← all articles

Authenticator apps vs hardware keys

I keep a $50 YubiKey on my keychain and Google Authenticator installed on three different phones. Losing access to either one, even for an hour, would lock me out of Cloudflare, GitHub, our domain registrar, and half a dozen accounts that keep theprivacywire and my other sites running. That’s the kind of stake that makes you actually think about which second factor you’re using, instead of just tapping “enable 2FA” and moving on.

Both authenticator apps and hardware security keys exist to replace SMS codes, which are the weakest widely-used form of two-factor authentication because a SIM swap or an intercepted text hands your code straight to an attacker. The two options solve the same problem, stopping someone from logging in as you without your permission, but they work in completely different ways, and one of them is meaningfully harder to phish than the other. If you’ve already read what a passkey actually is, this is the older, more manual cousin of that same idea.

what it is

An authenticator app is software, usually free, that generates a six-digit code on your phone every 30 seconds. Google Authenticator, Microsoft Authenticator, and Authy are the three most people run into. The app and the website share a secret key at setup time, usually scanned as a QR code, and both sides run the same math, a standard called TOTP (time-based one-time password), to land on the same number at the same moment. Plenty of password managers, including several we’ve tested in the best password managers in 2026, have TOTP generation built in too, so you may already have an authenticator without installing anything new.

A hardware security key is a small physical device, usually USB-C or USB-A with NFC, that you plug in or tap against your phone. YubiKey, made by Yubico, and Google’s Titan Security Key are the two brands you’ll actually find listed in most account security settings. Instead of generating a number you type in, the key holds a private cryptographic key that never leaves the device and signs a challenge from the website directly. You don’t read anything off it or type anything in. You just touch it. Google’s own guide to turning on 2-Step Verification walks through setting up either method on the same account, which is a decent way to compare them side by side before committing to one.

how it works

The app-based flow is simple, and that’s both its strength and its weakness. You type your password, the site asks for a code, you open the app, read six digits, type them in, done. Nothing about that flow checks whether the site asking for the code is actually the real site. If someone puts up a convincing fake login page and you type your password and your TOTP code into it, the attacker now has both and can log in as you within the 30-second window. Real-time phishing kits that do exactly this exist and get used in large campaigns.

So the weak link was never the math. It’s whoever’s staring at the six digits, typing them into whatever page is in front of them.

Hardware keys use a protocol called FIDO2/WebAuthn, developed by the FIDO Alliance. When you register the key with a site, it generates a unique key pair for that specific domain. When you log in later, the browser sends a challenge that includes the domain name, and the key only signs it if the domain matches what it registered against. Put the same key in front of a phishing page with a slightly different URL and it does nothing. That domain-binding is the entire point.

Setup effort differs too. An authenticator app costs nothing beyond installing it, but every new phone means re-enrolling every account by hand unless you saved backup codes first, and I’ve had accounts I genuinely couldn’t get back into because I skipped that step on a work trip in 2022. A hardware key runs $25 to $70 depending on the model and works across any device with a USB port or NFC reader, no reinstalling anything, but if you only register one key and it ends up in the wash, you’re locked out until support steps in.

why it matters

My own rule: a hardware key goes on anything that touches money, DNS, or code, so Cloudflare, our registrar, GitHub, and PayPal. TOTP covers everything else. Some security people will tell you to hardware-key every account you own. I think that’s overkill for a newsletter login, and it just means more physical keys to keep track of.

  • SMS is the floor, not a real option anymore. Both apps and hardware keys sit above it, but if you’re still on text-message codes for anything that matters, that’s the thing to fix first, not the app-versus-key debate.
  • Phishing resistance is the real dividing line. An app can’t tell a real login page from a fake one. A hardware key physically can’t be tricked into signing for the wrong domain, which is why NIST SP 800-63B puts multi-factor cryptographic device authenticators at the highest assurance level (AAL3) and leaves OTP apps a tier below at AAL2. Cloudflare’s own security team wrote publicly about a 2022 phishing campaign where employees typed real passwords and OTP codes into a fake login page, and the attack still failed because their hardware keys refused to sign for the wrong domain.
  • Recovery is a real cost, not a footnote. Lose your phone with the authenticator app on it and you’re digging through backup codes or filing a support ticket, depending on the service. Lose a hardware key and it’s the same problem, except you can’t export or back up a private key the way you can save TOTP seeds. I learned this the annoying way, misplacing a YubiKey during a move in 2024 and spending an evening working through Cloudflare’s account recovery flow before I found it in a jacket pocket. Buy two keys, register both on every account, and keep the second one somewhere that isn’t your bag.
  • For infrastructure accounts specifically, the stakes are higher than most people assume. If you’re running anything with paying customers behind it, a compromised Cloudflare, registrar, or hosting account isn’t an inconvenience, it’s downtime and possibly a domain hijack. I write more about keeping that kind of infrastructure locked down over at cloudf.one/blog, where the audience is managing fleets of devices instead of one laptop, but the account-security math is identical.

common misconceptions

Authenticator apps are “hackable” and hardware keys are “unhackable.” Neither is true. Hardware keys can still be lost, and the account behind them can still be compromised through password reset flows, session hijacking, or a compromised recovery email. What hardware keys fix specifically is phishing of the second factor itself, nothing more.

A hardware key is only for paranoid security people. Big platforms disagree. Google, Microsoft, GitHub, Apple, and most password managers support FIDO2 keys directly in account settings, no special setup required beyond buying a key and registering it.

Authenticator apps are basically obsolete now that passkeys exist. Not yet. Plenty of smaller services still only support TOTP, and TOTP still beats SMS by a wide margin. The realistic setup for most people is TOTP everywhere it’s offered, a hardware key on the handful of accounts that would actually hurt to lose, and passkeys wherever a site supports them.

Syncing your authenticator app to the cloud is always safe. It’s convenient, and it solves the lost-my-phone-lost-my-codes problem, but you’re trusting whatever encryption, or lack of it, the app vendor uses for that sync. Read the specifics before you turn it on. Don’t assume cloud backup automatically means safe.

where to go from here

For everything else on the site, the blog index has the rest of our security explainers.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-10.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →