Technology
Two-Factor Authentication: What It Is and Why They Keep Asking
Two-factor authentication means an account needs two things to open: something you know, and something you have.
The password is the first. A code sent to your phone, or generated by an app, is the second.
It exists because passwords leak. Not because you were careless — because companies get breached and lists of email addresses and passwords circulate. With two-factor turned on, a leaked password on its own is not enough.
It is the single most effective security step available to an ordinary person, and it takes about two minutes per account.
The rule that matters more than anything else
Nobody legitimate will ever ask you for the code.
Not your bank. Not the tax office. Not a delivery company. Not technical support. The code exists to prove you are you. Anyone asking for it is trying to become you.
The messages themselves usually say this. It is worth reading one properly: it will say the code should never be shared with anyone.
If someone on the phone asks you to read out a code you just received, that call is a fraud, regardless of what your screen said about who was calling. See the call from your bank.
The methods, from weakest to strongest
Text message. A code arrives by SMS. The most common, the easiest, and the weakest — because a determined attacker can persuade a phone company to move your number to their SIM, a technique called SIM swapping.
Use it if it is the only option. It is vastly better than nothing, and the attack requires effort and targeting.
Authenticator app. An app on your phone generates a six-digit code that changes every thirty seconds. Nothing is sent anywhere, so there is nothing to intercept.
This is the option worth choosing. Setup takes a minute: the service shows a square code, you scan it with the app, and the app produces codes from then on.
Push approval. The service sends a notification and you tap approve. Convenient, and it has one weakness: people approve without reading. If a prompt appears when you were not signing in, decline it and change your password — someone has your password and is trying it.
A physical key. A small device you plug in or tap. The strongest available, and worth considering for email if you want the most protection.
Which accounts to protect first
Your email, before anything else.
This is the account people get wrong. Email feels less valuable than a bank account, and it is more valuable — because every other account resets through it. Whoever controls your email can take everything else at their leisure.
Then:
- Your bank and any investment accounts
- Your password manager, if you use one. See password managers
- Anything holding saved card details
- Social media, particularly if it is your main contact with family
- Your phone account with the carrier, which is what SIM swapping targets
The objection that comes up
"What if I lose my phone?"
A fair concern, and it is handled at setup rather than afterwards.
Save the backup codes. Every service offers a set of one-time codes when you turn this on. Print them, or write them down, and keep them with your important papers. They will get you back in.
Add a second method where possible — an app plus a phone number.
Some authenticator apps back themselves up to your account, so a new phone restores them.
Do the backup codes at setup. Nobody does it afterwards, and it is the whole answer to the objection.
Practical points
It is not needed every time. Most services ask once per device and then trust it. You are not entering a code every day.
Set it up on the device you actually use.
If you change your phone number, update it first, before losing access to the old one.
Codes expire quickly. If one fails, wait for the next rather than re-entering the old one.
For anyone helping a parent
Set it up together, not for them. The whole value is in them holding the second factor. An account where a family member receives the codes is an account the person cannot use independently, which usually leads to it being turned off.
Save the backup codes somewhere they can find, not somewhere you can.
Cover the rule about never sharing the code, explicitly. It is the most useful sentence in this whole subject and the one that prevents the most expensive mistakes.
The fifteen minutes worth spending
- [ ] Turn it on for your email — use an app rather than SMS if offered
- [ ] Save the backup codes on paper, with your important documents
- [ ] Turn it on for your bank
- [ ] Turn it on for your phone carrier account
- [ ] Remember one sentence: nobody legitimate ever asks for the code
For additional public information on consumer fraud and scam prevention, see Federal Trade Commission.