reaches the same conclusion from the defender’s side, and it names exactly one widely available method that passes: FIDO/WebAuthn, the standard behind security keys and passkeys.

The ladder, strongest to weakest

MethodIf you are phished…Main thing that breaks itVerdict
Passkey or security key (FIDO2/WebAuthn)The fake page gets nothing usableRecovery becomes the weak point, not the loginUse wherever it is offered
Authenticator app code (TOTP)Code can be relayed live while validPhishing; not tied to your phone numberSolid default where passkeys are not offered
Push with number matchingNeeds you to read a code off the login screen, so blind approval failsA careful relay can still show you the numberAcceptable interim; keep pushing toward passkeys
Push without number matchingOne tap approvesPush bombing; a tired user taps yesTurn number matching on, or switch methods
SMS or voice codeCode is relayed, or read from a stolen numberSIM swap, network interceptionLast resort; replace when you can
Email codeYour second factor is now only as strong as your emailDelegates your security to another accountAvoid as a factor

This ordering is CISA’s, and it is worth noticing what it is not. It is not “old versus new.” An authenticator app code and an SMS code look equally old-fashioned, but they sit two rungs apart, because the app code does not depend on a phone number that can be taken from you.

The attack that is specific to SMS: the SIM swap

A SIM swap does not break encryption. It uses a phone call. The attacker convinces your carrier’s support line — through impersonation, a bribed insider, or both — to port your number to a SIM they control. From that moment, every text meant for you arrives on their device: your bank’s one-time code, and, more dangerously, the “reset your password” link that the bank sends by text.

The FBI’s figures trace the growth. From January 2018 through December 2020, its Internet Crime Complaint Center logged 320 SIM-swap complaints totaling about $12 million. In 2021 alone: 1,611 complaints and more than $68 million. The complaints are a floor, not a total: the figures reflect only what victims reported. The FBI’s own advice is blunt: once a criminal controls your number, they can defeat any SMS-based second factor, and the fix is to set a PIN or password on your carrier account and to move to app-based or hardware authentication.

Two practical points follow. First, a carrier PIN or port-out lock is worth setting even if you do nothing else — it is the only layer that sits in front of the SMS problem itself. Second, an eSIM raises the bar slightly, but the FBI notes that insider “plugs” at carriers still defeat it, so it is not a substitute for changing the method.

The tap-to-approve trap: push bombing

The push-notification method — a prompt appears, you tap Approve — has its own failure mode, and it is a human one. An attacker who already has your password can trigger the prompt again and again until you approve one out of confusion or sheer irritation. CISA calls this MFA fatigue, or push bombing, and it is why number matching exists: the login screen shows a number, and you have to type it into the app, so a prompt you did not start cannot be approved blindly. MITRE’s catalogue of attacker techniques records the method and its users — APT29, the extortion group LAPSUS$, and Scattered Spider among them.

Note where the weakness lives. The attacker needs your password first; the push is only the second step. And number matching, while it stops blind approval, does not make the method phishing-resistant — it is a mitigation, not a cure. If your app offers passkeys, that is the exit.

The part almost nobody fixes: recovery

Here is the fact that reorders everything. The cleanest way into your accounts is usually not the front door. It is the forgot password link — and the FBI advises avoiding SMS and voice for account recovery, not just for login, because a stolen number receives the reset code too.

Follow that thread and you arrive at your inbox. A password reset for your bank, your brokerage, or your password manager is, nine times out of ten, an email. Your primary email account is the master key to everything else. If it falls, the reset path for every other account falls with it — which is why the order below starts there and not at the bank.

The order that works

  1. Your primary email account. Give it the strongest factor it offers — a passkey or security key if available, an authenticator app if not — and remove phone-number recovery where the provider lets you.
  2. Your password manager. It holds the credentials for everything else, so it earns the same treatment as email.
  3. Financial accounts. Banks and brokerages are often still SMS-only. You cannot change their method, so do what you can: set the carrier PIN, and use a password that exists nowhere else.
  4. Everything else, as you log in. Convert accounts opportunistically; there is no need to audit all of them in one sitting.

If an account offers only SMS

You cannot change the factor, so change what surrounds it. Set a port-out lock or PIN at your carrier. Give the account a password you use nowhere else, so a breach elsewhere cannot be replayed here. And remove SMS as a recovery option on any other account that offers a better one — that is where a stolen number does the most damage.

Two myths worth retiring

“2FA makes an account unhackable.” No. It blocks the most common attacks and raises the cost of the rest, but adversary-in-the-middle phishing and push bombing both work against it, and both exploit the human approval step rather than the cryptography.

“Any 2FA is fine.” Half true, and the half that is false is the expensive part. CISA’s position is that any MFA beats none — which is why turning something on today is the right move. But the differences between the rungs are real, and once the weakest factor is on your most important account, it stops being a stopgap and becomes the thing an attacker plans around.

The bottom line

Use a passkey wherever a site offers one; fall back to an authenticator app where it does not; treat SMS as a placeholder to replace, not a destination; and start with your email account, because it is the reset path for everything else. If you are coming here from a breach notice, the credit tools are a separate fix — how a freeze, an alert, and a lock differ is in Credit Freeze, Fraud Alert, or Credit Lock, and the first-72-hours checklist for a leaked credential is in What to Do After a Data Breach Notice.

Byte is the technology site of the Omni Mundi Compendium network. What US privacy law does and does not protect is covered in What US Privacy Law Actually Protects.

This article is general information about account security, not legal advice. It is AI-written and independently AI-reviewed before publication; the review standard and this article’s findings are recorded in the network’s editorial review log.

Frequently asked questions

Is SMS two-factor authentication good enough?
It is better than nothing, but it is the weakest option still in wide use. A texted code can be intercepted, and it depends on a phone number an attacker can steal through a SIM swap. The FBI and CISA both treat it as a last resort to replace, not a place to stop.
What is the difference between a passkey and an authenticator app code?
A passkey is cryptographically bound to the real site's address, so a look-alike page cannot use it. A six-digit app code is not bound to anything — you can type it into a fake page, and an attacker who is relaying your session in real time can use it while it is still valid. Passkeys are phishing-resistant; app codes are not.
Which account should I protect first?
Your primary email account. It is the recovery route for almost everything else: a password reset for your bank or your password manager is usually a link sent to your inbox. If email falls, the reset path for every other account falls with it.
Does two-factor authentication make an account unhackable?
No. It raises the cost sharply and blocks the most common attacks, but two techniques still work against it: adversary-in-the-middle phishing, which relays your code in real time, and push bombing, which wears you down until you approve a login you did not start. The approval step is a human decision, and it can be fooled.

Sources

  1. Cybersecurity and Infrastructure Security Agency, "Implementing Phishing-Resistant MFA" fact sheet (October 2022) — the ranking of MFA forms from strongest (FIDO/WebAuthn, PKI-based) to weakest (SMS or voice), the vulnerabilities attaching to each, and the statement that FIDO/WebAuthn is the only widely available phishing-resistant authentication
  2. Cybersecurity and Infrastructure Security Agency, "Implement Number Matching in MFA Applications" fact sheet (October 2022) — the definition of MFA fatigue (push bombing), why it works, and number matching as the recommended interim mitigation
  3. Cybersecurity and Infrastructure Security Agency, "More than a Password" program page — that any MFA is better than none, but that forms differ in strength and phishing-resistant MFA is the standard to work toward
  4. National Institute of Standards and Technology, SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (final, July 31, 2025) — phishing resistance requires cryptographic authentication and authenticators that involve manual entry of an output (out-of-band and OTP) are not phishing-resistant; the public switched telephone network is the one authenticator class designated "restricted"; synced passkeys are recognized as an authenticator type
  5. Federal Bureau of Investigation, Internet Crime Complaint Center, Public Service Announcement I-020822-PSA (February 8, 2022) — SIM swap complaints and losses: 320 complaints with about $12 million in adjusted losses from January 2018 through December 2020, rising to 1,611 complaints with more than $68 million in 2021
  6. Federal Bureau of Investigation, public guidance on SIM swapping — that criminals defeat any SMS-based or mobile two-factor authentication once they control the phone number, and that users should avoid SMS and voice for both login and account recovery
  7. MITRE ATT&CK, technique T1621, "Multi-Factor Authentication Request Generation" — the technique of generating MFA requests to tire a user into approving, with documented use by APT29, LAPSUS$, and Scattered Spider
#two-factor authentication#2FA#passkeys#FIDO2#WebAuthn#SIM swap#push bombing#account security