The Lock on Top of the Lock
Two-factor authentication (often written as "2FA") is a second layer of security on top of your password. Even if someone steals your password, they still can't get into your account without the second factor.
Think of it like your front door having both a key lock and a deadbolt. A burglar who copies your key still can't get in because they don't have the deadbolt key.
How It Works
The code changes every time and expires quickly (usually in 30-60 seconds). So even if a scammer has your password, they can't log in because they don't have your phone to receive the code.
- You enter your username and password as usual.
- The website asks for a second verification — usually a code sent to your phone by text message, or generated by an app.
- You enter the code, and now you're logged in.
Types of Two-Factor Authentication
There are several types, from easiest to most secure:
Any form of 2FA is dramatically better than no 2FA. Don't let "perfect" be the enemy of "good" — even text message codes block the vast majority of attacks.
- Text message (SMS) codes: A code sent to your phone by text. Easy to set up, better than nothing, but can be intercepted in rare cases.
- Authenticator app: An app on your phone (like Google Authenticator or Microsoft Authenticator) generates a new code every 30 seconds. More secure than text messages.
- Push notification: The service sends a "Was this you?" prompt to your phone app. You just tap Yes or No.
- Physical security key: A small USB device you plug in. The most secure option, used by security professionals.
How to Turn It On
Most major services offer 2FA. Here's where to find it:
- Google/Gmail: Go to myaccount.google.com → Security → 2-Step Verification
- Microsoft/Outlook: Go to account.microsoft.com → Security → Advanced security options
- Apple: Go to Settings → your name → Sign-In & Security → Two-Factor Authentication
- Facebook: Settings → Security and Login → Two-Factor Authentication
- Amazon: Account → Login & Security → Two-Step Verification
- Your bank: Check their app's settings or call them — most banks now offer app-based 2FA
Which Accounts to Protect First
If you're going to enable 2FA on just a few accounts, prioritise these:
Your email account is the single most important account to protect with 2FA. A hacker with access to your email can reset passwords on almost everything else.
- Your email — this is the master key. If someone gets your email, they can reset passwords on everything else.
- Your bank and financial accounts.
- Any account that has your payment card stored (Amazon, eBay, etc.).
- Social media accounts.