What two-factor authentication is
Two-factor authentication, often shortened to 2FA and also called two-step verification, adds a second check on top of your password: a code sent by text, a code from an authenticator app, a prompt on your phone or your fingerprint or face. Even if someone gets your password, they cannot get in without that second step.
Read also: How to recover a hacked Google account, step by step and How to spot a fake website before you type your password.
Why a password alone is not enough anymore
Large data breaches have made it routine for old passwords to circulate in lists that criminals buy and test automatically against email, bank and shopping sites. If you have reused a password, there is a good chance it is already in one of those lists. With 2FA on, a leaked password by itself is not enough for an attacker to get in.
How much it protects, in numbers
Google published, with researchers from New York University and the University of California, San Diego, a study on how well basic account protections work. The numbers show how big the gain is.
A code sent by text message to a recovery phone blocked 100% of automated bot attacks, 96% of bulk phishing attempts and 76% of targeted attacks. An on-device prompt, which the study points to as a safer alternative to texts, blocked 100% of automated attacks, 99% of bulk phishing and 90% of targeted attacks.
Not every second factor is equal
From weakest to strongest:
- Text message (SMS): better than nothing, but exposed to SIM swapping, when a criminal convinces your carrier to move your number to their SIM card, and to scams that simply ask you for the code.
- Authenticator app, such as Google Authenticator or Microsoft Authenticator, which generates a code that changes every 30 seconds: much safer, and it works without cell signal.
- On-device prompts and passkeys: the sign-in is confirmed on your own device with your fingerprint, face or screen lock.
- Physical security key: the strongest protection against phishing, recommended for people at higher risk.
The digital identity guidelines from NIST, the U.S. National Institute of Standards and Technology, classify codes sent by text as a restricted method precisely because the message can be redirected.
Source: NIST, Special Publication 800-63B, Digital Identity Guidelines.
Which accounts to protect first
Start with your main email, because it is the key used to reset every other password. Then move on to your bank and credit card apps, PayPal or Venmo, your Apple ID or Google account, and the social networks you use most. The path is usually Settings, then Security, then Two-step verification or Two-factor authentication; the exact name changes from service to service.
Golden rule: never share a verification code with anyone, by phone, text or chat. Your bank, your carrier and real companies do not call to ask for it.
Save your recovery codes
When you turn on 2FA, most services offer one-time recovery codes. Store them somewhere safe off your phone, such as printed and kept at home, or in a password manager. They are your way back in if your phone is lost, stolen or replaced. It also helps to add a second method, like a backup email or a second device. If an account does get taken over, see how to recover a hacked Google account.
Sources
- Google Security Blog. New research: How effective is basic account hygiene at preventing hijacking, 2019. https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html
- NIST. Special Publication 800-63B, Digital Identity Guidelines: Authentication and Lifecycle Management. https://pages.nist.gov/800-63-3/sp800-63b.html
Frequently asked questions
What happens if I lose my phone?
The recovery codes you saved when you turned on 2FA let you back in, so keep them somewhere off the phone.
Is text message a good second factor?
It is better than nothing, but it is the weakest option because your number can be hijacked through SIM swapping. Authenticator apps, passkeys and security keys protect more.
Is an authenticator app safer than SMS?
Generally yes. Text codes can be intercepted in SIM swap scams, while the authenticator app is tied to your device.
Will this slow me down every day?
It adds one step, but most services let you trust a device for a while, so you do not have to verify every time.