- 🥇Hardware key (YubiKey, Passkey) — phishing-proof
- 🥈TOTP app (Aegis, Authy, Google Auth)
- 🥉Email code — use only if no better option
- ✗SMS — vulnerable to SIM-swap attacks
PRIORITY ACCOUNTS FOR 2FA
- ✓Email (controls password resets for everything)
- ✓Banking and financial accounts
- ✓Password manager
- ✓Social media
- ✓Cloud storage (Google Drive, iCloud, Dropbox)