Abstract
This paper provides a comprehensive comparison of six multi-factor authentication (MFA) methods — SMS codes, authenticator apps, hardware tokens, biometric verification, FIDO2 passkeys, and certificate-based authentication — evaluated across security strength, user experience, cost, and implementation complexity.
1. Evaluation Framework
We assessed each method against four dimensions: resistance to phishing, user adoption rate, total cost of ownership (3-year), and integration complexity with existing identity systems.
2. Results
| Method | Phishing Resistance | User Adoption | 3-Year Cost | Integration |
|---|---|---|---|---|
| SMS Codes | Low | High | Low | Easy |
| Authenticator Apps | Medium | Medium | Low | Easy |
| Hardware Tokens | High | Medium | High | Medium |
| Biometric | High | High | Medium | Medium |
| FIDO2 Passkeys | Very High | Medium | Medium | Hard |
| Certificate-Based | Very High | Low | High | Hard |
3. Recommendations
For Hong Kong enterprises, we recommend a tiered approach: FIDO2 passkeys for high-risk systems, biometric authentication for general corporate access, and authenticator apps as a baseline minimum.