Comparing Multi-Factor Authentication Methods from SMS and TOTP to FIDO2/WebAuthn and Passkeys: A Qualitative Study of Practitioner Perspectives
DOI:
https://doi.org/10.66395/globeis.19Keywords:
FIDO2/WebAuthn, identity and access management, multi-factor authentication, passkeys, phishing resistance, usabilityAbstract
The escalation of cyber-attacks has intensified the need for stronger multi-factor authentication (MFA), motivating a shift from traditional knowledge- and possession-based factors, such as SMS one-time passwords (OTP) and time-based one-time passwords (TOTP), toward FIDO2/WebAuthn credentials and passkeys. This study qualitatively compares five widely deployed MFA methods, grouped as traditional (SMS-based OTP, TOTP, and push-based authentication) and advanced (FIDO2 security keys and platform biometric authenticators), across four criteria: usability, security, cost, and implementation challenges. Adopting an interpretive qualitative design, the study draws on semi-structured interviews with four identity-and-access-management (IAM) practitioners, analysed through Braun and Clarke's six-phase reflexive thematic analysis. Coding produced an initial framework of 30 codes that was consolidated into four themes corresponding to the study criteria. Practitioners consistently characterised traditional methods as more affordable and broadly familiar but weaker in security and more prone to operational reliability problems, whereas FIDO2 security keys and platform biometrics were described as offering stronger phishing resistance and smoother day-to-day operation at a higher initial and maintenance cost. The study situates these accounts within organisational governance and cross-regional regulatory drivers of adoption and recommends a risk-based migration toward FIDO2/WebAuthn and passkeys.
Downloads
References
1. Abbas, W., Joshua, S. R., Abbas, A., & Lee, J. H. (2025). An end-to-end GSM/SMS encrypted approach for smartphone employing advanced encryption standard (AES). arXiv. https://arxiv.org/abs/2503.18859
2. Abduhari, E. S., Shaik, T. C., Adidul, A. B., Ladja, J. H., Saliddin, E. S., Adin, A. J., Rumbahali, F. A., Sali, A. B., Jemser, J. M., & Tahil, S. K. (2025). Access control mechanisms and their role in preventing unauthorized data access: A comparative analysis of RBAC, MFA, and strong passwords. Natural Sciences Engineering and Technology Journal, 5(1), 418–430. https://doi.org/10.37275/nasetjournal.v5i1.62
3. Abiew, N. A. K., Jnr, M. D., & Banning, S. O. (2020). Design and implementation of cost effective multi-factor authentication framework for ATM systems. Asian Journal of Research in Computer Science, 5(3), 7–20.
4. Acemyan, C. Z., Kortum, P., Xiong, J., & Wallach, D. S. (2018). 2FA might be secure, but it's not usable: A summative usability assessment of Google's two-factor authentication methods. Proceedings of the Human Factors and Ergonomics Society Annual Meeting, 62(1), 1141–1145.
5. Almass, S., & Chowdhary, S. K. (2024). Comprehensive study on cyber security and cyber attacks. In Proceedings of the 1st International Conference on Electronics, Communication and Signal Processing (ICECSP) (pp. 1–6). IEEE.
6. Almeida, L. E., Fernández, B. A., Zambrano, D., Almachi, A. I., Pillajo, H. B., & Yoo, S. G. (2023). One-time passwords: A literary review of different protocols and their applications. In International Conference on Advanced Research in Technologies, Information, Innovation and Sustainability (pp. 205–219). Springer Nature.
7. Ang, K. W., Chekole, E. G., & Zhou, J. (2025). Unveiling the covert vulnerabilities in multi-factor authentication protocols: A systematic review and security analysis. ACM Computing Surveys.
8. Angelogianni, A., Politis, I., & Xenakis, C. (2024). How many FIDO protocols are needed? Analysing the technology, security and compliance. ACM Computing Surveys, 56(8), 1–51.
9. Aramide, O. O. (2023). AI-driven identity verification and authentication in networks: Enhancing accuracy, speed, and security through biometrics and behavioral analytics. Adhyayan: Journal of Management Sciences, 13(2), 60–69.
10. Arora, S., & Bhatia, M. P. S. (2022). Challenges and opportunities in biometric security: A survey. Information Security Journal: A Global Perspective, 31(1), 28–48.
11. Bartłomiejczyk, M., & El Fray, I. (2024). Device risk analysis protocol for SMS-based OTP authentication. IEEE Access.
12. Bianchi, G., & Valeriani, L. (2023). Time is on my side: Forward-replay attacks to TOTP authentication. In International Symposium on Security and Privacy in Social Networks and Big Data (pp. 109–126). Springer.
13. Bicakci, K., Varli, F. M., Korkmaz, M. E., & Uzunay, Y. (2026). QES-backed virtual FIDO2 authenticators: Architectural options for secure, synchronizable WebAuthn credentials. arXiv. https://arxiv.org/abs/2601.06554
14. Bindel, N., Cremers, C., & Zhao, M. (2023). FIDO2, CTAP 2.1, and WebAuthn 2: Provable security and post-quantum instantiation. In Proceedings of the IEEE Symposium on Security and Privacy (SP) (pp. 1471–1490). IEEE.
15. Burda, K. (2025). Electronic identification of persons and objects – current status. International Journal of Computer Science and Network Security, 25(6), 1.
16. Clarke, N., & Furnell, S. (2025). Usable authentication: Are we there yet? Computers & Security, 104823.
17. Duy, P. T., Minh, V. Q., Dang, B. T. H., Son, N. D. H., Quyen, N. H., & Pham, V. H. (2024). A study on adversarial sample resistance and defense mechanism for multimodal learning-based phishing website detection. IEEE Access.
18. Eko-Davies, O. (2025). Emerging trends in user authentication tools: Innovations, challenges, and future directions. In Proceedings of the IEEE International Conference on Electro Information Technology (eIT) (pp. 51–55). IEEE.
19. European Parliament & Council of the European Union. (2014). Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (eIDAS). Official Journal of the European Union, L 257, 73–114. http://data.europa.eu/eli/reg/2014/910/oj
20. European Parliament & Council of the European Union. (2015). Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2). Official Journal of the European Union, L 337, 35–127. http://data.europa.eu/eli/dir/2015/2366/oj
21. Ferdous, M. S., Ali, M. Y., Chowdhury, F. R., Nahid, M. A., Ionita, A., & Prinz, W. (2026). A passwordless authentication mechanism for the web using self-sovereign identity. ACM Transactions on the Web.
22. Ganmati, A., Afdel, K., & Koutti, L. (2025). Deep learning-based multi-factor authentication: A survey of biometric and smart card integration approaches. arXiv. https://arxiv.org/abs/2510.05163
23. George, A. S. (2024). The dawn of passkeys: Evaluating a passwordless future. Partners Universal Innovative Research Publication, 2(1), 202–220.
24. Grassi, P. A., Fenton, J. L., Newton, E. M., Perlner, R. A., Regenscheid, A. R., Burr, W. E., Richer, J. P., Lefkovitz, N. B., Danker, J. M., Choong, Y.-Y., Greene, K. K., & Theofanos, M. F. (2017). Digital identity guidelines: Authentication and lifecycle management (NIST Special Publication 800-63B). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63b
25. Gupta, S. (2025). Hacking the system: A deep dive into the world of e-banking crime. In Techno-Legal Dynamics of Cyber Crimes in Industry 5.0 (pp. 121–148).
26. Huseynov, E. (2020). Improving user experience with TOTP hardware tokens by implementing QR codes and HID keyboard emulation. In Proceedings of the IEEE International Conference on Application of Information and Communication Technologies (AICT) (pp. 1–5). IEEE.
27. Idrus, Z. S. S., Cherrier, E., Rosenberger, C., & Schwartzmann, J. J. (2013). A review on authentication methods. Australian Journal of Basic and Applied Sciences, 7(5), 95–107.
28. Ikram, M., Sentana, I. W. B., Asghar, H., Kaafar, M. A., & Kepkowski, M. (2024). More than just a random number generator! Unveiling the security and privacy risks of mobile OTP authenticator apps. In International Conference on Web Information Systems Engineering (pp. 177–192). Springer.
29. Jubur, M., Shrestha, P., & Saxena, N. (2025). An in-depth analysis of password managers and two-factor authentication tools. ACM Computing Surveys, 57(5), 1–32.
30. Kalash, Ghosh, B. C., & Addya, S. K. (2025). Enhancing security in smart contract wallets: An OTP-based two-factor authentication approach. In Proceedings of the International Conference on Distributed Computing and Networking (pp. 211–220).
31. Kamaruddin, N. H. C., & Zolkipli, M. F. (2024). The role of multi-factor authentication in mitigating cyber threats. Borneo International Journal, 7(4), 35–42.
32. Karim, N. A., Khashan, O. A., Kanaker, H., Abdulraheem, W. K., Alshinwan, M., & Al-Banna, A. K. (2023). Online banking user authentication methods: A systematic literature review. IEEE Access, 12, 741–757.
33. Kasse, M. C., & Mboup, E. H. M. (2025). Post-quantum secure authentication protocol based on OTP and TEE. The Journal of Supercomputing, 81(16), 1–33.
34. Kaur, K., & Jain, A. K. (2025). A survey on phishing attack taxonomy, detection techniques, datasets, and security measures. Journal of Applied Security Research, 1–52.
35. Kavitha, L., Ashwitha, K., Dharshana, P. K., & Elakkiyaa, M. (2025). Wireless locking system through OTP. In Proceedings of the International Conference on Multi-Agent Systems for Collaborative Intelligence (ICMSCI) (pp. 1795–1799). IEEE.
36. Kim, H., Han, J., Park, C., & Yi, O. (2020). Analysis of vulnerabilities that can occur when generating one-time passwords. Applied Sciences, 10(8), 2961.
37. Lassak, L., Pan, E., Ur, B., & Golla, M. (2024). Why aren't we using passkeys? Obstacles companies face deploying FIDO2 passwordless authentication. In 33rd USENIX Security Symposium (pp. 7231–7248).
38. Lyastani, S. G., Schilling, M., Neumayr, M., Backes, M., & Bugiel, S. (2020). Is FIDO2 the kingslayer of user authentication? A comparative usability study. In Proceedings of the IEEE Symposium on Security and Privacy (SP) (pp. 268–285). IEEE.
39. Maryniuk, M. D., Dalbo, A., Stanitski, J., & Khan, Y. (2025). Using text messaging to reach, reinforce, remind, and support. ADCES in Practice, 13(1), 16–19.
40. Matzen, A., Rüffer, A., Byllemos, M., Heine, O., Papaioannou, M., Choudhary, G., & Dragoni, N. (2025). Challenges and potential improvements for passkey adoption – a literature review with a user-centric perspective. Applied Sciences, 15(8), 4414. https://doi.org/10.3390/app15084414
41. Mitra, A., & Sethuraman, S. C. (2025). Verifiable passkey: The decentralized authentication standard. arXiv. https://arxiv.org/abs/2512.21663
42. Mondal, P. C., & Sarkar, P. P. (2025). A novel risk-based multi-factor authentication approach for card-not-present transactions. International Journal of Research and Innovation in Social Science, 9(3), 3062–3076.
43. Muir, A., Brown, K., & Girma, A. (2024). Reviewing the effectiveness of multi-factor authentication methods in preventing phishing attacks. In Proceedings of the Future Technologies Conference (pp. 597–607). Springer.
44. Nallainathan, S. (2021). Analysis onto the evolving cyber-attack trends during COVID-19 pandemic. International Journal of Science and Research, 10(4), 139–144.
45. Obulose, C., & Agu, P. C. (2024). The future of passwordless authentication: Trends, predictions, and emerging technologies.
46. Ometov, A., Bezzateev, S., Mäkitalo, N., Andreev, S., Mikkonen, T., & Koucheryavy, Y. (2018). Multi-factor authentication: A survey. Cryptography, 2(1), 1.
47. Ometov, A., Petrov, V., Bezzateev, S., Andreev, S., Koucheryavy, Y., & Gerla, M. (2019). Challenges of multi-factor authentication for securing advanced IoT applications. IEEE Network, 33(2), 82–88.
48. Omotunde, H., & Ahmed, M. (2023). A comprehensive review of security measures in database systems. Mesopotamian Journal of Cybersecurity, 115–133.
49. Papaspirou, V., Papathanasaki, M., Maglaras, L., Kantzavelou, I., Douligeris, C., Ferrag, M. A., & Janicke, H. (2023). A novel authentication method that combines honeytokens and Google Authenticator. Information, 14(7), 386. https://doi.org/10.3390/info14070386
50. PCI Security Standards Council. (2022). Payment Card Industry Data Security Standard: Requirements and testing procedures (Version 4.0). https://www.pcisecuritystandards.org
51. Peeters, C., Patton, C., Munyaka, I. N., Olszewski, D., Shrimpton, T., & Traynor, P. (2022). SMS OTP security: Hardening SMS-based two-factor authentication. In Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS) (pp. 2–16).
52. Pietrzak, K. (2020). Delayed authentication: Preventing replay and relay attacks in private contact tracing. In International Conference on Cryptology in India (pp. 3–15). Springer.
53. Prabha, R. S., Dharaneesh, C. K. V., & Reshekkaesh, K. A. (2025). Bio secure authentication framework. In Proceedings of the International Conference on Electronics, Computing, Communication and Control Technology (ICECCC) (pp. 1–6). IEEE.
54. Qian, Y. (2024). Applying combined one-time passwords to prevent phishing attacks in electronic banking. Journal of Artificial Intelligence and Systems Modelling, 2(4), 32–46.
55. Ravilla, H., Sayal, R., & Kulkarni, P. (2023). Study and analysis of FIDO2 passwordless web authentication. In International Conference on Advances in Computational Intelligence and Informatics (pp. 375–386). Springer.
56. Reese, K., Smith, T., Dutson, J., Armknecht, J., Cameron, J., & Seamons, K. (2019). A usability study of five two-factor authentication methods. In Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS) (pp. 357–370).
57. Senapartha, I. K. D., & Nendya, M. B. (2024). Usability evaluation of mobile multi-factor authentication based on face authentication, geolocation and QR code. JITK (Jurnal Ilmu Pengetahuan dan Teknologi Komputer), 10(2), 425–432.
58. Shukla, S., Varshney, G., Singh, S., & Goel, S. (2025). A passwordless MFA utilizing biometrics, proximity, and contactless communication. Information Security Journal: A Global Perspective, 34(6), 633–654.
59. Sriman, J., Thapar, P., Alyas, A. A., & Singh, U. (2024). Unlocking security: A comprehensive exploration of biometric authentication techniques. In Proceedings of the IEEE Confluence (pp. 136–141).
60. Suleski, T., Ahmed, M., Yang, W., & Wang, E. (2023). A review of multi-factor authentication in the Internet of Healthcare Things. Digital Health, 9, 20552076231177144.
61. Vorakulpipat, C., Pichetjamroen, S., & Rattanalerdnusorn, E. (2021). Usable comprehensive-factor authentication for a secure time attendance system. PeerJ Computer Science, 7, e678.
62. Yusop, M. I. M., Kamarudin, N. H., Suhaimi, N. H. S., & Hasan, M. K. (2025). Advancing passwordless authentication: A systematic review. IEEE Access.
63. Zhao, J., He, F., Yang, Y., & Zhang, Y. (2025). Identifying implementation flaws of SMS OTP authentication. IEEE Transactions on Mobile Computing.
64. Zou, F., Zhang, Z., & Hu, Y. (2025). OTP-Hunter: An app-based fuzzing framework to discover one-time password vulnerabilities. IEEE Transactions on Dependable and Secure Computing.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 GlobeIS International Journal of Global Information Systems

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.