Two-factor authentication (2FA) means proving who you are with two different kinds of evidence, usually a password plus something else. Any second factor is much better than none. But they are not equally strong. An SMS code can be intercepted or phished. An authenticator app beats SIM swaps but can still be phished. A push approval can be spammed until you tap “yes”. Only security keys and passkeys, built on the FIDO standards, resist phishing by design. That is the ranking set out by the US Cybersecurity and Infrastructure Security Agency (CISA) in its guidance on phishing-resistant MFA.
The three factors
Authentication factors come in three kinds. India’s Reserve Bank uses the same framing in its 2025 directions on authenticating digital payments:
- Something you know: a password, PIN or passphrase.
- Something you have: a phone, a card, a hardware token or security key.
- Something you are: a fingerprint, face or other biometric.
Two-factor (or multi-factor, MFA) authentication combines at least two different kinds. A password plus a security question is still one factor, because both are things you know.
Those RBI directions require at least two distinct factors for domestic digital payments from 1 April 2026, with limited exemptions. They also require that, for most transactions, one factor be dynamic, meaning unique to that transaction. The directions do not mandate SMS OTPs. They list passwords, SMS OTPs, PINs, card hardware, software tokens and biometrics as options, which leaves room for banks to move beyond SMS.
SMS codes: better than nothing, weakest of the lot
An SMS one-time password (OTP) proves you control a phone number. The problem is that a phone number can be taken over or listened in on.
- SIM swap. A fraudster persuades or tricks a mobile operator into issuing a new SIM for your number, then receives your OTPs. RBI’s Ombudsman office describes fraudsters posing as telecom staff and offering a “free upgrade” from 3G to 4G to obtain a duplicate SIM. Its advice: if your phone loses network for a long time in a normal setting, contact your operator. In India, TRAI rules effective 1 July 2024 bar requesting a number port within seven days of a SIM swap or replacement, to block one route for this fraud.
- SS7 interception. SS7 is an old signalling system that telecom networks use to route calls and texts between operators. CISA notes that attackers exploit SS7 vulnerabilities to obtain MFA codes sent by SMS or voice. In December 2024 guidance for highly targeted individuals, it went further: “Do not use SMS as a second factor for authentication”, because SMS messages are not encrypted and anyone with access to a telecom network who intercepts them can read them.
- Phishing. A fake site asks for your password and then your OTP, and passes both to the real site while the code is still valid.
NIST, the US standards body, classes OTPs sent by SMS or phone call as a “restricted” authenticator in its digital identity guidelines, SP 800-63B-4. Services that use them are expected to offer users an alternative and explain the risks. CISA still calls SMS acceptable as a temporary last-resort option while stronger methods are introduced.
For most Indians, SMS OTPs are unavoidable for banking today. The practical defence is to never share an OTP with anyone, including callers who claim to be from your bank. Our guide to how UPI frauds work covers the scams built around that request.
Authenticator apps (TOTP)
Apps such as Google Authenticator and Microsoft Authenticator generate a six-digit code that changes every 30 seconds. They use the time-based one-time password (TOTP) method, an open standard published as IETF RFC 6238 in 2011. When you set it up, the website and your app share a secret key, usually by scanning a QR code. From then on, both sides combine that secret with the current time to calculate the same code independently.
Because no message is sent to your phone number, SIM swaps and SS7 interception don’t apply. CISA lists app-based and token-based OTPs among the best options for organisations that can’t yet adopt phishing-resistant MFA.
Their weakness is that you still type the code, so a convincing fake page can collect it. CISA’s own example of phishing is a fake login portal that collects “the 6-digit code from their mobile phone’s authenticator app”. NIST says plainly that any method involving manual entry of a code “SHALL NOT be considered phishing-resistant”.
Also back up the app, or save the recovery codes a site gives you. If you lose the phone without a backup, getting back into your accounts can be slow.
Push approvals and “MFA fatigue”
Some services send a prompt to an app on your phone: “Is this you trying to sign in? Approve / Deny”. It is convenient, but it creates a new attack. An attacker who already has your password triggers login after login. The prompts keep coming until a tired or confused user taps Approve. CISA calls this push bombing, or push fatigue.
It has worked against large companies. Uber said in September 2022 that an attacker used a contractor’s stolen password, triggered repeated two-factor approval requests, and got in when the contractor accepted one.
The fix is number matching: the login screen shows a number, and you must type it into the app to approve. CISA recommends it for any push-based system that isn’t phishing-resistant. NIST says push systems should limit how many prompts are sent. For users, the rule is simple: if you get a sign-in prompt you didn’t start, deny it and change your password.
Security keys and passkeys
Security keys are small USB or NFC devices. Passkeys are the same FIDO technology stored in your phone, computer or password manager. Instead of a code, your device signs a one-off challenge with a private key that never leaves it. Crucially, it only does so for the genuine website it was registered with. A lookalike site gets nothing, so there is nothing to phish, no SMS to intercept and no prompt to spam.
CISA calls FIDO/WebAuthn the only widely available phishing-resistant authentication and “the gold standard”. Its mobile guidance names hardware security keys as the most effective form. Our passkeys explainer covers how they work, how they sync and what happens if you lose a device.
The drawbacks are practical rather than technical. Not every site supports them, hardware keys cost money and can be lost, and recovery depends on having a second key or a synced copy.
Comparison
| Method | SIM swap / SS7 | Phishing (fake site) | Spam approvals | Convenience | Main risk |
|---|---|---|---|---|---|
| SMS OTP | Vulnerable | Vulnerable | Not applicable | High; nothing to install | Number takeover, interception, sharing codes |
| Authenticator app (TOTP) | Not applicable | Vulnerable | Not applicable | Medium; type a code | Fake sites, losing the phone without backup |
| Push without number matching | Not applicable | Vulnerable | Vulnerable | High; one tap | Tapping “Approve” by mistake |
| Push with number matching | Not applicable | Vulnerable | Resistant | Medium | Fake sites relaying the login |
| Security key / passkey (FIDO) | Not applicable | Resistant | Not applicable | High once set up | Recovery if all devices are lost |
Based on CISA’s ranking of MFA methods and NIST SP 800-63B-4.
Which should you use?
This is general guidance. Your bank, employer or app may dictate what is available.
- Turn on some form of 2FA everywhere it is offered. CISA notes that any MFA is better than none.
- Use passkeys or security keys where available, starting with your email account and your Google, Apple or Microsoft account. These are the keys to resetting everything else.
- Where passkeys aren’t offered, prefer an authenticator app to SMS. Then remove SMS as a backup if the site allows it. CISA warns that adding an app does not automatically switch off SMS, which can leave a weak fallback.
- Treat every unexpected prompt or OTP as a warning sign. Deny it, don’t share it, and change your password.
- Plan for losing your phone. Save recovery codes offline, add a second passkey or key, and keep your mobile number and recovery email up to date.
The point: Two-factor authentication is only as strong as the factor you choose. SMS codes can be stolen through the phone network or simply talked out of you. App codes can still be phished. Push prompts can be spammed. Passkeys and security keys are the only common option that a fake website cannot trick, so switch to them wherever they are offered and keep a backup way in.
Sources
- Implementing phishing-resistant MFA — CISA, October 2022
- Mobile communications best practice guidance — CISA, December 2024
- SP 800-63B-4: Digital Identity Guidelines, Authentication and Authenticator Management — NIST, July 2025
- RFC 6238: TOTP, Time-Based One-Time Password Algorithm — IETF, May 2011
- Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025 — Reserve Bank of India, September 2025
- BE(A)WARE: a booklet on modus operandi of financial fraudsters — Office of the RBI Ombudsman, Mumbai-II
- Telecommunication Mobile Number Portability (Ninth Amendment) Regulations, 2024 to come into force on July 1 — All India Radio News, June 2024
- Security update — Uber, September 2022