Security Keys vs Authenticator Apps: Which Second Factor Fits Your Practice? — Herarx Blog

Security Keys vs Authenticator Apps: Which Second Factor Fits Your Practice?

Both are vastly better than a password alone. They fail in different ways, and the right choice depends on how you and your team actually work.

July 30, 2026
Security Keys vs Authenticator Apps: Which Second Factor Fits Your Practice?
Back to blog

Two-factor authentication is not optional for professional accounts any more — we have written about the numbers before. The question that follows is which second factor. Herarx supports two, and they are not interchangeable.

Authenticator apps (TOTP)

A six-digit code that changes every thirty seconds, generated on your phone from a secret you scanned as a QR code. Google Authenticator, Authy, 1Password and Microsoft Authenticator all work. It is free, it works offline, and it is what most people already use elsewhere.

How it fails: a convincing fake login page can ask you for the code and use it within its thirty seconds. Phishing-resistant it is not. And a lost phone with no backup of the secret means recovery through your security questions or an admin.

Security keys (passkeys / FIDO2)

A hardware key — a YubiKey or similar — or the passkey built into your phone or laptop. You tap it, or use Face ID or Windows Hello, and the device signs a challenge that is cryptographically bound to the real Herarx domain. A fake page cannot ask for anything useful.

How it fails: the key is lost or breaks. Register two — one you carry, one in a drawer. A key-only account with no backup is one dropped bag away from a support ticket.

What we recommend

  • Solo practitioners: a security key as the primary factor, an authenticator app as fallback. Set both up in Settings → Security. A key-only account can add an authenticator app at any time.
  • Teams: the organisation can require a second factor for every member. Keys for anyone who handles secured cases or has admin rights; apps are acceptable elsewhere.
  • Everyone: save your recovery options and keep at least two factors registered.

Where the second factor is asked for again

Signing in is not the only gate. Deleting a case permanently, emptying Trash, changing the organisation's second-factor policy and turning off deletion protection each ask for the factor again, with a shared lockout counter across those actions so a guessed code cannot be retried indefinitely. A code that has been used once cannot be replayed within its window.

Sessions and devices

Whichever you choose, review Settings → Security → Sessions occasionally. Every signed-in device is listed; revoke anything you do not recognise. The native apps keep a longer idle window than the browser, so a phone that goes missing should be revoked there, not just wiped.