Two-factor authentication is probably the single best security upgrade most people can make. It is also the one most people do with the weakest possible version. If your second factor is a text message, you have installed a good lock and left the key under the mat. Here is the honest ranking of the ways to do two-factor, from weakest to strongest, and why the difference matters more than the fact that you turned it on at all.
Why two-factor matters, briefly
A password by itself is one leak away from disaster, and passwords leak constantly, in breaches, through phishing, by reuse. Two-factor authentication adds a second requirement, so that a stolen password alone is not enough to get into your account. Turn it on everywhere that matters. Nobody serious disagrees with that part. The argument, and the whole point of this post, is about which second factor you choose, because they are not remotely equal.
The ranking
SMS codes: the weakest, though still better than nothing. This is the code texted to your phone, and it is by far the most common and the most defeated. It is vulnerable to a SIM swap, where an attacker convinces your carrier to move your number to their SIM and simply receives your codes. It is exposed to the old signaling flaws in the phone network that let codes be intercepted. It funnels through the same handful of carrier and aggregator bottlenecks that see and can leak your login activity. And it is phishable: a fake login page can ask for the code and relay it to the real site in real time, before it expires. SMS two-factor is better than a password alone, but it is the version attackers routinely beat. Use it only where nothing better is on offer.
Authenticator apps: much stronger, and the right default for most people. An authenticator app on your phone generates a rotating six-digit code entirely on the device. No text message, no carrier, no phone number involved. That immediately defeats SIM swaps, the signaling attacks, and the aggregator bottleneck, because the code never travels across the network to reach you. It is still phishable in principle, a fake site can still trick you into typing the current code, but it removes the entire category of phone-number attacks in one move. Use a good, open-source authenticator, and back up its seeds somewhere safe so a lost phone does not lock you out. For most people and most accounts, this is the sweet spot.
Hardware keys and passkeys: the strongest, and the only phishing-resistant option. A physical security key, or a passkey, uses public-key cryptography, and it has one property the others lack: it is phishing-resistant. The key cryptographically verifies the real website’s identity before it will authenticate, which means it simply will not respond to a fake login page, no matter how convincing. That defeats the relay attack that beats both SMS and authenticator codes. This is what actually stops targeted phishing. A hardware key is a small device you tap or plug in; a passkey is the same underlying cryptography stored on your device for convenience. For your most important accounts, this is the tier you want.
The parts people get wrong
Your email is the master key. Whatever protects your email protects, or fails to protect, everything else, because email is the password-reset channel for all your other accounts. If an attacker owns your inbox, they own your life. So put your strongest available factor, ideally a hardware key or passkey, on your email first, before anything else.
Plan for recovery, or you will avoid two-factor entirely. The number one reason people do not turn on strong two-factor is the fear of locking themselves out, and it is a legitimate fear. Solve it deliberately: store your backup codes somewhere safe and offline, and register a second hardware key kept in a different place. Two-factor should protect you from attackers without handing you a new way to lose your own accounts.
Know the passkey fine print. Passkeys are excellent security, but the convenient versions often sync through and tie you to an ecosystem, Apple’s or Google’s, which is its own kind of lock-in. If that matters to you, use device-bound keys or a passkey store you actually control. The security is real; just go in knowing the tradeoff.
And keep it proportionate. For a throwaway account where SMS is the only option, SMS two-factor still beats none. This is a threat-model question, not a purity test. The goal is to move your important accounts, email, financial, anything that would hurt to lose, onto the strong factors, not to achieve perfection on your pizza-ordering login.
Doing it right on a hardened phone
A de-Googled, hardened phone makes the strong path the natural one. You run a good open-source authenticator locally, keep the seeds off any cloud, and use hardware keys or passkeys you control rather than ones an ecosystem holds for you. And moving off SMS two-factor has a bonus we have written about elsewhere: it also gets your logins off the carrier and aggregator bottlenecks, so you are no longer depending on your phone number as a security credential at all. Strong, phishing-resistant, and not routed through anyone you did not choose.
Two-factor is the highest-leverage thing you can do for your account security, so it is worth doing well rather than doing weakly and calling it done. Strongest factor on your email, authenticator apps over SMS everywhere else, hardware keys or passkeys for what truly matters, and a recovery plan so it locks out attackers instead of you.
If you want a phone set up to hold your two-factor the right way, on your terms rather than a carrier’s or an ecosystem’s, email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.