Default
Door staff@engadget.com (Gabriela Vătu) - 23 Sep 2026
Standalone apps like Google Authenticator take a more isolated approach because they work offline. There's physical separation, so your second factor actually lives on a different device than your passwords, and there's a lower chance of having your data stolen.
On the other hand, that isolation comes at a cost, because you'll still be copying six-digit codes by hand. Also, most authentication apps are mobile-only, so you're out of luck if your phone isn't nearby. Unless, that is, you have one of the models that also offer desktop apps or browser extensions, like 2FA or 1Password. There's also the risk of temporary lockout of your accounts if you lose or break your phone, requiring you to set up a replacement device and restore your cloud backups before accessing your codes again.
The hybrid model brings the best of both worlds
One of the best ways to make your life easier while still keeping everything safe is to mix and match. Most timed one-time password codes can lie safely in a password manager, but a small handful, such as the codes for your main email account and the password manager itself, are better kept on a separate hardware key or an authenticator app. This way, if your vault is ever compromised, your most critical accounts remain out of reach.
The breakdown is to use your password manager's built-in 2FA for low-risk everyday services, like shopping sites and subscriptions. Use a dedicated authenticator app or hardware key for your email, banking and the password manager itself. In this way, the friction is minimal, and your most essential accounts are safe if your password manager is ever compromised.
Ultimately, neither tool is flawless on its own, and the best choice depends on what you're protecting and how much back-and-forth between devices you tolerate. For most people, a hybrid approach seems to be the best path forward.
On the other hand, that isolation comes at a cost, because you'll still be copying six-digit codes by hand. Also, most authentication apps are mobile-only, so you're out of luck if your phone isn't nearby. Unless, that is, you have one of the models that also offer desktop apps or browser extensions, like 2FA or 1Password. There's also the risk of temporary lockout of your accounts if you lose or break your phone, requiring you to set up a replacement device and restore your cloud backups before accessing your codes again.
The hybrid model brings the best of both worlds
One of the best ways to make your life easier while still keeping everything safe is to mix and match. Most timed one-time password codes can lie safely in a password manager, but a small handful, such as the codes for your main email account and the password manager itself, are better kept on a separate hardware key or an authenticator app. This way, if your vault is ever compromised, your most critical accounts remain out of reach.
The breakdown is to use your password manager's built-in 2FA for low-risk everyday services, like shopping sites and subscriptions. Use a dedicated authenticator app or hardware key for your email, banking and the password manager itself. In this way, the friction is minimal, and your most essential accounts are safe if your password manager is ever compromised.
Ultimately, neither tool is flawless on its own, and the best choice depends on what you're protecting and how much back-and-forth between devices you tolerate. For most people, a hybrid approach seems to be the best path forward.

