By Eric L.
09/08/2026 · 6 MIN READ

Two-factor authentication (2FA) is a second step after the password: a code, a confirmation on your phone, or a physical key.

Even if the password leaks, nobody gets in without the second factor. But the methods aren't equal. An SMS code can be intercepted by SIM swapping and by phishing; a code from an authenticator app resists SIM swapping but not real-time phishing; a hardware key or passkey (FIDO2) can't be phished by design. The rule: turn on any 2FA today, then move from SMS to an app or a key as soon as you can.

Why use two-factor authentication

Passwords leak: databases get breached, people reuse one password across sites, phishing pages collect them by the thousand. A second factor makes a leaked password useless: the attacker also needs something only you have, your phone or your key. Nearly every email and social media takeover happens to accounts without 2FA.

SMS VS APP VS KEYFIG. 01
                 SMS  App  Key
stops leak        ✓    ✓    ✓
stops SIM swap    ✗    ✓    ✓
stops phishing    ✗    ✗    ✓
works offline     ✗    ✓    ✓
free              ✓    ✓    ✗
SMS and an app share the same weak spot: phishing. Only the key closes every gap, and only the key costs money.
WHY A SECOND FACTORFIG. 02
your password leaks
  ├─ without one: they are in
  └─ with one: the password
     is not enough
breaches happen without you
doing anything wrong

2FA methods from weakest to strongest

SMS and voice calls. A code arrives at your number. Simple, but the number has two weak points. SIM swapping: the attacker convinces the carrier, or uses leaked personal data, to move your number to their SIM, and all your codes go to them. Phishing: a fake site asks for your password and "the code from the SMS," you type it, they log in. Better than nothing; move on as soon as you can.

SIM SWAPPING: THE CODE FOLLOWS THE NUMBERThe servicetexts a codeYour carrierroutes the numberbeforeYour SIMthe code arrivesafterThe attacker's SIMall your codes go hereThe attackermoves your numbertalks the carrier into it,or uses leaked personal dataApp codes and key signatures never travel over your number, so a swap gets the attacker nothing.
Whoever controls your phone number gets your SMS codes; an app or a key isn't tied to the number.

Authenticator apps (TOTP). Google Authenticator, Aegis, Microsoft Authenticator, 2FAS, or the generator built into a password manager. The code is computed on the device from a secret and the time; no network needed, and a SIM swap doesn't help the attacker. The one weakness is real-time phishing: a fake site relays your code to the real one within the same minute. Far stronger than SMS.

● CODE FROM SMS OR AN APPYoupassword + codeLook-alike sitea fake domainsame minuteReal sitelets the attacker in● HARDWARE KEY OR PASSKEYYouwith a keysigns this domainLook-alike sitea fake domainwrong domainReal site refusesno valid signatureA code is just a number to pass along; a key's signature only works on the site it was made for.
A fake site can relay a code within the minute; a key signs for the fake domain, so the relay fails.

Push confirmation. "Is this you? Yes / No" in an app. Convenient, but vulnerable to notification fatigue: an attacker with your password sends requests until you tap Yes by reflex. Good implementations make you match a number shown on the login screen.

Hardware keys and passkeys (FIDO2/WebAuthn). YubiKey and similar devices, or passkeys stored in Apple's or Google's keychain. The key signs a challenge bound to the exact site you're on; a look-alike domain gets no valid signature. Phishing fails by construction. The strongest option for email, the password manager and banking.

WEAKEST TO STRONGESTFIG. 03
SMS code            ||
push approval       ||||
code from an app    ||||||
hardware key        ||||||||||
   └─ a phone number can be
      reissued; a key cannot

Which accounts to protect with 2FA first

  1. Email. Everything else resets through it.
  2. The password manager, if you have one; if not, it's worth getting, see password managers: why and how to choose.
  3. Banking and payment services.
  4. Social media and messengers: in Telegram it's the cloud password under privacy settings; in WhatsApp, two-step verification.
  5. Government services and cloud storage.
WHAT TO ENABLE FIRSTFIG. 04
1  the mailbox everything resets to
2  banking and payments
3  messengers
4  photo and file cloud
5  everything else
   └─ ordered by what you lose

2FA backup codes and recovery

When you enable 2FA, the service gives you backup codes. Store them in the password manager or print them: losing the phone without backup codes means a long exchange with support or a lost account. For TOTP apps, prefer ones with encrypted export (Aegis, 2FAS) so moving to a new phone isn't an ordeal. Have two hardware keys: a daily one and a spare in a drawer.

THREE MISTAKESFIG. 05
codes on the same phone you log
in with, and you lose the phone
backup codes never saved
second factor only on SMS
   └─ each turns protection into
      a way to lose the account

Three common 2FA mistakes

  • One factor in two roles. 2FA codes stored in the same password manager as the passwords, with the same master password and no 2FA on the manager itself. One breach gets everything. At minimum, protect the manager with a key or a separate app.
  • SMS to the same phone that runs the banking app. A stolen, unlocked phone has both the password and the code. Screen lock and a short timeout are mandatory.
  • Ignoring requests you didn't expect. A "confirm sign-in" push when you're not signing in is someone else with your password. Tap No and change the password.
WHERE A TUNNEL FITS HEREFIG. 06
it does not replace a second factor
it does not stop a phishing page
it hides which sites you visit
   └─ different problem, different
      tool

Does a VPN replace 2FA?

Not directly: 2FA protects the account, a VPN protects the connection. They combine well: the VPN keeps a shared network from seeing where you log in and from tampering with pages on public Wi-Fi, while 2FA keeps out anyone who got the password anyway. What a VPN does and doesn't do is in what is a VPN.

The order to enable it in depends on what you lose if an account falls.

Prompt for an AI
Help me prioritise second factors across my
accounts.

My accounts: (list them: mail, banking,
messengers, social, cloud, work).
Do I have a spare phone: (yes / no).
Do I have a hardware key: (yes / no / considering).

Say in what order to enable a second factor and
which method to use for each account.
Point out where SMS would be the weak link.
Tell me what to do with backup codes so I do not
lose access if the phone disappears.

In short

  • Turn on 2FA, at least by SMS, today if you have none.
  • Move to an authenticator app; for email and the password manager, to a hardware key or passkey.
  • Save backup codes; keep a spare key.
  • Passwords long and unique, from the password generator.

404 VPN protects the network side of signing in: VLESS in the apps or a WireGuard config from the dashboard, DNS inside the tunnel, and in the Android app a kill switch in case the tunnel drops on a public network. Get started here.