Skip to content
Cuswpc Tech

70 lettersUpdated

New message
Folders

What Is Two-Factor Authentication?

Filed by
Tech
Received
Length
4 min
Mockup, screen and smartphone

Passwords get reused, guessed, phished and leaked. Two-factor authentication, often written as 2FA, exists because a password on its own is a single point of failure. With 2FA turned on, signing in requires a second proof that you are who you claim to be, so a stolen password is no longer enough to get into the account.

The three kinds of factor

Security people usually describe proof of identity in three groups:

  • Something you know – a password, PIN or passphrase.
  • Something you have – a phone, a hardware security key or a bank card reader.
  • Something you are – a fingerprint or face scan, usually checked on your own device.

Two-factor authentication combines two different groups. A password plus a security question is not true 2FA, because both are things you know. A password plus a code from your phone is, because the phone is something you physically hold.

How a typical sign-in works

  1. You enter your username and password as normal.
  2. The service asks for a second factor.
  3. You provide it: a code, a tap on a prompt or a touch on a security key.
  4. Only when both checks pass does the service let you in.

Many services offer to "remember" a trusted device, so you are not asked every time on your own laptop, but new devices and unusual sign-ins still trigger the second step.

Common methods compared

MethodHow you use itStrengthsWeak points
Text message codeA short code is sent to your phone number.Easy, works on almost any phone.Codes can be intercepted or redirected if someone takes over your number.
Authenticator appAn app on your phone generates a new code every short interval.Works offline; not tied to your phone number.Codes can still be typed into a convincing fake page.
Push promptYou approve or deny a sign-in notification.Very quick.Repeated prompts can trick tired users into tapping approve.
Hardware security keyA small device you plug in or tap against your phone.Designed to resist phishing; checks the real website.Must be bought and carried; keep a spare.
PasskeyA credential stored on your device, unlocked with fingerprint, face or PIN.Phishing-resistant and simple once set up.Support varies between services and devices.

Any of these is a clear improvement on a password alone. If a service offers several, an authenticator app, a security key or a passkey is generally preferred over text messages.

Which accounts to protect first

Start with the accounts that can unlock others:

  1. Email – password resets for almost everything else go there.
  2. Password manager – it holds the keys to the rest.
  3. Banking and payment apps – the direct route to your money.
  4. Work and cloud storage accounts – documents, client data and backups.
  5. Social media – a hijacked profile can be used to scam your contacts.

Payment services are a good example of how security and convenience now go together; our look at fast and secure payment platforms shows how layered checks have become part of everyday transactions.

Setting it up without locking yourself out

  • Find the option under a heading such as "Security", "Sign-in" or "Two-step verification" in the account settings.
  • When the service shows backup codes, save them somewhere safe and offline, such as a printed sheet stored at home or a secure note in your password manager.
  • Add a second method where possible, for example an authenticator app plus a spare security key.
  • Before replacing your phone, move your authenticator accounts to the new device and test them while the old one still works.
  • Keep your account recovery email and phone number up to date.

What 2FA does not do

Two-factor authentication raises the bar considerably, but it is not magic. It does not stop malware already running on your device, and some phishing kits try to capture codes in real time. Be suspicious of any message urging you to read out or type a code you did not request; legitimate support teams do not ask for them. If you get an approval prompt you did not trigger, deny it and change your password.

For small businesses

If you run a team, require 2FA on shared tools such as email, accounting software and file storage. Write a short procedure for what staff should do if they lose a phone, and keep admin recovery details in a secure place that more than one trusted person can reach. The same principle applies at home: a secure network underneath your devices matters too, which is covered in our guide on how to improve your Wi-Fi signal, including keeping router settings protected.

The takeaway

Two-factor authentication pairs your password with a second, different kind of proof. Turn it on for email and money first, save your backup codes and prefer app-based codes, security keys or passkeys where they are available. It takes a few minutes per account and closes one of the most common doors attackers use.

In the same threadTech