TOTP apps generate codes offline and resist SIM-swapping, while SMS rides fragile telecom rails and leaks metadata. If SMS is your only option, restrict it to low-value accounts. Prefer device-based authenticators, and always store printed backup codes somewhere physically safe, separate from everyday devices and wallets.
Hardware security keys provide origin binding, rendering most phishing pages useless. Passkeys extend that magic across devices with synced credentials tied to your biometrics. Start with two keys per person, register both everywhere, and practice recovery once. Label, store, and test periodically to avoid unpleasant surprises.
Backup codes are lifelines during travel, phone loss, or hardware failure. Print, seal, and place them with passports or a fireproof safe. Test at least once. Document recovery emails and numbers, prune risky ones, and keep everything updated after moves, promotions, or changes to your primary device.