Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Turn on a second factor if a service offers one you can use and recover from. It adds another hurdle when someone has your password—but “any” does not mean every method is equally secure, or that two-factor authentication (2FA) prevents every account takeover.

What a second factor changes

A password-only account depends on one secret. With 2FA, signing in also requires another proof, such as a code or a physical key. That can stop an attacker who has obtained your password but cannot provide the additional proof.

It is an added barrier, not a guarantee. A stolen, already-authenticated session, a compromised device, weak account-recovery procedures, or a successful phishing attempt can still put an account at risk. Ask Leo! makes the practical case for enabling an available second factor in its June 16, 2023 article, updated from an article first posted October 12, 2019.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the common options differ

Method What you need Important limitation
SMS or voice code Access to the phone number receiving the message or call. Phone numbers can be taken over, reassigned, or moved through SIM changes or number porting. NIST classifies PSTN-delivered out-of-band authentication as restricted.
Authenticator-app code (TOTP) The enrolled device and an app that generates time-based one-time passwords. A code typed into a fake sign-in page can be relayed to the real service during a live phishing attempt.
Email code or link Access to the mailbox associated with the account. If an attacker can access or redirect that mailbox, the email may not provide a separate barrier. NIST says email SHALL NOT be used for out-of-band authentication.
Hardware security key A physical key, plus an account and device sign-in flow that support it. Compatibility and recovery options vary. Whether a flow resists phishing depends on how its authentication protocol works, not merely on the fact that a physical key is involved.

These methods have different convenience, compatibility, and recovery trade-offs; no single option is practical for every service or person. Check which methods the service supports and how you can regain access before relying on one factor alone.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why codes can still be phished

A code that changes frequently may sound safe, but a short expiry does not stop an attacker from relaying it immediately. NIST defines phishing resistance in terms of whether the protocol prevents authentication secrets or valid outputs from being disclosed to an impostor verifier without depending on the user to spot the deception. Under that definition, manually entered one-time passwords and out-of-band codes are not phishing-resistant: the entered value is not bound to the specific sign-in session and can be relayed.

NIST’s current guidance states, “Out-of-band authentication is not phishing-resistant.” This is a specific limitation of those methods, not a reason to conclude that all 2FA is useless. A hardware key may support a phishing-resistant flow, but verify the service’s implementation rather than assuming every key or sign-in path has that property. See NIST SP 800-63B-4.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What to do about SMS and email

If SMS is the only usable option

Enabling SMS is generally a better practical choice than leaving an account password-only, while recognizing its exposure to phone-number takeover. NIST treats use of the public switched telephone network (PSTN), including SMS and voice delivery, as a restricted authenticator. Its guidance identifies device swaps, SIM changes, and number porting as risk indicators, and says providers should make alternative authenticator types available. If the service offers another workable method, compare it and set up a recovery route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a service emails you a code or link

Some services use email for sign-in confirmation or account recovery. That is distinct from NIST-conformant out-of-band authentication: NIST says email SHALL NOT be used for that purpose because a mailbox may be accessible with only a password, intercepted, or rerouted. Email can still be part of a service’s own account flow, but whether it adds meaningful protection depends on how well the mailbox itself is secured.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For the standard’s email guidance, see NIST SP 800-63B-4, email.

Set up a factor you can keep using

  1. Open the account’s security settings. Look for the service’s two-factor, two-step, or multi-factor sign-in options; exact labels and available methods vary.
  2. Choose a supported method you can access reliably. Consider whether you have the enrolled device, cellular service, mailbox access, or compatible security key when signing in.
  3. Configure recovery before you depend on the factor. Follow the service’s own recovery instructions and make sure you have a way to regain access if a phone is lost or replaced, or a key is unavailable.
  4. Test the sign-in and recovery details. Confirm the factor works on the devices you use and that the recovery route is available to you; do not assume another device or method is supported.
  5. Revisit the choice when your circumstances change. A new phone number, device, or service-supported method may change which factor is convenient and recoverable.

A FIDO2-compatible security key is one possible physical option when the account supports it. Check compatibility and recovery arrangements before choosing a key.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is two-factor authentication still worth using if hackers can bypass it?

Yes. The fact that some attacks can bypass or evade particular 2FA methods does not erase the protection they add against password-only access. Choose the strongest supported method that fits your account and recovery needs; if a less resistant option is all you can use, it can still add a hurdle. Keep in mind that a phishable code is not equivalent to a phishing-resistant sign-in protocol.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.