Support in selection

Compare sign-in methods

Check the differences between codes, confirmations and access keys. Choose two methods you consider in your account.

Compare login methods

Choose two methods to compare

You compare: Application Codes (TOTP) and Passkey synchronized.

Application codes (TOTP)

The application generates a short-lived code that you enter after entering the password.

Resistance to phishing
No, a fake page can extort and pass on the current code.
What is needed
Authentication application. The self-generation of codes usually does not require the Internet.
Before losing the device
Prepare the backup codes and check how the application is transferred or copied.
What to watch out for
Only enter the code when logging in, which you start on your own. Do not share the configuration secret or QR code.
How to turn on 2FA →

Passkey synced

A key saved from a supplier that synchronizes it between your devices.

Resistance to phishing
Yes, for FIDO2/WebAuthn login. The key is related to the right service, instead of the code being copied to the page.
What is needed
Supported service, device and provider of passkeys. You confirm the use of e.g. screen lock.
Before losing the device
Check synchronization, access from the second device and recover the supplier's account.
What to watch out for
Secure your devices and sync account. Passkey does not protect you from any threat or affected session.
How to start with passkeys →
How do you understand resistance to phishing?

The comparison concerns logging on a fake page that tries to take over the code or confirmation. FIDO2/WebAuthn binds authentication to the right service. It does not replace device protection, session and account recovery.

This is educational material without testing your account. The choice of methods is not saved or sent.