Tuesday, September 29, 2026
Independent Edition
Archive
THE POLITICAL HURRICANE
Politics, Policy and Public Life
Privacy & Security

Two-Factor Authentication Isn’t One Thing: Why Some Methods Are Much Stronger

SMS codes, authenticator apps, push prompts, security keys and passkeys all get called “two-factor authentication.” They do not provide the same protection.

Laptop representing cybersecurity and account authentication
Photo by FlyD on Unsplash.

“Turn on two-factor authentication” is good advice. It is also incomplete advice.

A text message, a six-digit code from an authenticator app, a push notification and a hardware security key can all be used as a second step when signing in. They are not equally resistant to attack.

That matters because modern phishing is often designed not merely to steal your password, but to trick you into handing over the second factor too.

The basic idea is still sound

Multifactor authentication requires more than one form of evidence before an account accepts a login.

Traditionally, those factors are described as something you know, something you have or something you are: a password, a device or token, or a biometric characteristic.

The advantage is obvious. A stolen password by itself is no longer enough.

But a six-digit code can still be phished

Suppose an attacker creates a convincing fake login page.

You enter your password. The real service sends or generates a one-time code. The fake page asks you for that code too. If the attacker relays both to the real service quickly enough, the second factor has not saved you from the fake site.

This is why the National Institute of Standards and Technology does not classify manually entered one-time passwords as phishing-resistant authentication.

SMS is better than password-only — but it sits low on the hierarchy

CISA’s guidance is blunt: any MFA is better than none, but text- or email-delivered one-time codes provide weaker protection than stronger alternatives.

SMS can be exposed to several failure modes, including phishing and attacks involving a victim’s mobile number.

That does not mean somebody should disable SMS MFA and go back to a password alone. It means that, where a stronger method is available, there is a reason to move up.

Authenticator apps improve the setup, but the details matter

An authenticator app that generates rotating codes avoids some of the weaknesses of SMS delivery because the code is generated on the device rather than transmitted through the mobile network.

But the code is still something a user can type into a fake website. That means it can still be phished.

Push-based authentication can also be abused if users are trained to approve prompts mechanically. Number matching — where the app requires the user to confirm a number shown on the login screen — is designed to reduce simple “approve this notification” attacks.

Phishing-resistant authentication changes the game

CISA recommends moving toward phishing-resistant MFA, particularly FIDO/WebAuthn-based authentication.

The important difference is that the authenticator is cryptographically bound to the legitimate service. A fake site cannot simply ask you to copy a valid code and relay it.

This is the security idea behind modern hardware security keys and many passkey implementations.

Security keys are strong because the user has less to decide

That sounds backwards, but it is important.

Traditional phishing defense often depends on a human noticing that a URL is slightly wrong, a page looks suspicious or a request arrived unexpectedly.

Phishing-resistant authentication is designed so the protocol itself refuses to authenticate to the wrong service. NIST describes phishing resistance as preventing valid authentication secrets or outputs from being disclosed to an impostor verifier without relying on the user’s vigilance.

That is a much stronger model than hoping every person spots every fake login page.

Where do passkeys fit?

Passkeys use public-key cryptography and are designed to replace traditional password-based authentication in supported systems. Depending on implementation, they can provide phishing-resistant authentication because the credential is bound to the legitimate website or application.

The practical benefit for ordinary users is that the strongest login method can also be easier: a device prompt, fingerprint or face check may replace remembering and typing a password plus copying a temporary code.

What should you use?

For accounts that support it, a practical order of preference is:

  1. Phishing-resistant methods such as a FIDO security key or supported passkey.
  2. Strong authenticator-app methods, especially number matching where available.
  3. Authenticator-app one-time codes.
  4. SMS or email codes when stronger methods are not offered.
  5. Password-only as the last and weakest option.

The exact choices depend on what a service supports, whether you need recovery options and how much complexity you can manage.

Do not forget account recovery

A wonderfully secure login method becomes a problem if losing one device permanently locks you out.

When enabling stronger authentication, review recovery methods too: backup keys, recovery codes, secondary authenticators or other options supported by the service.

Store recovery material somewhere different from the device you use every day.

The 2026 shift is no longer theoretical

Large identity platforms are now moving users away from weaker authentication methods rather than merely recommending stronger ones.

Microsoft Entra began making passkeys the default authentication experience on September 1, 2026 for users enabled for SMS or voice, with registration prompts appearing during MFA sign-in. Microsoft says its own SMS and voice authentication will be retired for most affected users on February 1, 2027, with later timing for some administrator and external-user groups.

That makes the hierarchy in this article practical rather than academic: organizations are actively being pushed from phishable factors toward passkeys, Windows Hello and FIDO2 security keys.

The harder question is recovery, not login

Recent user discussions around passkeys repeatedly come back to the same fear: what happens if the phone is lost, the laptop dies, or every device containing a credential disappears at once?

That is not an argument for weak authentication. It is a reminder that the recovery path is part of the security design.

Before switching an important account to passkeys, check whether the service supports multiple passkeys, synced credentials, a second hardware key, recovery codes or another strong fallback. A phishing-resistant front door paired with a weak SMS recovery route can leave the account dependent on the weaker path.

Passkeys solve phishing; they do not solve every endpoint problem

There is another useful nuance that simplistic “passkeys are unhackable” coverage misses.

Passkeys are designed to resist credential phishing because the authentication is bound to the legitimate service. They do not make a compromised device trustworthy. Security research discussed publicly in 2026 has focused on attacks that assume malware is already running locally and then abuse implementation details or the device environment.

The practical lesson is not to retreat to passwords. It is to understand the boundary: phishing-resistant authentication is a major improvement, while device security, software updates and recovery design still matter.

The useful takeaway

The question is no longer merely, “Do you have 2FA?”

It is, “What kind?”

Turning on any second factor is usually an improvement over password-only security. But if an account protects money, email, sensitive work or the ability to reset your other accounts, moving toward phishing-resistant authentication is a meaningful upgrade rather than a cosmetic one.

Sources
CISA — Require Multifactor Authentication MFA guidance and stronger authentication methods.
CISA — More Than a Password Practical multifactor-authentication guidance.
NIST SP 800-63B Phishing resistance and authentication standards.
Microsoft Entra — Passkeys by Default and SMS/Voice Retirement 2026 passkey rollout and 2027 retirement timeline for Microsoft-provided SMS and voice authentication.
SpecterOps — Pass-the-Passkey Research 2026 research on implementation and endpoint attacks around WebAuthn/passkeys.