Multi-factor authentication (MFA) requires a second form of verification beyond your password before granting access to an account. The idea is straightforward: even if your password is stolen — through a data breach, phishing, or malware — an attacker still can't get in without also having your second factor, whether that's your phone, a hardware key, or a fingerprint.
The Three Categories of Authentication Factors
- Something you know — a password or PIN.
- Something you have — a phone that receives a code, an authenticator app, or a physical security key.
- Something you are — a fingerprint or face scan (biometrics).
True multi-factor authentication combines factors from at least two different categories. Two passwords, or a password plus a security question (which is really just another "something you know"), doesn't meaningfully add the same protection.
Common MFA Methods, Compared
| Method | How it works | Strength | Weakness |
|---|---|---|---|
| SMS text code | A one-time code sent by text message | Simple, no extra app needed | Vulnerable to SIM-swapping attacks and interception; weakest common option |
| Authenticator app | App generates a time-based one-time code (TOTP) locally on your device | Not dependent on phone network; works offline | Lost device without backup codes can lock you out |
| Push notification | App sends an approve/deny prompt to a trusted device | Fast and convenient | "Prompt bombing" — repeated requests hoping you approve by mistake or fatigue |
| Hardware security key | Physical USB/NFC device you tap or insert | Highly resistant to phishing and remote attacks | Cost of the device; inconvenient if lost without a backup key |
| Biometric | Fingerprint or face recognition, usually paired with device-level security | Fast, hard to phish remotely | Typically device-bound rather than portable across accounts on its own |
Why SMS Codes Are the Weakest Common Option
SMS-based MFA is far better than no second factor at all, but security researchers have long flagged it as the weakest widely available method, mainly because of SIM-swapping — a social-engineering attack where someone convinces your mobile carrier to transfer your phone number to a SIM card they control, letting them intercept your text-based codes directly. If a service offers an authenticator-app or hardware-key option alongside SMS, those alternatives are generally preferable.
What MFA Doesn't Protect Against
Real limitations
- Sophisticated real-time phishing. Advanced phishing kits can relay your password and one-time code to the real site instantly as you enter them on a fake page, effectively bypassing standard MFA. Hardware security keys using the FIDO2/WebAuthn standard are specifically designed to resist this, because the key cryptographically verifies the site's actual domain before responding.
- Prompt fatigue attacks. An attacker with your password can repeatedly trigger push-notification prompts, hoping you'll eventually approve one out of frustration or confusion. Never approve a login prompt you didn't personally initiate.
- Lost access to your second factor. Always set up backup codes or a secondary MFA method when you enable it, so a lost phone doesn't permanently lock you out of your own account.
Where to Enable It First
You don't need to turn on MFA everywhere at once. Prioritize accounts where a breach would cause the most damage or cascade into other accounts:
- Primary email account — often the recovery method for every other account you own, making it the highest-value target.
- Password manager — protects the master key to all your other credentials.
- Financial accounts — banking, payment services, and investment platforms.
- Social media and cloud storage accounts — frequent targets for both financial fraud and impersonation.
Setting It Up
Most services list MFA setup under Security or Login settings in account preferences. The typical flow: choose a method (authenticator app is a solid default for most people), scan a QR code or enter a setup key into your authenticator app, confirm with a generated code, and — critically — save the backup/recovery codes the service provides somewhere secure and separate from the device running your authenticator app.
Frequently Asked Questions
Is SMS-based two-factor authentication still worth using?
Yes — it's meaningfully better than no second factor at all and blocks a large share of common automated attacks. Where a service offers an authenticator app or hardware key as an alternative, those options provide stronger protection against SIM-swapping and interception.
What happens if I lose the phone with my authenticator app?
This is why saving backup/recovery codes at setup time matters — most services provide a set of one-time backup codes specifically for this scenario. Without them, regaining account access typically requires going through the service's account-recovery process, which can take time.
Can multi-factor authentication be bypassed?
Sophisticated, real-time phishing techniques can bypass some MFA methods, and prompt-fatigue attacks target push notifications specifically. Hardware security keys using the FIDO2/WebAuthn standard are currently the most phishing-resistant widely available option, because they cryptographically verify the destination site before authenticating.