Two-factor authentication, explained properly
Two-factor authentication — 2FA, MFA, two-step verification — all mean the same thing: proving who you are with something more than a password.
It is the single most effective thing you can do for your online safety, and on the accounts that matter it takes about two minutes to switch on.
Why it works
A stolen password becomes useless on its own. The attacker has half of what they need, and the other half is sitting in your pocket. That's why almost every serious attack now tries to get around 2FA rather than through it.
The types, best first
They are not all equal, though any of them beats nothing.
- Security key or passkey — a physical key or your phone's fingerprint/face unlock. Phishing-proof, because it will only work on the real website
- Authenticator app — a six-digit code that changes every 30 seconds. Free, and works without signal
- Push approval — a "was this you?" prompt. Convenient, but never approve one you didn't trigger
- Text message code — the weakest, because numbers can be hijacked, but still far better than a password alone
Where to turn it on first
Start with the accounts that unlock everything else, then work outwards.
- Email — first, always; it's how every other account is reset
- Online banking and payment accounts
- Your Microsoft or Apple account
- Anywhere a card is stored: Amazon, PayPal, the supermarket
- Social media, so nobody can impersonate you to your friends
- For a business: remote access, accounting software and the payroll system
Set up recovery before you need it
This is the step people skip, and it's the one that causes the lockouts.
- Save the backup or recovery codes each service gives you — print them or store them in your password manager
- Add a second method, such as a partner's phone number or a second authenticator
- If you use an authenticator app, pick one that backs up to your account, so a new phone restores everything
- Don't store the codes only on the same phone that holds the app
Never approve a prompt you didn't ask for
If a code arrives or your phone asks you to approve a sign-in and you weren't signing in, somebody has your password. Don't approve it, and don't read the code to anyone who rings about it — that phone call is part of the attack.
Change that password straight away, then check the account's list of signed-in devices and remove anything you don't recognise.