Multi-factor authentication compared: SMS, apps, keys and passkeys
KINNEX Team5 min read
Passwords alone are the easiest door to break. A second factor closes most of the common attacks, but the strength of that second factor varies.
From weakest to strongest
- SMS codes: better than nothing, but vulnerable to SIM swapping and interception.
- Authenticator app codes: stronger, generated on the phone, though still phishable if a user types the code into a spoofed page.
- Push approval with number matching: convenient, with protection against accidental approvals.
- Hardware security keys (FIDO2): resistant to phishing, because the key checks the real website.
- Passkeys: FIDO-based credentials stored on devices or password managers, replacing the password altogether.
What to prioritise
- Administrators and remote access first. These accounts are the most valuable.
- Email and cloud applications next, since a stolen mailbox is a stepping stone.
- Everyone else, with an approach that people can use daily.
Practical issues
Plan for lost phones with recovery methods. Block legacy authentication that bypasses the second factor. Use conditional access, such as requiring stronger checks from new locations or unmanaged devices. Train users to reject unexpected prompts.
Beyond staff
Customers and partners can also be offered strong options. Where regulation or risk demands it, use phishing-resistant methods.
The best factor is the one actually enabled for everyone, then upgraded over time.