Technology

Two-factor authentication: SMS vs app vs security key

Not all second factors are equal. Here's how SMS codes, authenticator apps, push approvals and security keys or passkeys compare, which attacks each one stops, and how to choose.

Illustrative cover: Two-factor authentication: SMS vs app vs security key
Illustration: Pointales

Two-factor authentication (2FA) means proving who you are with two different kinds of evidence, usually a password plus something else. Any second factor is much better than none. But they are not equally strong. An SMS code can be intercepted or phished. An authenticator app beats SIM swaps but can still be phished. A push approval can be spammed until you tap “yes”. Only security keys and passkeys, built on the FIDO standards, resist phishing by design. That is the ranking set out by the US Cybersecurity and Infrastructure Security Agency (CISA) in its guidance on phishing-resistant MFA.

The three factors

Authentication factors come in three kinds. India’s Reserve Bank uses the same framing in its 2025 directions on authenticating digital payments:

  • Something you know: a password, PIN or passphrase.
  • Something you have: a phone, a card, a hardware token or security key.
  • Something you are: a fingerprint, face or other biometric.

Two-factor (or multi-factor, MFA) authentication combines at least two different kinds. A password plus a security question is still one factor, because both are things you know.

Those RBI directions require at least two distinct factors for domestic digital payments from 1 April 2026, with limited exemptions. They also require that, for most transactions, one factor be dynamic, meaning unique to that transaction. The directions do not mandate SMS OTPs. They list passwords, SMS OTPs, PINs, card hardware, software tokens and biometrics as options, which leaves room for banks to move beyond SMS.

SMS codes: better than nothing, weakest of the lot

An SMS one-time password (OTP) proves you control a phone number. The problem is that a phone number can be taken over or listened in on.

NIST, the US standards body, classes OTPs sent by SMS or phone call as a “restricted” authenticator in its digital identity guidelines, SP 800-63B-4. Services that use them are expected to offer users an alternative and explain the risks. CISA still calls SMS acceptable as a temporary last-resort option while stronger methods are introduced.

For most Indians, SMS OTPs are unavoidable for banking today. The practical defence is to never share an OTP with anyone, including callers who claim to be from your bank. Our guide to how UPI frauds work covers the scams built around that request.

Authenticator apps (TOTP)

Apps such as Google Authenticator and Microsoft Authenticator generate a six-digit code that changes every 30 seconds. They use the time-based one-time password (TOTP) method, an open standard published as IETF RFC 6238 in 2011. When you set it up, the website and your app share a secret key, usually by scanning a QR code. From then on, both sides combine that secret with the current time to calculate the same code independently.

Because no message is sent to your phone number, SIM swaps and SS7 interception don’t apply. CISA lists app-based and token-based OTPs among the best options for organisations that can’t yet adopt phishing-resistant MFA.

Their weakness is that you still type the code, so a convincing fake page can collect it. CISA’s own example of phishing is a fake login portal that collects “the 6-digit code from their mobile phone’s authenticator app”. NIST says plainly that any method involving manual entry of a code “SHALL NOT be considered phishing-resistant”.

Also back up the app, or save the recovery codes a site gives you. If you lose the phone without a backup, getting back into your accounts can be slow.

Push approvals and “MFA fatigue”

Some services send a prompt to an app on your phone: “Is this you trying to sign in? Approve / Deny”. It is convenient, but it creates a new attack. An attacker who already has your password triggers login after login. The prompts keep coming until a tired or confused user taps Approve. CISA calls this push bombing, or push fatigue.

It has worked against large companies. Uber said in September 2022 that an attacker used a contractor’s stolen password, triggered repeated two-factor approval requests, and got in when the contractor accepted one.

The fix is number matching: the login screen shows a number, and you must type it into the app to approve. CISA recommends it for any push-based system that isn’t phishing-resistant. NIST says push systems should limit how many prompts are sent. For users, the rule is simple: if you get a sign-in prompt you didn’t start, deny it and change your password.

Security keys and passkeys

Security keys are small USB or NFC devices. Passkeys are the same FIDO technology stored in your phone, computer or password manager. Instead of a code, your device signs a one-off challenge with a private key that never leaves it. Crucially, it only does so for the genuine website it was registered with. A lookalike site gets nothing, so there is nothing to phish, no SMS to intercept and no prompt to spam.

CISA calls FIDO/WebAuthn the only widely available phishing-resistant authentication and “the gold standard”. Its mobile guidance names hardware security keys as the most effective form. Our passkeys explainer covers how they work, how they sync and what happens if you lose a device.

The drawbacks are practical rather than technical. Not every site supports them, hardware keys cost money and can be lost, and recovery depends on having a second key or a synced copy.

Comparison

MethodSIM swap / SS7Phishing (fake site)Spam approvalsConvenienceMain risk
SMS OTPVulnerableVulnerableNot applicableHigh; nothing to installNumber takeover, interception, sharing codes
Authenticator app (TOTP)Not applicableVulnerableNot applicableMedium; type a codeFake sites, losing the phone without backup
Push without number matchingNot applicableVulnerableVulnerableHigh; one tapTapping “Approve” by mistake
Push with number matchingNot applicableVulnerableResistantMediumFake sites relaying the login
Security key / passkey (FIDO)Not applicableResistantNot applicableHigh once set upRecovery if all devices are lost

Based on CISA’s ranking of MFA methods and NIST SP 800-63B-4.

Which should you use?

This is general guidance. Your bank, employer or app may dictate what is available.

  1. Turn on some form of 2FA everywhere it is offered. CISA notes that any MFA is better than none.
  2. Use passkeys or security keys where available, starting with your email account and your Google, Apple or Microsoft account. These are the keys to resetting everything else.
  3. Where passkeys aren’t offered, prefer an authenticator app to SMS. Then remove SMS as a backup if the site allows it. CISA warns that adding an app does not automatically switch off SMS, which can leave a weak fallback.
  4. Treat every unexpected prompt or OTP as a warning sign. Deny it, don’t share it, and change your password.
  5. Plan for losing your phone. Save recovery codes offline, add a second passkey or key, and keep your mobile number and recovery email up to date.

The point: Two-factor authentication is only as strong as the factor you choose. SMS codes can be stolen through the phone network or simply talked out of you. App codes can still be phished. Push prompts can be spammed. Passkeys and security keys are the only common option that a fake website cannot trick, so switch to them wherever they are offered and keep a backup way in.

Sources

Chander Prakash

Chander Prakash

Chander Prakash is the founder and editor of Pointales. He reviews every story before it is published and sets the publication's editorial standards, with a focus on clear, well-sourced explanations of business and technology.