"Turn on 2FA" is good advice that hides an enormous range. Here is what each method actually buys you.
| Method | Stops a breached / reused password | Stops a convincing phishing page | Stops a stolen session cookie |
|---|---|---|---|
| Password only | No | No | No |
| SMS code | Yes | No | No |
| Authenticator app code (TOTP) | Yes | No | No |
| Push approval | Yes | Not reliably | No |
| Push with number matching | Yes | Partly | No |
| Passkey / hardware security key | Yes | Yes | No |
Read the last column first. Nothing in it says yes. That is not a flaw in the methods — it is a reminder that a second factor protects the act of logging in, and a stolen session cookie is not a login. It is a login that already happened, resumed by someone else. Different problem, different defence, covered in our piece on infostealers.
A text message is a second factor delivered over a channel you do not control. Three separate weaknesses:
Regulators have responded — US carriers are now subject to rules requiring stronger customer authentication before a SIM change or a number port. That raises the bar; it does not remove the category. Treat SMS as better than nothing and worse than everything else.
A time-based code from an app never travels over the phone network, so SIM swapping is irrelevant. That is a genuine improvement, and for most accounts it is the practical default.
What it does not survive is a real-time relay. A phishing page proxies your login: you type your password, it forwards it to the real site, the real site asks for a code, the page asks you for the code, you type it, it forwards that too. The code is valid, the attacker is logged in, and you are looking at an error message. The code was correct. It was just typed into the wrong place — and any secret you can read and retype can be relayed this way.
An approve/deny prompt removes the typing, which removes the simplest relay. The failure mode is fatigue: send enough prompts, at a bad enough moment, and someone eventually taps approve. Number matching — where the site shows a number you must select in the app — substantially reduces that, because there is no longer a single button to press reflexively. It is a good option where offered.
A passkey is not a password, and not a code. It is a cryptographic key pair.
When you create one, your device generates two halves. The private half stays on your device, in hardware designed to keep it there, and is released only after you prove you are present — a fingerprint, a face, a PIN. The public half goes to the website. To log in, the site sends a random challenge; your device signs it with the private key; the site verifies the signature against the public key it stored.
Three properties fall out of that, and they are the whole argument:
That last point is why passkeys are a genuine category change rather than a nicer code. Every other method on the ladder depends, at some moment, on a human correctly judging whether a page is real.
This is the section most passkey coverage skips, and it is where the real decisions are.
A passkey protects the front door. Recovery is the side door, and it is usually still guarded by an email link, a text message, or a support agent asking questions. If your account can be reset with an SMS code, then adding a passkey has not made the account passkey-strength. It has made the front door stronger than the side door, and attackers use side doors.
Spend twenty minutes on this and you will get more security than from any other change in this article.
For each important account, write down three things: the strongest factor it requires, every way the account can be recovered without that factor, and therefore the weakest route in. The third column is your actual security level.
| Account | Strongest factor | Recovery paths | Real strength |
|---|---|---|---|
| Passkey | SMS code, backup email | SMS | |
| Bank | App approval | Phone call + knowledge questions | Knowledge questions |
| Password manager | TOTP | None — recovery code only | TOTP |
That table is an example, not a finding about your accounts. Filling it in for real is the exercise, and the pattern is usually the same: the front door has been upgraded and the side door has not.
Then, where the provider allows it: remove the weak recovery path, or replace it. Many services let you delete a recovery phone number once another method exists. Some let you turn off SMS as a factor but quietly keep it for recovery — which is why you have to read the recovery settings specifically, not just the two-factor page.
1Start with email. It resets everything else, so it deserves the strongest factor available and the narrowest recovery path you can live with. Doing email first means a mistake elsewhere is recoverable.
2Turn on passkeys where they are offered — email, your password manager, financial accounts, anything holding money. It usually takes one click on a settings page.
3Get two hardware keys if you want the strongest option, and register both. One lives with you, one lives somewhere safe. One key is a single point of failure; two is a system.
4Replace SMS with an authenticator app everywhere a passkey is not available — then check whether SMS survived as a recovery method anyway.
5Save every recovery code offline, on paper or in a vault that is not the thing they recover. Codes stored inside the account they unlock are decoration.
6Add a carrier PIN or port-freeze on your mobile account. It is free, it takes one call or one settings page, and it is the direct defence against the SIM swap that makes SMS weak.
7Do the recovery audit above for your five most important accounts. This is the step that finds the gap the others leave.
One thing not to do: do not let perfect be the enemy of done. An authenticator app on every account today beats a plan to buy hardware keys next month. The ladder exists so you can climb it, not so you can wait at the bottom for the top rung.
Two of the weakest links above do not run on technology at all. They run on facts about you.
A SIM swap is a social engineering attack on your carrier. Whoever calls needs to sound like you: your address, your date of birth, maybe a previous address or the last four digits of something. Knowledge-based recovery questions are the same attack aimed at a support desk. Previous addresses, relatives' names, the city you were born in — these are not secrets. They are product categories, compiled and sold.
So the honest framing: passkeys and hardware keys close the technical routes in, and what remains is the human route, which is powered by published data. Removing that data does not replace 2FA — nothing does. It narrows the channel that the strongest key on the market cannot defend, because the attacker never touches your key. They talk to someone who can reset it. We have written about the sharpest version of this in what happens when a data broker gets your Social Security number, and the general scope in what data brokers know about you.
Turn on passkeys and set a carrier PIN today — both are free and both matter more than anything you can buy. Then, for the part that is not a settings page: Vigilant Privacy sends legal deletion demands to the brokers publishing the addresses, phone numbers, dates of birth and relatives used to talk past a support desk, and tracks what each one does about it, for $9.95/month.
Start free — no card requiredNo signup, no card, no data kept.