Compare two-step verification methods before choosing one
For a conventional second step, a hardware security key offers strong phishing resistance where supported. A passkey is different: on services such as Google, passkey sign-in can replace the password-and-second-step flow rather than act as an additional step. Authenticator codes are a useful offline alternative; prompts are convenient when the trusted phone is available; SMS is better than a password alone but depends on the phone number and mobile network.
Last verified: 12 September 2026
Compare the methods by failure mode
| Method | Useful when | Main limitation |
|---|---|---|
| Passkey (often not a second step) | The service supports passwordless or passkey-first sign-in confirmed with the device unlock. | Its role, availability, sync and recovery vary by provider and platform; do not assume it is an extra factor. |
| Hardware security key | You need strong phishing resistance or protection for a high-risk account. | The key must be compatible and available; keep a spare or another recovery path. |
| Google prompt | A trusted signed-in phone is nearby and online. | A lost, offline or unavailable phone requires another method. |
| Authenticator code | You need rotating codes that work offline. | Codes can still be typed into a phishing page; transfer and recovery must be planned. |
| SMS or voice code | No stronger supported method is practical. | Depends on the phone number, carrier and signal, and is less resistant to interception or number takeover. |
| Backup code | Your normal second step is unavailable. | Each code is a recovery tool, not a routine method; store it securely and separately. |
Choose for the account, not just the device
Start with the methods the service actually supports. For an email account that can reset other accounts, prioritize phishing resistance and maintain a tested fallback. For a lower-impact account, an authenticator code may be a reasonable balance if passkeys or security keys are unavailable.
Keep recovery independent
Do not make the same phone the only place holding the password, the second factor, and the recovery code. Keep backup codes offline or in a separately protected vault. Enroll a spare security key where the provider permits it, and remove lost devices or keys promptly.
Avoid misleading certainty
No method prevents every account takeover. A passkey or security key reduces phishing risk, but recovery settings and already-signed-in devices still matter. Authenticator codes work without a network, but that does not make a fraudulent sign-in page safe. Prompts should be denied when you did not initiate the sign-in.
For an app-specific example, see Bitwarden Password Manager: what to know before installing. The separate password-manager comparison explains why vault security and account recovery also deserve review.
Authoritative sources
- Google Account Help: Turn on 2-Step Verification
- Google Account Help: Use a security key
- Google Account Help: Sign in with Google prompts
- Google Account Help: Sign in with backup codes
See more decision-focused analysis on Reviews & Comparisons.