Lesson 4 +15 XP

2FA Explained (SMS vs Authenticator Apps vs TOTP)

Two Locks Are Better Than One!

Even with strong passwords, a key can be stolen. Multi-Factor Authentication (2FA) adds a second layer of defense.

The 3 Factors of Authentication

  1. Something You Know: Password or PIN.
  2. Something You Have: Authenticator app, phone, or hardware key.
  3. Something You Are: Fingerprint, Face ID, or iris scan.

Comparing 2FA Methods (From Weakest to Strongest)

MethodSecurity LevelVulnerability
SMS / Text Message⚠️ LowSIM Swapping (attackers trick phone carriers into transferring your phone number)
Email Verification🟡 MediumVulnerable if your primary email is compromised
Authenticator Apps (TOTP)🟢 HighTime-based 6-digit codes (Aegis, Ente Auth, 2FAS)
Hardware Keys (FIDO2)🛡️ MaximumPhishing-resistant physical USB key
⚠️ Warning

Avoid SMS 2FA whenever possible! Cybercriminals frequently target phone carriers to hijack phone numbers via SIM swaps and intercept SMS codes.