EDITS

Cyber Tips

Multi-factor authentication: the four kinds, ranked

Multi-factor authentication means needing a key and a lock combination to open your IT door. Even if someone steals the password, they are still standing outside.

People talk about MFA as if it were one thing. It is four things, and they are not equally good. Any of them beats none of them — but if you are setting it up today, start at the top of this list.

Do this today
  1. Best: a hardware key (YubiKey and similar) or a passkey stored on your phone. These cannot be phished — they refuse to work on a fake site, which is the whole attack.
  2. Good: an authenticator app that generates six-digit codes. Free, works offline, and vastly better than text messages.
  3. Weak but real: codes by text message. SIM swapping is a genuine attack, but SMS still stops the person who only bought your password. Turn it on if it is the only option.
What good looks like

Your email, your bank, and your password manager all require a second factor, and at least the first two use an app or a key rather than a text message.

You have your backup codes saved somewhere that is not the phone — printed, or in your password manager. Losing a phone should be annoying, not catastrophic.

Want someone to just do this for you? Start a conversation — twenty minutes, free.

Last reviewed: September 2026