A password on its own is a thin lock for an account that holds your money. It can be guessed, reused from a breached site, or typed into a convincing fake login page. That is why security agencies have spent years pushing people towards multifactor authentication (MFA), and why the conversation has now moved on to something stronger: sign-in methods that a fake website simply cannot trick.
This guide walks through the options you are likely to see on a financial account today, from the weakest to the strongest, and the small habits that make each of them work.
What multifactor authentication actually means
CISA describes MFA as "a layered approach to securing your online accounts and the data they contain." Instead of a password alone, you provide two or more authenticators before a service lets you in: typically something you know (a password or PIN), something you have (a phone or security key), or something you are (a fingerprint or face).
The point is simple. If someone steals one factor, such as your password, they still cannot meet the second requirement. CISA is also clear that the type of factor matters: in its words, "any MFA is better than no MFA," but stronger methods offer much better protection.
Here are the common second factors, roughly in order of strength:
- Text or email codes. A one-time code is sent to your phone number or inbox.
- Authenticator apps with one-time codes (TOTP). An app on your phone generates a fresh code every 30 seconds.
- Authenticator apps with number matching. The app shows a prompt and asks you to enter a number displayed on the login screen.
- Passkeys and security keys (FIDO/WebAuthn). A cryptographic credential on your device or a physical key that only works on the genuine website.
Why text-message codes are the weakest option
SMS codes are familiar, and they are far better than nothing. But CISA's own guidance for businesses says a text or email code "provides the weakest protection" and should be used "only if stronger options aren't available for that account."
NIST, the federal agency that publishes US digital identity guidelines, goes further. Its SP 800-63B guidelines classify delivering codes over the public telephone network (that is, SMS or voice calls) as a restricted authenticator. NIST tells services that rely on it to consider risk signals such as "device swap, SIM change, number porting" before sending a code, and to make sure alternative authenticator types are available to everyone.
Those risk signals hint at the underlying problem. A text message is tied to a phone number, not to your physical phone, and phone numbers can be moved. A code sent by text can also be read aloud or typed into a fake site by someone who has been talked into it.
Authenticator apps (TOTP): a solid step up
An authenticator app generates time-based one-time passwords, usually called TOTP. When you set it up, the service shows you a QR code; your app stores the secret inside it and from then on produces a new code every 30 seconds.
Because the secret lives in the app on your device rather than travelling over the phone network, number porting and SIM changes do not hand an attacker your codes. That makes TOTP a meaningful upgrade over SMS.
It is not perfect. NIST states plainly that "OTP authentication is not phishing-resistant." Any method where you read a code and type it in can, in principle, be typed into a fake page instead of the real one. If a scammer builds a lookalike login screen and relays what you enter in real time, a TOTP code can be captured just like a password.
A code you can type is a code you can be tricked into typing somewhere else.
Passkeys: built so a fake site cannot use them
Passkeys are the newest option and the one security agencies are most enthusiastic about. The FIDO Alliance, the industry body behind the standard, defines a passkey as "an authentication credential based on FIDO standards, that can be stored on your phone or computer, or in a hardware security key."
Instead of a shared secret like a password, a passkey uses public-key cryptography. Your device keeps a private key and the service stores only the matching public key. To sign in, you approve the request "with the same process they use to unlock their device (for example, biometrics, PIN, or pattern)," as FIDO puts it. Your fingerprint or face never leaves your device; it simply unlocks the key.
The anti-phishing property comes from how the web standard behind passkeys, WebAuthn, is designed. The W3C specification says a credential is "scoped" to a specific website, and "can only be accessed by origins belonging to that Relying Party," with that scoping enforced by both your browser and your authenticator. In plain terms: a passkey made for your bank's real address will not even be offered to a lookalike domain, so there is nothing for you to hand over by mistake.
This is why CISA says "the only widely available phishing-resistant authentication is FIDO/WebAuthn authentication," and that when an attacker tricks someone into visiting a fake website, "the FIDO protocol will block the attempt." NIST's guidelines now say that services at its middle assurance level, AAL2, must offer at least one phishing-resistant option.
Passkeys can also sync. FIDO explains that a passkey created on one device can be synced to your other devices that use the same passkey provider account, which makes them practical for everyday use. NIST calls these syncable authenticators and rules them out only at its highest assurance level, AAL3.
Backup codes: your plan for a lost phone
Strong sign-in methods raise a fair question: what happens if you lose the device? This is where backup codes come in. NIST describes these as look-up secrets and notes that "a typical application of look-up secrets is for one-time saved recovery codes."
A few habits make them work:
- Store them offline or in a password manager, not in an email to yourself or a photo in your camera roll.
- Treat each code as single-use. Once you use one, cross it off, and generate a fresh set when you are running low.
- Regenerate them if you think they have been seen by anyone else.
- Register more than one strong method where a service allows it, such as a passkey on your phone and another on your laptop.
Review where you are signed in
The strongest sign-in method only protects the front door. It is also worth checking who is already inside. Many financial apps and websites list your active sessions or trusted devices. Look for anything you do not recognize, such as an unfamiliar device, browser or location, and sign it out.
Check after replacing a phone, after using a shared computer, or after an unexpected security notice. If something looks wrong, change your password, remove unknown passkeys or devices, and contact your provider using the details on its official website or app rather than any link in a message.
Putting it together
If you take one thing away, let it be the order of preference. Use a passkey where one is offered. If not, use an authenticator app. Treat text-message codes as a fallback rather than a first choice. Keep your backup codes somewhere safe, and glance at your signed-in devices every so often.
None of this requires technical skill, just a few minutes in your account's security settings.