Skip to content

FAQ 2FA Types

Michael Loßin edited this page Sep 5, 2021 · 7 revisions

How to choose the correct type of 2FA

Here are all the 2FA types with a small description of every one of them.
Please keep in mind that many methods of 2FA can fit into multiple types.

u2f

This includes U2F keys, often something like a security token such as a Yubikey.

custom-hardware

Hardware based authentication would include the following:

totp

This means time-based one-time passwords (according to RFC-6238), often indicated by support for Google Authenticator.

custom-software

Software based authentication other than totp would include the following:

  • Authenticator apps like Authy or Zoho OneAuth that use their own protocol.
  • Smartphone apps that offer verification by confirming a popup prompt.

email

Electronic mail based authentication.

sms

SMS Text Message based authentication.

call

Phone call based authentication, e.g. by reading a one-time password or by responding via the phone keypad.