Best Practices for 2fa Setup and Security
Best practices for 2FA

The best practices for two-factor authentication involve prioritizing hardware security keys, using authenticator apps, and securing your recovery codes offline. Users consider hardware keys like YubiKeys the most robust solution because they provide a physical layer of security that remote attackers cannot easily bypass.
For convenience without sacrificing too much security, authenticator apps like Authy, Aegis, Google Authenticator, and Ente Auth offer a good balance. You should back up your authenticator app seeds to encrypted vaults in multiple offline locations so you can recover access if your phone is lost.
Avoid SMS-based 2FA whenever possible, as it is vulnerable to SIM swapping attacks. Always maintain an offline emergency sheet containing your recovery codes and backup keys, storing them in a fireproof safe and keeping a second copy in a separate location.
key steps
- prioritize hardware keys use yubikeys for a robust physical layer of security.
- buy multiple keys keep one in a secure offsite location like a fire safe to prevent lockout.
- use authenticator apps apps like authy, aegis, google authenticator, and ente auth offer good security.
- backup app seeds store seeds in encrypted vaults in multiple offline locations for recovery.
- avoid sms 2fa sms is vulnerable to sim swapping and cannot be secured.
- create an emergency sheet include recovery codes and backup keys on an offline sheet.
- store codes securely keep the emergency sheet in a fireproof safe with a second copy elsewhere.

Prioritize Hardware Security Keys
Utilize Authenticator Apps
Secure Recovery Codes
Are you looking for specific recommendations for 2FA apps or hardware?
Bottom line
To implement strong two-factor authentication (2FA) practices, Users recommend prioritizing hardware security keys like YubiKeys, followed by authenticator apps, and securing recovery codes.
Community answers 26
What others in the community said:
Hi, I am just becoming a digital nomad and wondering how to deal with 2FA? They are critical for my job (paid advertising manager) and I don’t really wanna keep my home country number - it’s expensive and useless outside of EU. I don’t want to use eSIM because it’s also expensive and pretty much useless too - I just buy local SIM with unlimited data right in the airport. How do you guys manage 2FAs? Maybe you can recommend some reliable solution?
UPDATE: wow. A lot of activity, many cool options I never heard about. But I just found out Zadarma. Ukranian project which costs almost nothing and has everything a man need. I even could call IRS to get my EIN number from Germany, which costed me 0€.
I've been locking down all my accounts lately, and have been getting more cautious about security. I decided to use Bitwarden as my password vault after research. However, i still can't find a proper place to store my backup codes. I don't understand much about encryption as a newbie, so, I have a few questions (Android user);
1: As the title says, what is the best foolproof app/method to store backup and recovery codes for accounts? I would much much prefer a service that's online. My phone isnt top of the line, and I'm definitely not too careful with it. If it gets wrecked/stolen, I need to still be able to access my backup codes, starting from nothing.
2: Similarly, I'm looking for a secure, trusted authenticator app. I've been using Google Authenticator for the longest time, but recently I've read about alot of people advising against it for many reasons, so, I would like to transfer the codes to a safer app. I heard alot of good things about Aegis, however, I know that it's an offline service. So I'm very worried about the same issue I mentioned beforehand - about losing access to my phone - therefore losing my accounts. What are the most secure online-based 2FA apps?
3: How can I backup my Bitwarden passwords in the same case of losing access to my phone? And how can I secure them?
4: An open-ended dumb question and I'm not sure what answer I'm expecting, but, what should I do to foolproof myself in case I lose access to my primary Gmail account which has all of my services. Any tips?
Also, any general account security tips for a newbie are greatly appreciated.
Make an emergency sheet or a full backup.
Do NOT try to rely on your memory alone.
Enabling multiple forms of 2FA arguably weakens your 2FA.
Having an emergency sheet is NOT AN OPTION. Your only choice is how to protect it.
The best thing is: All your passwords: bitwarden Authenticator: Ente Auth
I recommend that you store your 2FA recovery codes in Ente and not Bitwarden, following the principle of "don't put all your eggs in one basket".
Hey all, as a follow up to our last community poll about replacing TOTP with passkeys, what's your best 2FA strategy to avoid a lockout? Share your best tips and tricks and we'll share a few in the next Vault Hours session.
Resources:- Why Use Two-Step Login?
Hi,
I just lost my 2FA list (LastPass), silly me flashed my phone, though I backed up with Smart Switch, I didn't backup specific app data :(. When I setup Android 10, Play Store said 'LastPass' wasn't compatible with my version, so now I'm looking for a new way to do 2FA.
I use to save passwords in Google password manager, but now I don't think it's a good idea, I started writing them down if I can't remember them. So many, they add up over the years :/.
I'm wondering, what are your methods for securing 2FA and passwords?
I thought about getting an old second phone specifically for 2FA code generation, unless there's dedicated devices you recommend?
This is not about 2FA for bitwarden but 2FA methods in general. I realize many people recommend a TOTP app or some type of hardware key over email and sms. I typically try to use TOTP app when available. But let's say on an account that uses TOTP or hardware key, if someone figures out the password and tries to login, will you get a notification in your email tied to that account that someone is trying to login? Do all accounts have some form of new device login protection? With SMS or email as a 2FA method, if someone knows your password and tries to login, you will get a text or email when that happens
TOTP seeds are 32 characters long. Could you remember 32 characters?
Threat Model: Government-based
I may lose all of my devices (including Yubikey, phone) due to seizure. I may even not be able to return to my house.
Background:
For 2FA, there are two authentication factors: something you know and something you have. Due to seizure, detention, etc., what I have may only be my memory. I cannot pass the "something you have" check. I may even be forced to leave this region or face detention.
Problem:
So how should I protect my accounts? My current idea is enabling TOTP 2FA for all accounts and backing up encrypted seeds in Bitwarden. However, Bitwarden will disable new device verification and 2FA. So when I lose everything, I can still log into Bitwarden and recover my TOTP through an encrypted passphrase. But I think Bitwarden would be dangerous if I disable 2FA.
I know some people may suggest using Shamir's secret sharing. First, I don't have someone I can ultimately trust. Second, physically meeting someone wouldn't be safe for either me or my friend. And I need to regain access to all my online accounts to contact them.
I have read the rules
KeePass (or KeePassXC) works pretty well. It uses encrypted kdbx files to store the passwords, so you can just sync that between your devices and copy it to a hard drive occasionally to have backups.
It can also store TOTP and other files.
Currently using 1Password as it supports my less-technically able family members. It seems competent and claims to have no knowledge of my secret keys.
Hello there, I am currently in the proccess of upping my general online secruity, most of which is done by now, I updated all my passwords to be better, activated 2FA wherever I could. I had reset my PC and then made a windows boot usb, nothing actually happened to me so far but I like to be prepared and secured, addmittedly a bit paranoid of something being in my system even though nothing has happened and several AVs came back negative.
Whilst 2FA is probably generally more secure, for which I now use an authenticator app for all of it, are there actually methods I shouldn't use? Such as phone number I heard can be more of an issue if you are victim of a sim swap, same with email.
I had also heard instances of people getting their accounts compromised due to infostealers that circumvent 2FA however some seemingly had it happened without any strange software being run, which thats pretty spooky.
There is also two other things I am curious about, how does 2FA protect against a compromise exactly, couldn't it be turned off by the hacker/stealer? Also, how is it I am still logged into/active in a prior desktops session despite resetting the PC? I have seen that on some of my accounts, I recognize the desktop name and know it was me who signed in but because of a fresh install my desktop rn has a different name, could those instances still be dangerous despite them being functionally not active?
Get a physical safe.
Get USB drives, backup the vault to them and put them in the safe.
Also, get 2 Yubikey's, use these as your 2FA, and keep 1 in the safe at all times, rotate these keys every 6 months to be sure both are always still working and don't have issues due to never seeing power for too long.
This is probably a dumb question but does US Mobile offer 3rd party authentication that isn't paired with SMS. I'm looking for a company that gives me the option of turning off SMS authentication entirely.
There is only so much you can do on a technical level. Hardware can fail and get lost, emergency sheets can burn up or get soaked in your apartment, you might skip your backup routine just that one time, you might get incapacitated or stranded without your electronic devices, etc. InfoSec is about more than just technical controls. It does not have to be you against the world.
So in addition to secondary Yubikeys, semi-regular encrypted exports and an emergency sheet: Have someone you trust, make sure they are on the same page as you with regard to their account security, and set them up with emergency access to your account.
I think this is also one of the most beginner-friendly approaches. If someone is starting to use a password manager (great!) and looks for ways to avoid lockout (even better!), approaches involving two other tools, several hardware items or a bank vault can seem daunting.
1) Something you know
2) Something you are
It’s not ideal but it sounds like your second factor needs to be biometric.
I'm so confused with so many opinions of people. People say so many things -
- SMS is weak. NEVER use it. Some say "oh, it's a myth, because Banks use it too"
- Email as an authentication is a bad idea because that can be hacked too.
- An authenticator app is good, but not recommended because you might get locked out.
- Yubikey is the gold standard (which I know and agree with, but not an option for me atm).
I have like 5 accounts. 2 of these accounts contain sensitive information. How many I even supposed to go about securing all these 5 accounts without leaving a backdoor for a hacker or someone else to get in, while at the same time without locking my own self out?
PS- I'm starting a business soon, and so, a little tighter security for my accounts has been recommended atm. YubiKey's too but those will be provided later.
You very much answered your own post, I had a workmate who would get his 2FA through email, someone set up a forwarding rule in his webmail, every time he tried to log in (to change his password), they would change it before him, it seemed more that they were playing with him but it was a devil to break the cycle and get control of his accounts, he uses Yubikey now, just register additional keys, if one is lost you can use another for recovery, he did that and keeps one key locked away.
SMS is weak. NEVER use it. Some say "oh, it's a myth, because Banks use it too"
SMS is weak. That's an objective fact. It can't be secured, it can never be secured. It's built into the design of the protocol -- it was never designed to be used the way we use it. I wouldn't say "NEVER use it" because it's better than having no second factor. If it's SMS or nothing, use SMS. Those who say "oh, it's a myth" are simply incorrect. Some banks use it because their systems are ancient, or their customers simply will not engage with anything more secure. For them, it's better than nothing. Besides, SMS security isn't the bank's job.
Email as an authentication is a bad idea because that can be hacked too.
Email is better than SMS, but worse than other options. Email can be compromised, but there are measures you can take to reduce the chances. For example, Google's advanced protection program certainly helps. Granted, that requires at least two hardware keys on your account (or at least, it used to -- not sure what's required now), so you're stuck if you can't use them.
An authenticator app is good, but not recommended because you might get locked out.
Not sure who wouldn't recommend it. Maintain backup codes in a secure location to keep yourself from being locked out of your accounts. You do need to trust the security of your phone. That means no side-loading sketchy apps, not installing every random app you see on the Google Play Store, etc.
Yubikey is the gold standard (which I know and agree with, but not an option for me atm)
Yes. Any other option is a downgrade.
How many I even supposed to go about securing all these 5 accounts without leaving a backdoor for a hacker or someone else to get in, while at the same time without locking my own self out?
Security is not a goal. There is no such thing as "secure". Security extends the time required for bad actors to gain access to your information. If you can extend that "time to access" period far enough out it becomes inefficient for a malicious actor to continue attempting access. Extend it even further, and the data revealed becomes irrelevant (e.g., you're dead).
If you're running from a hungry bear, you don't need to outrun the bear. You just need to outrun the next slowest person. Don't be the slowest member of the flock, and you reduce your chances of being eaten.
I've noticed that most end-user facing login systems (private Microsoft, Google, Amazon, etc. accounts) typically ask for 2FA on new devices or after some time has passed. This time however is typically on the order of weeks.
By contrast, e.g.
- Our time recording system requires a Google Authenticator code on every login.
- Our Microsoft Team's accounts require reauthenticating with Microsoft Authenticator once a day.
It is confounded by these systems spread over multiple organizations due to the project structure, each implementing a not-so-single signon system.
Is that actually good practice for an industrial environment, or is it genuinely just excessive? Or am I just unlucky, because my project isn't limited to a single organization?
SMS-based 2FA is a dumpster fire. Yes, banks use it, but that’s like saying jaywalking is safe because a few people do it daily. It’s vulnerable to SIM swapping and interception. don’t do it unless you enjoy Russian roulette with your accounts.
Email 2FA is equally laughable. If your email is compromised, your "second factor" might as well be a welcome mat. It’s the classic circular logic failure.
Authenticator apps (Google Authenticator, Authy) are your friend here. Unless you’re allergic to common sense. Sure, the risk of getting locked out exists, but that’s mitigated by keeping your backup codes somewhere secure (not taped under your keyboard).
YubiKeys and hardware tokens are the only truly robust solution. but since you can’t deploy them just yet, focus on layered defenses.
My advice: Use an authenticator app for all critical accounts, print or securely store backup codes offline, and for less sensitive accounts, a good password manager combined with strong, unique passwords.
If you want "unbreakable" you’ll have to accept a pinch of inconvenience. Security without sacrifice is a fantasy perpetuated by the uninformed.
What’s the time limitation? Can you not have a friend mail an authenticated phone to a mail forwarder and pick it up in the next country?
- increased number of transfers of data through potentially insecure networks
- increased points of attack because every account can now also be compromised by compromising an email account
- 3-5 digit codes are brute forceable if what an attacker cares about is access rather than the account of a specific user ie the typical case
It seems to me that the benefits of 2fa rely on perfect use - no shared passwords, passwords that are essentially uncrackable, accounts that are fully secure. In a typical use case, how much security does it add when the realities of its use are taken into account?
I ask because my user data shows that a certain percentage of legitimate, uncompromised accounts will be "put off" engaging casually with content if the login process has extra steps, and because the volume of user feedback and bug reports I'm receiving decreased when I implemented 2fa.
However, I understand nothing about cybersecurity - I don't even know if those things at the top are really true. So how much security am I gaining, against attacks that are how common, so I can better judge whether it's worth the loss of engagement etc?
Replies (0)
No replies yet. Be the first to reply.