The methods, ranked
Not all second factors are equal, and the settings page rarely says which is which. From strongest to weakest, they run as follows.
- A hardware security key or a passkey is the strongest, because it checks the site's real address and simply will not work on a fake one.
- An authenticator app comes next, producing a six-digit code that changes every thirty seconds and never travels over the phone network.
- A push prompt that asks you to approve a login is convenient and reasonably strong, provided you only ever approve logins you started.
- A code sent by text message is the weakest common option, because a thief who talks your carrier into moving your number to a new SIM card receives your codes.
A text message code is still far better than nothing. Use it wherever it is the only thing on offer.
The order to do it in
Start with your email, because the password reset for every other account lands there. Then protect your password manager, your bank and investment accounts, the main account that runs your phone and cloud storage, your social media, and finally any shop that stores your card. The whole job takes about an hour.
Backup codes and new phones
When you turn on two-factor authentication, most services hand you eight or ten single-use backup codes. These get you in when the phone is lost or broken. Print them, or keep them in your password manager, and keep the codes for the manager itself and for your email on paper. The classic mistake is wiping or trading in an old phone before moving the authenticator app, since those accounts do not always come across in an ordinary phone backup. Confirm that the codes work on the new phone before the old one leaves your hands.
How it still gets beaten
The codes are rarely cracked. They are asked for. A caller claiming to be your bank's fraud department says a code is on its way and asks you to read it back, and that code is the one that lets the caller in. No legitimate company will ever ask you to read out a code. If a login prompt arrives that you did not start, deny it, and then change that password, because somebody already has it.
Tip Call your mobile carrier and ask for a port-out PIN or number lock on your account. It takes five minutes and closes the SIM-swap route that makes text message codes risky.


